- Basics
- About Knox
- Knox licenses
- Knox white paper
- Sign up for Samsung Knox
- Latest release notes
- General Knox FAQ
- General Knox KBAs
- Submit a support ticket
- User Acceptance Testing
- For IT admins
- Knox Admin Portal
- Knox Suite
- Knox Platform for Enterprise
- Introduction
- How-to videos
- Before you begin
- Get started with UEMs
- Introduction
- Blackberry UEM
- Citrix Endpoint Management
- FAMOC
- IBM MaaS360
- Microsoft Intune
- MobileIron Cloud
- MobileIron Core
- Samsung Knox Manage
- SOTI MobiControl
- VMware Workspace ONE UEM
- Knox Service Plugin
- Release notes
- Migrate to Android 11
- FAQs
- Troubleshoot
- KBAs
- Knox Mobile Enrollment
- Knox Configure
- Mobile
- Wearables
- Shared Device
- FAQ
- KBAs
- Knox Capture
- Welcome
- Overview
- How-to guides
- Manage licenses
- Scanning profiles
- Apps and activities
- Scan engine settings
- Keystroke output rules
- Export configuration and deploy through EMM
- Set the camera scan trigger
- Connect a hardware scanner
- Configure the output path
- Use the scanner overlay
- Check a configuration in test mode
- Use intent output
- Knox Capture AR
- Get started
- How-to videos
- Release notes
- FAQ
- KBAs
- Troubleshoot
- Knox Capture: Scandit Edition
- Introduction
- How it works
- IT admins: Get started
- Getting started with Knox Capture
- Step 1: Launch Knox Capture
- Step 2: Create a scanning profile
- Step 3: Select apps and activities
- Step 4: Configure the scanner
- Step 5: Set keystroke output rules
- Step 6: Test apps in your configuration
- Step 7: Share your configuration
- Step 8: Deploy Knox Capture in Managed mode
- End users: Get started
- Features
- Knox Asset Intelligence
- Knox Manage
- Introduction
- How-to videos
- Get started
- Video: Getting started with Knox Manage
- Integration with Managed Service Provider
- Access Knox Manage
- Configure basic environments
- Create user accounts
- Create groups
- Create organization
- Set up devices and profiles
- Create a new profile
- Assign profiles to groups and organizations
- Enroll devices
- Shared Android device quickstart
- Non-shared Android device enrollment quickstart
- Android Management API device enrollment quickstart
- Apple User Enrollment quickstart
- View device information
- Apply profiles to organizations
- Set up Knox Manage deployment with a Knox Suite license
- Manage Chromebooks
- Manage Android devices with the Android Management API
- Manage Shared iPads
- Configure
- Licenses
- Organization
- Users
- Sync user information
- Groups
- Devices
- Content
- Applications
- Profile
- Knox E-FOTA
- Certificates
- Advanced settings
- Monitor
- Kiosk devices
- Knox Remote Support
- Active Directory
- Microsoft Exchange
- Mobile Admin
- Appendix
- Release notes
- Features
- FAQ
- KBAs
- Knox E-FOTA
- Introduction
- How-to videos
- Get started
- Features
- EMM integration
- Appendix
- Release notes
- FAQ
- KBAs
- Troubleshoot
- Knox E-FOTA On-Premises
- Legacy Knox E-FOTA products
- Knox Guard
- Introduction
- How-to video
- Get started
- Using Knox Guard
- Dashboard
- Manage devices
- Device management
- Accept or reject devices
- Upload devices
- Delete devices
- Complete device management
- Send notifications
- Enable or disable SIM control
- Download devices as CSV
- View device log
- View device deletion log
- Start and stop blinking reminder
- Lock and unlock devices
- Update lock message
- Send relock timestamp
- Turn on/off relock reminder
- Manage policies
- Manage licenses
- Manage resellers
- Manage admins and roles
- Activity log
- Knox Deployment App
- Release notes
- FAQ
- KBAs
- Support
- Knox Guard REST API
- Samsung Care+ for Business
- For Knox Partners
- Knox Deployment Program
- Knox MSP Program
Enabling Dual DAR with Knox Service Plugin (KSP)
Prerequisites
- Enable DualDAR in KME or KME Direct profile configuration
- MDM/UEM to deploy KSP
- Knox DualDAR license Key
- Device that has Dual DAR 1.1.0 or higher
Supported devices
Android version | Samsung Exynos | Qualcomm Snapdragon |
Android 9 | Galaxy S10e (Spring 2019) | Galaxy S10+ (Spring 2019) |
Android 10 |
Galaxy S20+ (Spring 2020) Galaxy S10e (Spring 2020) |
Galaxy S20+ (Spring 2020) Galaxy S10e (Spring 2020) |
Android 11 |
Galaxy S21 Ultra (Spring 2021) Galaxy S20+ (Spring 2021) Galaxy S10e (Spring 2021) Galaxy Tab Active3 (Spring 2021) |
Galaxy S21 Ultra (Spring 2021) Galaxy S20+ (Spring 2021) Galaxy S10+ (Spring 2021) |
Android 12 | Galaxy S22 (Spring 2022) DO and WP-C PO mode Tab S8 (Spring 2022) DO and WP-C PO mode |
Galaxy S22 (Spring 2022) DO and WP-C PO mode Tab S8 (Spring 2022) DO and WP-C PO mode |
How to enable DualDAR for DO
NOTE — In order to successfully deploy and activate DualDAR through the Knox Service Plugin, you must enable DualDAR in the Knox Mobile Enrollment or Knox Mobile Enrollment Direct configuration.
- Through your EMM of choice, go to KSP Configuration.
-
On the KPE configuration page:
- If your EMM uses profiles, enter the profile name.
- Enter the KPE Premium key.
- Click on Device-wide policies (Selectively applicable to Fully Manage Device (DO) or Work Profile-on company owned devices (WP-C) mode as noted)(which drops down additional configurations) under Enable device policy controls set to True
- Set Enable password policy controls with KSP > Passcode Policy to True.
- Expand Dual Data-at-Rest (DAR) Encryption, then set the following:
- Enable Dual DAR Controls — true
- Data lock timeout type — Select a data lock type. This feature locks the credential encrypted (CE) storage and flushes the key from memory. Once locked, apps can't use the CE until the device user provides the credential again.
- Data lock timeout value (in minutes) — Enter a lockout duration higher than 5.
- Restrict access to device encrypted (DE) storage — false.
- List of apps approved to access DE storage — Enter one or more app package names For example, com.android.messages.
- Set password minimum length for inner layer — Enter a password minimum length for the inner layer password at DualDAR for fully managed devices.
- Set a new password for inner layer — Enter a new password for the inner layer at DualDAR for fully managed devices. The password must be stronger than the minimum quality. For example, if the minimum quality is numeric, then you must enter an alphanumeric password.
How to enable DualDAR for work profiles
NOTE – Ensure you have enabled DualDAR in the Knox Mobile Enrollment or Knox Mobile Enrollment Direct configuration in order to successfully deploy and activate the DualDAR feature through Knox Service Plugin.
- Through your MDM/UEM of choice, go to the KSP Configuration
-
Under the initial KPE Screen
- Enter profile name if applicable (some MDM/UEM don’t require this)
- Enter the KPE Premium key
- Click on Work Profile Policies(which drops down additional configurations) under Enable Work Profiles set to True
- Set Enable password policy controls with KSP > Passcode Policy to True
- Set Work Profile Configuration > Enable Work Profile Configuration Controls to True.
-
Click on Dual Data-at-Rest (DAR) Encryption (which drops down additional configurations)
- Enable Dual DAR Controls set to True
- Data lock timoeout type set to any option in the drop down
- Use this control to set a data lock type. This locks the credential encrypted (CE) storage and flushes the key from memory. Once locked, apps can’t use the CE until user provides the credential again
- Data lock timeout value (in mimutes) set to any value above 1
- Use this control to specify the data lock timeout value in minutes. To use this feature, you must set the data lock timeout type to specified value.
- List of apps approved to access DE storage
- List application’s package name (example com.android.messages)
How to verify Dual DAR is enabled on a device
Verification method 1 via KSP application
- Go to your Work Profile and click on Knox Service Plugin
- Click on Configuration on date & time
- Configuration results should show Dual Data-at-rest(DAR) Encryption as successful
Verification Method 2 via Settings and Work Profile
- Navigate to Settings (gear icon)
- Scroll down to Work Profile Settings
- Scroll to the very bottom to About Work Profile
- Under version number it will say DualDAR enabled (if successfully configured)