Knox Manage 26.10 release notes (new console)
Last updated October 8th, 2026
This document is new for the Knox cloud services 26.10 UAT.
On this tab
- New
- Use Microsoft Conditional Access with device compliance
- Google Workspace synchronization and authentication
- Enroll devices without a designated user
- XR device management
- New rule settings
- Configure rules to measure device compliance
- New device connection condition
- Set automatic profile updates
- Users by organizations dashboard widget
- Collect EID information
- New Android Enterprise policies
- New device commands
- Updates
- New data included when exporting device list
- Remove work profile during device unenrollment
- Update to user creation
- Allow multi-app kiosk users to clear app data
- App information installed in device report export options
- Updates to device commands
- Activate eSIM cellular plan
- Deactivate eSIM cellular plan
- Re-enter kiosk mode as a device user
- Deprecated
- Deprecated device commands
New
Use Microsoft Conditional Access with device compliance
You can now integrate the new console as a compliance partner with Microsoft Intune. This lets you enforce Conditional Access policies through Microsoft Entra ID on Android devices enrolled in Knox Manage. Device compliance status is evaluated by Knox Manage and synced to Microsoft Entra ID, where it’s used to grant or deny access to protected resources, like Microsoft 365. This helps companies enforce device security requirements before users can access Microsoft Entra ID-protected apps. See Configure Knox Manage as a compliance partner with Microsoft Intune.
Google Workspace synchronization and authentication
From the new console, you can now integrate your Knox Manage tenant with Google Workspace to sync directory resources, such as users and groups, from your Google Admin Console. Once integrated, device users can enroll Android Enterprise devices with their managed Google accounts. To link your Google Admin Console, go to Configure Google authentication. This integration is available if you registered your Android Enterprise environment with a Managed Google Domain account only, not a personal one. To check what account you registered with, go to Managed Google domain.
Enroll devices without a designated user
You can now enroll fully managed devices without an assigned user. Multiple users can share a device enrolled with a userless enrollment token without needing to enter their credentials. The super admin who created the tenant can create userless enrollment tokens that generate a QR code, which devices scan to enroll. To learn more, see Enroll devices with a userless enrollment token.
XR device management
As of 26.10, the new console supports the management of XR devices. Supported XR devices are enrolled as fully managed and display as Fully Managed (XR) in the device list. Currently, XR devices support most device commands that are available for fully managed, Android devices.
New rule settings
Configure rules to measure device compliance
Previously you could configure general rules only to trigger specific actions on a device once it met predefined conditions. With the 26.10 release, you can also create compliance rules, which define the security conditions a device must meet to be considered compliant.
When devices violate the assigned security conditions and become non-compliant, set actions are triggered, such as locking the device or notifying IT admins. When Knox Manage is integrated with Microsoft Intune as a Compliance Partner, compliance rules are used to grant or block access to protected resources, such as Microsoft 365 apps. To learn more, see Create rules.
New device connection condition
You can now create a general rule with the Device Connection (Keepalive) condition. Similar to the keepalive feature in the original console, it triggers actions based on whether a device has communicated with the Knox Manage server within a set period.
Set automatic profile updates
With the 26.10 release, profile changes can now be applied on a set schedule without manual intervention. Automatic profile updates support multiple schedules, which you can configure globally or for selected groups and organizations, so you no longer need to manually push updates every time you change a profile. To learn more, see View and edit a profile.
Users by organizations dashboard widget
Starting from 26.10, the new Users by organizations widget is available on the dashboard. This widget displays the number of active users broken down by organization, providing a quick overview of user distribution across your organizational structure. You can click (Expand icon) on the widget to go to the Organizations page, or click a user count number to view the list of users assigned to that organization. To learn more, see Customize the dashboard.
Collect EID information
Starting from Knox Manage 26.10, you can collect the Embedded Identity Document (EID) — a unique 32-digit identifier assigned to the eSIM chip of a device — from work profile on personally-owned devices using a new device command under MOBILE NETWORK.
For these devices, users must provide consent before EID information can be collected. The collected EID information is displayed in the device sliding panel under NETWORK > MOBILE NETWORK INFORMATION > EID. To learn more, see Send device commands.
New Android Enterprise policies
With this release, the following Android Enterprise policy settings are added to the new console.
| Setting | Description |
|---|---|
| Allow users to clear cache and data | Let kiosk users delete app data and cache from apps in multi-app kiosks. In scenarios where multiple users, such as students, share a single kiosk device, each user can clear the previous user's data and reuse the app. |
New device commands
With this release, the following device commands are added to the new console.
| Device command | Description |
|---|---|
| Reapply Samsung Knox Wi-Fi policy | Reapplies all Wi-Fi configurations defined by assigned Knox Service Plugin policies. This command is helpful in situations where the device user has removed a configured Wi-Fi network from the network settings. |
Updates
New data included when exporting device list
Previously, exporting your device list as an XLSX file included only a limited set of device information. With this release, you can select additional checkboxes to include device details, app details, and security codes in the export. To learn more, see Device actions.
Remove work profile during device unenrollment
When you unenroll a work profile on company owned device, you can now remove the work profile without factory resetting the device. To learn more, see Unenroll and delete devices.
Update to user creation
Previously, you couldn’t specify a phone number when creating a user. With this release, you can enter a Primary phone number and select a country code from the drop-down. To learn more, see Create and delete users.
Allow multi-app kiosk users to clear app data
A new Clear App Data widget lets device users delete the cache and data for apps in a multi-app kiosk, once the Allow users to clear cache and data policy is enabled. This is especially useful in scenarios where multiple users share a single kiosk device. To learn more, see Build a multi-app kiosk.
App information installed in device report export options
Starting from Knox Manage 26.10, when exporting the App: Information installed in device report, you can choose between two export methods based on your needs:
- All apps with no calculations and filters — Exports all app data, providing the complete report as before.
- First 100,000 apps with calculations and filters applied — Limits the export to the first 100,000 apps with full calculations and filters, reducing wait time.
To learn more, see Report queries.
Updates to device commands
Activate eSIM cellular plan
Starting from Knox Manage 26.10, the Activate eSIM cellular plan device command supports multi-device activation. Previously limited to single-device only, you can now send this command to multiple devices simultaneously by entering an eSIM activation URL. Device users must manually enter the activation code on their devices.
For work profile on personally-owned devices, users must confirm the activation request on their device before the eSIM can be activated. After activation, eSIMs are shown in the device sliding panel under NETWORK > MOBILE NETWORK INFORMATION > Installed eSIMs. To learn more, see Send device commands.
Deactivate eSIM cellular plan
Starting from Knox Manage 26.10, the Deactivate eSIM cellular plan device command supports selecting which specific eSIM to deactivate when deactivating one device with multiple eSIMs. When deactivating an eSIM, the dialog varies based on your selection:
- One device with one eSIM — Deactivates the device’s only eSIM.
- Multiple devices — Deactivates all eSIMs on all selected devices. Deactivates the eSIMS on selected devices with only one eSIM. If devices have multiple eSIMS, the command fails.
- One device with multiple eSIMs — A dropdown appears, allowing you to select which specific eSIM to deactivate.
To learn more, see Send device commands.
Re-enter kiosk mode as a device user
Device users now have the option to re-enter kiosk mode, if it was previously configured for the device, from the Knox Manage agent.
Deprecated
Deprecated device commands
With this release, the following device commands are deprecated.
| Device command | Description |
|---|---|
| Reset data usage | Resets the device's inventory information for all network and Wi-Fi traffic. |
| Check for Compromised OS | Detects if the device OS is compromised. |
| Lock Knox Manage agent | Locks the Knox Manage agent. |
| Unlock Knox Manage agent | Unlocks the Knox Manage agent. |
Is this page helpful?
Thank you for your feedback!