WEBVTT
Kind: captions
Language: en-GB

00:00:07.466 --> 00:00:14.057
Hello and welcome to this Samsung Knox training video on Getting started with Knox Mobile Enrollment Direct.

00:00:14.058 --> 00:00:20.849
In this video, we'll explain what Knox Mobile Enrollment Direct is, the different features it offers,

00:00:20.850 --> 00:00:25.553
and how it can be used to enroll a large device fleet in an EMM.

00:00:25.553 --> 00:00:31.465
Specifically, you'll learn how to install the software, how to create a profile,

00:00:31.466 --> 00:00:35.843
how to update or delete a profile, and how to enroll a device.

00:00:35.844 --> 00:00:41.419
So, if you're new to the world of Knox Mobile Enrollment Direct, then this video is for you.

00:00:41.420 --> 00:00:43.366
Let's get started!

00:00:43.766 --> 00:00:47.632
Before you begin, you'll need to have an account at&nbsp;samsungknox.com.

00:00:47.633 --> 00:00:51.999
For more information, check out the video on Getting started with Knox Admin Portal.

00:00:52.533 --> 00:00:55.666
A laptop or desktop computer running Windows 10 or higher 

00:00:55.666 --> 00:00:59.117
to run the Knox Mobile Enrollment Direct PC app.
 

00:00:59.118 --> 00:01:03.432
And, one or more Samsung devices running&nbsp;Android 11 or higher. 
 

00:01:04.600 --> 00:01:08.094
Knox Mobile Enrollment Direct, or KME Direct,

00:01:08.094 --> 00:01:11.099
is the on-premise version of Knox Mobile Enrollment.

00:01:11.433 --> 00:01:15.433
By using a PC app, KME Direct allows IT admins

00:01:15.433 --> 00:01:20.433
to easily enroll and set up a large fleet of devices in locally-hosted EMMs.

00:01:20.966 --> 00:01:25.609
To start using KME Direct, you must install the KME Direct PC app.

00:01:25.610 --> 00:01:31.133
To do so, log into your Samsung Knox account.

00:01:31.933 --> 00:01:37.499
and download the app installer ending with .exe, found in Step 1.

00:01:37.800 --> 00:01:41.168
Once you run the installer, accept the terms of agreement,

00:01:41.168 --> 00:01:45.932
then create a passcode that you’ll need to enter every time you run the app in the future.

00:01:46.033 --> 00:01:50.236
Once you finish creating your passcode, you’ll see a unique recovery key on screen. 

00:01:50.236 --> 00:01:54.032
This key helps you reset your passcode if you forget it in the future.

00:01:54.033 --> 00:01:56.766
Copy this key to a secure location on your PC.

00:01:57.233 --> 00:02:00.110
Next, copy the Activation request key, 

00:02:00.111 --> 00:02:06.965
then go back to the KME Direct Download page and paste the key in the dialogue box in Step 2.

00:02:06.966 --> 00:02:10.099
This generates the License activation key.

00:02:10.099 --> 00:02:13.232
Copy this key, navigate back to your app installer,

00:02:13.233 --> 00:02:16.420
and paste it in the License activation key field.

00:02:16.420 --> 00:02:20.683
Then, choose where you’d like to install the app, and click Install.

00:02:20.684 --> 00:02:24.125
After the installation is complete, launch the app,

00:02:24.126 --> 00:02:27.799
then enter your passcode to start using the KME Direct app. 

00:02:27.900 --> 00:02:30.715
When you log in to the app for the first time,

00:02:30.715 --> 00:02:36.732
you’ll see the Global Settings screen that lets you configure the relay server and QR code settings.

00:02:37.000 --> 00:02:41.566
The relay server is the internal server where you upload the XML file 

00:02:41.800 --> 00:02:45.033
containing your settings that the target device will download. 

00:02:45.400 --> 00:02:48.066
You can either use the built-in relay server 

00:02:48.466 --> 00:02:52.366
or provide a customizable local server location.

00:02:52.733 --> 00:02:58.109
Note that this server will be used any time you create a device configuration profile,

00:02:58.110 --> 00:03:01.333
a kind of profile that we’ll look into shortly.

00:03:01.333 --> 00:03:06.106
For the purposes of this video, we’ll select the built-in relay server option.

00:03:06.107 --> 00:03:12.838
You can also use QR codes to enroll your devices and decide how they’re scanned on your devices.

00:03:12.838 --> 00:03:20.227
We’ll select the minimized single QR code with hiding passwords that encrypts passwords in the QR code.

00:03:20.228 --> 00:03:22.599
Once done, hit Save and close.

00:03:23.966 --> 00:03:27.266
Next, let’s look at how you can create a profile.

00:03:27.266 --> 00:03:32.799
Click the Create profile button. KME Direct offers two profile types:

00:03:32.800 --> 00:03:36.695
Device configuration profiles let you configure settings related

00:03:36.695 --> 00:03:40.465
to your device’s display, sounds, key mapping, and more.

00:03:40.466 --> 00:03:45.499
Device deployment profiles helps you enroll devices, install apps,

00:03:45.499 --> 00:03:49.665
and push your device configuration profiles during the initial setup.

00:03:50.000 --> 00:03:52.882
Let’s take a look at device configuration profiles.

00:03:52.882 --> 00:03:55.165
Click on Configuration profile.

00:03:55.166 --> 00:04:00.000
Enter a profile name. Then, configure the device’s display settings by selecting 

00:04:00.001 --> 00:04:06.399
the duration of screen timeout, brightness levels, font size, and touch sensitivity.

00:04:06.400 --> 00:04:12.366
For fully managed devices, you can configure key-press settings, that let you set the button order

00:04:12.366 --> 00:04:15.232
and resulting actions for key presses on the device.

00:04:15.833 --> 00:04:20.957
Then, you can configure some general settings such as Near-field communication,

00:04:20.958 --> 00:04:25.699
Wi-Fi blocklist to block devices from connecting to some Wi-Fi SSIDs, 

00:04:25.700 --> 00:04:31.866
sound settings to selectively control the device’s volume, and the language and location settings.

00:04:31.866 --> 00:04:39.866
Next, set the device’s roaming to turn the device roaming on or off and set the Access Point Name configuration.

00:04:39.866 --> 00:04:44.366
Note that APN settings are supported only on fully managed devices.

00:04:45.000 --> 00:04:52.033
Once done, confirm all your configurations on the Summary page and click Generate XML/QR code.

00:04:52.033 --> 00:04:56.018
This generates and uploads an XML file on to the relay server.

00:04:56.019 --> 00:05:00.782
This XML file allows the KSP agent to push your settings to the devices.

00:05:00.782 --> 00:05:05.032
Note that if you configure a local relay server in your Global Settings,

00:05:05.033 --> 00:05:09.366
you’ll have to manually upload this XML file to the local server.

00:05:10.366 --> 00:05:16.199
Finally, click Generate QR code to generate or download the QR code for this profile.

00:05:17.066 --> 00:05:21.326
Next, let’s deploy these configurations onto a target device. 

00:05:21.327 --> 00:05:25.399
To do so, let’s create a device deployment profile by clicking

00:05:25.400 --> 00:05:28.619
Create profile and selecting Deployment profile.

00:05:28.619 --> 00:05:31.482
Enter the profile and organization name. 

00:05:31.482 --> 00:05:36.632
Then, select Set up Wi-Fi to configure the Wi-Fi network connection policies.

00:05:36.633 --> 00:05:40.596
Next, enter any custom legal agreement information, 

00:05:40.596 --> 00:05:45.766
including privacy policy, EULAs, and terms of service. 

00:05:45.767 --> 00:05:50.791
Then, configure the Android Enterprise settings. Here, select your EMM provider.

00:05:50.791 --> 00:05:57.497
Doing so auto-populates all its information such as the URI where the EMM agent APK is located,

00:05:57.497 --> 00:06:01.221
the receiver component name, as well as the signature checksum.

00:06:01.222 --> 00:06:07.001
Next, you can optionally provide a customizable server URI for the target device to connect to,

00:06:07.001 --> 00:06:11.579
and any custom data in JSON format that is sent to the EMM agent. 

00:06:11.580 --> 00:06:16.144
Then, select Dual DAR to secure device data through two layers of encryption,

00:06:16.144 --> 00:06:18.744
add any root or intermediate certificates, 

00:06:18.745 --> 00:06:22.911
and select which enrollment screens are displayed during device enrollment,

00:06:22.911 --> 00:06:25.962
depending on the Android version of the target device.

00:06:25.962 --> 00:06:29.899
Then, you can also configure any additional deployment options as needed.

00:06:29.900 --> 00:06:36.370
Note that you can only configure the following settings if you’ve previously set up a Device configuration profile.

00:06:36.370 --> 00:06:40.646
Specify the location for the device configuration profile and KSP agent,

00:06:40.646 --> 00:06:44.799
then specify the location for the Knox Enrollment Service agent.

00:06:46.266 --> 00:06:51.801
Select whether pre-installed system apps are enabled on the target device and available to the profile.

00:06:51.801 --> 00:06:54.945
Then, add any apps to deploy on devices 

00:06:54.946 --> 00:06:59.132
(based on its name, signature checksum, and the app APK URI).

00:07:00.033 --> 00:07:05.066
Once done, confirm all your settings and then click Generate QR code button 

00:07:05.066 --> 00:07:08.483
to generate or download the QR code for this profile

00:07:08.483 --> 00:07:13.965
and use it for enrolling devices and pushing the device configurations during the initial phone setup.

00:07:13.966 --> 00:07:17.782
To update a profile, click on the profile name,

00:07:17.783 --> 00:07:22.664
click on the specific setting you’d like to update, for example Key configuration,

00:07:22.664 --> 00:07:26.532
and then click the Edit button at the bottom of the sliding panel.

00:07:26.533 --> 00:07:29.333
Once you make your changes, hit Save.

00:07:30.633 --> 00:07:36.199
To delete a profile, select a profile on the Profiles page, and click Delete.

00:07:37.600 --> 00:07:41.158
This completes the Knox Mobile Enrollment Direct tutorial.

00:07:41.158 --> 00:07:46.818
Congratulations! You're now ready to deploy different configurations onto multiple devices at once 

00:07:46.818 --> 00:07:49.054
and enroll them into your EMMs!

00:07:49.055 --> 00:07:55.890
For help at any point, see the KME-Direct documentation at docs.samsungknox.com. 

00:07:55.891 --> 00:07:57.666
Thank you for watching!

