Knox Manage 19.09 release notes
Last updated July 26th, 2023
Please refer to the below list of new features and improvements to be released with Knox Manage version 19.09 scheduled for September 26, 2019 through September 30, 2019.
- UI/UX design refreshment
- Multi-profile support
- Android zero-touch support
- AD/LDAP group sync support
- Android 10 updates
Look and feel refreshment
The UI/UX design of Knox Manage console been redesigned into Knox Suite style. This refreshment will allow IT admins with simplified workflows and deliver harmonized look and feel with other Knox Cloud services such as Knox Configure.
App assignment workflow enhancements
App management profile step has been removed to streamline steps to assign applications to groups and organizations. Now three clicks with connection points are all steps you have to do to assign apps.
With Multi-profile support, IT admins can assign more than one profile to groups and organizations and manage each by priority settings. The profile with the highest priority overrides the others when policy conflict occurs among multiple profiles.
Simplified group management
It was often hard for IT admins to understand and manage many different types of groups with different limitations.
Now, there are only three groups (of user, device and AD/LDAP) where multiple MDM profiles or device commands can be executed regardless of types of the group.
Relocation of keepalive and profile update scheduler settings
Two types of Knox Manage agent policies, keepalive and profile update scheduler, have been moved to console’s main Setting page.
Also, IT admins can apply each setting globally or per group/organization.
Profile assignment to AD/LDAP groups
Previously, IT admins could not assign profiles to AD/LDAP groups directly; they had to firstly create organizations and move users to organization to assign profiles.
With 19.09 improvements, IT admins can assign profile to AD/LDAP group.
Transferring of entire folders in Remote Support
Until the release, Remote Support supported transfer of file types only. With this release, Remote Support can move folder and every files inside that folder together.
This improvement is especially useful for the IT admin to gather a whole bunch of device dump logs in the saved folder.
Samsung Knox Mobile Enrollment is a crucial feature for B2B customers who usually require bulk enrollment feature, but the service is available for Samsung devices only.
In consideration of customers with mixed device environment, Knox Manage implemented similar service by Google, called Zero-touch, from 19.09. It means we now support bulk enrollment services for general Android devices as well.
Automatic app deletion upon profile removal on kiosks
Previously, once-downloaded kiosk apps stayed on the device side even after the removal of kiosk profiles or unenrollment upon IT admin’s command.
Now IT admins can decide whether to remove kiosk application from the device automatically or not when released from Kiosk mode. Default value is Allow (remove).
AER advanced feature updates
Knox Manage passed the standard level of Android Enterprise Recommended validation. And now, we plan to implement advanced features as well starting from fully managed and work profile devices. 19.09 update includes several advanced items like below.
- When compliance issue happens, work profile apps will be hidden
- Advanced password policy for AER advanced requirement
- Key guard management for AER advanced requirement
- Zero-touch device owner enrollment
Time zone setting
IT admins can force Select Time zone of user devices. If time zone policy is setup, then the Date/Time auto configuration option will be grayed out.
Android Go support through Android Enterprise
Samsung Android Go devices does not have Knox platform and miss Knox API sets, so do Knox policies. However it was not clear for IT admins to understand such technical limitation.
Android GO devices should be handled as a non-Samsung Android devices although the manufacturer is Samsung, and it is recommended to be enrolled through Android Enterprise if were to use.
Deprecated features with Android 10
Some EMM features are dependent to device OS. With huge updates in Android 10, the below features will not be supported from Android 10 devices. Please refer to the below deprecation list when managing Android 10 devices.
- MDM Profile > Knox > Container Data > Moving a file to Knox area / general area
- Android Enterprise / Android (Legacy) > System > S Beam
- Android Enterprise / Android (Legacy) > Interface > NFC Control
- Knox > Firewall > Container > All Packages ( By Application is still available)
- Knox / Android (Legacy) > Security > Smart Card Browser Authentication
- Android (Legacy) > Security / App / System > … > Device Lock
- Device Command > Device > Lock & Unlock device / Power off device / Data reset
- Device detailed information > Wi-Fi & Network data usage
Updated features with Android 10
- Containers (Knox Workspace in Samsung Legacy, work profile in AE device) should be created manually through notification bar. High Accuracy setup also requires manual notification bar.
- Application runtime permission at Android Legacy can’t be forced to end user. In other words, end user can change configuration from the device settings anytime later.
- Silent COMP deployment is limited from Android 10. If the device screen is off, then end user must click notification to deploy COMP later.
Resolved issues and improvements
- [00173876 / KMVOC-8491] Wifi not automatically deploying
- [00169394 / KMVOC-8152] Factory Reset issue
- [00169035 / KMVOC-8186]Device command delivery has failed (device not found)
- [00170363 / KMVOC-8198] E-FOTA - status is not displayed at all.
- [00170608 / KMVOC-8212] Legacy Exchange activesync configuration applied but not registered by KM Agent
- [00168158 / KMVOC-8220] KM Client given for 4.4 is not working properly - especially Multi app kiosk mode.
- [00170715 / KMVOC-8238] Dialer app does not accept incoming calls
- [00172103 / KMVOC-8298] Bug in App Permission policy
- [00172629 / KMVOC-8327] Using Knox Manage after upgrade to version 9 (same issue as #8328)
- [Internal testing / KMVOC-8334] COMP is not created in P devices.
- [00173004 / KMVOC-8350] SIM PIN being shown on KM Client App “View Policies”
- [Internal testing / KMVOC-8351] Activation Type is wrong
- [00173438 / KMVOC-8359] Display warning details
- [Internal testing / KMVOC-8361] AE DO and COMP enrollment flow issue
- [00172514 / KMVOC-8361] Issues with Samsung e-mail app
- [00173456 / KMVOC-8371] AE DO enrollment issue with KM (same issue as #8361)
- [internal testing / KMVOC-8435] Email Account deleted automatically
Is this page helpful?
Thank you for your feedback!