Android Management API device enrollment quickstart
Last updated September 25th, 2024
Knox Manage supports the following management modes on Android Management API devices:
- Work profile
- Fully managed
Starting with Knox Manage 23.09, support for new fully-managed Android Management API devices is restricted. To enroll new fully managed devices, use the Android Enterprise platform.
You must use the Android Device Policy app to enroll devices and to deploy and manage Android Management API policies on the devices.
For app management, Android Management API makes exclusive use of Managed Google Play. Fully-managed devices enrolled with Android Management API can only install private apps.
You can enroll Android Management API devices with the following provisioning strategies:
User-based enrollment with Android Management API
A user-based device is associated with a specific user account, and requires the device user to authenticate with their Knox Manage account during the enrollment flow. By default, this strategy uses a QR code to initiate the enrollment flow, but you can also make use of enrollment providers like Knox Mobile Enrollment and Zero-touch.
To enroll a user-based device using a QR code:
Step 1 — Prepare the device for enrollment
- Factory reset and power off the device.
- On the Knox Manage console, go to User.
- Select the user, then click Request Enrollment. An enrollment email with the QR code is sent to the user.
Step 2 — The device user enrolls the device
- Power on the device.
- At the welcome screen, tap the screen six times. The QR code reader app automatically installs and launches.
- Using another device to display the enrollment email, scan the QR code with the device.
- On the Agree to Terms and Conditions screen, read and acknowledge the terms and conditions. If you agree, the sign-in screen opens with a Samsung Knox Manage logo.
- Sign in with the user account credentials.
As the sign-in URL for Android Management API devices is the same regardless of the enrollment method — QR code, Knox Mobile Enrollment, or Zero-touch — the Device page on the Knox Manage console only categorizes the Enrollment Type of these devices as Others.
Userless enrollment with Android Management API
Starting with Knox Manage 23.09, support for new fully-managed Android Management API devices is restricted. To enroll new fully managed devices, use the Android Enterprise platform.
A userless device isn’t associated with a single user account — instead, it’s a shared device operated by multiple users or used in multiple enterprise contexts. It supports multiple user accounts, and applies user profiles and settings at the start of their session.
You can enroll a userless device using Knox Mobile Enrollment, Zero-touch enrollment, or by issuing an enrollment token generated by the Knox Manage console.
To enroll a userless device using an enrollment token:
Step 1 — Prepare the device for enrollment
- Factory reset and power off the device.
Step 2 — Generate token and QR code
-
On the Knox Manage console, go to Device Enrollment > Android/Wear OS Token.
-
Click Add to open the Add Token page, and specify the Name, Device Group, and Expiration Period of the token. You can select expiration periods ranging from 1 Day to Unlimited.
-
Back on the Android/Wear OS Token page, click the name of the new token to view its details.
-
Click Download QR Code as PDF and save the file to your file system.
-
Open the PDF.
Step 3 — Enroll the device
Ensure that the QR code generated with the enrollment token is valid at the time of enrollment.
- Power on the device.
- At the welcome screen, tap the screen six times. The QR code reader app automatically installs and launches.
- Scan the QR code from the open PDF file displayed on your other system.
- On the Agree to Terms and Conditions screen, read and acknowledge the terms and conditions. If you agree, the sign-in screen opens with a Samsung Knox Manage logo.
The device is enrolled and awaiting the start of a user session. Device users can now sign in with their user account credentials.
As the sign-in URL for Android Management API devices is the same regardless of the enrollment method — QR code, Knox Mobile Enrollment, or Zero-touch — the Device page on the Knox Manage console only categorizes the Enrollment Type of these devices as Others.
On this page
Is this page helpful?