Knox Manage 26.10 release notes (original console)
Last updated October 8th, 2026
This document is new for the Knox cloud services 26.10 UAT.
On this tab
- New
- Upgrade to a managed Google domain account
- Enforce Google Workspace account upgrades
- Switch to the new console from the original console
- iOS software update policy using Device Declarative Management
- New device commands
- New Android Enterprise policies
- New AMAPI policies
- Updates
- Google authentication is now available on work profile device types
- Apps installed on device report export options
- OpenAPI support for macOS device commands
- Switch device modes in the Knox Manage agent
- Deprecations
- Data Roaming and Voice Roaming report fields
- Pre-notice Android Legacy deprecation for existing devices
- Deprecation of the fully managed with work profile management type
New
Upgrade to a managed Google domain account
Previously, if you registered your Android Enterprise environment with a Managed Google Play account, you had to unlink your Google account and re-register with a managed Google domain account to configure Google Workspace authentication. With this release, you can upgrade your Managed Google Play account to a managed Google domain account from Knox Manage. Once upgraded, you can prompt Android Enterprise and Android Management API (AMAPI) device users to switch to Google Workspace authentication. To learn more, see Configure Google Workspace authentication.
Enforce Google Workspace account upgrades
If you upgrade to a managed Google domain account, you can set a policy to enforce AMAPI device users to upgrade their Google account and authentication method. With this capability, you can lock the work profile or factory reset the device if the device user doesn’t upgrade their account within a specified period, helping ensure devices stay compliant with your authentication requirements. To learn more, see Configure Google Workspace authentication. Similarly, you can request Android device users to upgrade their Google account and authentication method with the Upgrade to managed Google account device command.
Switch to the new console from the original console
Super admins can now switch their preferred console view directly from the original console. When a super admin switches consoles, all sub-admins are switched to that console on their next sign-in. To learn more, see Sign in to Knox Manage.
iOS software update policy using Device Declarative Management
Starting from Knox Manage 26.10, iOS software updates can be managed through a new policy that uses Apple’s Device Declarative Management (DDM) framework, enabling devices to autonomously evaluate their status and apply updates, even when offline. When the date and time matches the settings you configured, the device automatically updates its OS to the target OS version you set without needing to communicate with Knox Manage.
You can configure the target OS version and target local date time in the Software Update Enforcement (Declarative) section of an iOS policy, accessible from the Profiles page. Additional settings, including Automatic Software Updates and Software Update Deferrals, are available in the Software Update category. Note that these features require supervised devices. To learn more, see iOS policies.
New device commands
With this release, the following Android Enterprise device commands are added to the original console.
| Device command | Description |
|---|---|
| Upgrade to managed Google account | Sends a notification to the user's device requesting them to switch to sign-in with their Google account. |
New Android Enterprise policies
With this release, the following Android Enterprise policies are added to the original console.
| Policy | Description |
|---|---|
| Add work profile apps to home screen widgets | Allows the user to create widgets on their home screen from selected apps in the device's work profile. |
New AMAPI policies
With this release, the following AMAPI policies are added to the original console.
| Policy | Description |
|---|---|
| Upgrade to Managed Google Account | Requests device users to sign in with a managed Google account. |
| Take Actions if User Account Is Not Upgraded | Set the Lock work profile + Factory reset action if the user doesn’t upgrade their account in the period specified below. |
| Set Days before Work Profile Lock (days) | Sets the period (in days) before the work profile on a device is locked if the user doesn’t upgrade their account. |
| Set Days before Factory Reset (days) | Sets the period (in days) before the device is factory reset if the user doesn't upgrade their account. |
Updates
Google authentication is now available on work profile device types
Users synced from Google Workspace can now enroll their work profile type devices with their Google accounts.
Apps installed on device report export options
Starting from Knox Manage 26.10, when exporting an App Information Installed in Device report, you can choose between two export methods based on your needs:
- All apps with no calculations and filters — Exports all app data, providing the complete report as before.
- First 100,000 apps with calculations and filters applied — Limits the export to the first 100,000 apps with full calculations and filters, reducing wait time.
To learn more, see Default reports and report queries.
OpenAPI support for macOS device commands
Starting from Knox Manage 26.10, you can invoke macOS device commands through OpenAPI. This enhancement extends API-based device management capabilities to include macOS devices, enabling automated workflows and integration with third-party management systems.
Switch device modes in the Knox Manage agent
Device users can now switch their device back to a previously configured mode directly from the Knox Manage agent app, without IT admin intervention. To learn more, see Navigate the Knox Manage agent. The following options are available:
- Enter Kiosk — Switches the device back to kiosk mode if there’s a kiosk assigned to it.
- Enter Non-Shared Device — Switches the device back to non-shared device mode if it was previously configured.
- Enter Shared Device — Switches the device back to shared device mode if it was previously configured.
Deprecations
Data Roaming and Voice Roaming report fields
The Data Roaming and Voice Roaming report output fields have been removed (pre-noticed in v26.06). Any reports that contain only these fields have also been removed.
Pre-notice Android Legacy deprecation for existing devices
Previously, Knox Manage deprecated support for Android Legacy devices, meaning they could no longer enroll in Knox Manage. In an upcoming release, the Knox Manage agent will no longer be supported on Android Legacy devices. Similarly, Android Legacy profile and user creation will be blocked. The Knox Manage team strongly recommends that you migrate to the latest Android Enterprise platform.
For detailed information about migrating your device fleet, see the Android Legacy to Android Enterprise migration guide.
Deprecation of the fully managed with work profile management type
Knox Manage no longer allows devices to be enrolled as the fully managed with work profile management type. There is no impact on devices that are currently enrolled as this management type, but in a future release, these devices won’t be able to update to later Knox Manage versions.
Back to release notesIs this page helpful?
Thank you for your feedback!