How the Knox Service Plugin managed configuration is pushed to a device

Last updated July 14th, 2026

Categories:

Environment

  • Knox Manage
  • Knox Service Plugin

Overview

This article explains the implementation logic behind KM and KSP, and describes the steps involved with deploying a managed configuration to a device.

How the Knox Service Plugin managed configuration is pushed to a device

  1. Knox Manage sends the Knox Service Plugin schema data to Google.

  2. Google sends the Knox Service Plugin managed configuration to the device, and Knox Service Plugin sends feedback to the Knox Manage server.

  3. When the device’s Knox Service Plugin app receives the new managed configuration, the app applies the new policies. If there are no functional changes to the previous policy configuration, the app doesn’t update the managed configuration.

    • New policies are typically applied to your devices almost immediately, but is subject to server traffic, internet connectivity, and device status. If your changes aren’t applied within one or two days, submit a support ticket.
    • The Knox Service Plugin managed configuration is delivered to devices through Managed Google Play. When Managed Google Play checks for updated managed configurations, it also updates the Knox Service Plugin app if there’s a new version available. This helps ensure that Knox Service Plugin remains up to date with the latest features and security enhancements.

Additional Information

For more details about Knox Service Plugin, see Knox Service Plugin admin guide.

Is this page helpful?