Knox Guard 26.10 release notes
Last updated October 8th, 2026
This document is new for the Knox cloud services 26.10 UAT.
On this tab
- New
- Cursor-based pagination for device info
- Malware scanning for application installation policy uploads
- API support for app access control policy
- API support for outgoing call controls
- Updates
- Get device info returns new fields
- Blocked characters in message fields
- Get device info by deviceId renamed to Get latest pay-as-you-go action
- Deprecations
- Notice for removal of the app block policy endpoint
New
Cursor-based pagination for device info
Starting with Knox Guard 26.10, you can use the new Get device info (cursor-based pagination) endpoint to retrieve device information. This endpoint offers faster and more consistent performance than Get device info.
To retrieve the first page of devices, specify the number of devices to return using pageSize. To retrieve subsequent pages, pass the cursor value returned in the previous response.
This endpoint only supports filtering by updateTimeFrom. To filter by status or SIM control parameters, use Get device info instead.
Malware scanning for application installation policy uploads
APK files uploaded using the Upload new app to application installation policy endpoint are now automatically scanned for malware.
You can check the status of the malware scan using the Get application installation policy endpoint. The scanResult field in the response returns one of the following:
Pending: The app is waiting to be scanned.Clean: The app has been scanned and is safe to use.
If malware is detected, the upload is rejected and the app is immediately removed.
API support for app access control policy
Previously, Knox Guard Advanced customers could only block app access using Update the app block policy. With Knox Guard 26.10, this has been expanded to support both blocking and allowing specific apps.
Use the new Update app access control policy endpoint to apply an app blocklist and allowlist to a device, or the corresponding Async endpoint to apply access controls to up to 10,000 devices at once. You can block up to 50 apps using blockedAppList, and allow up to 10 apps using allowedAppList.
Note that enabling the allowlist doesn’t block access to pre-loaded system apps*. To block a system app, add it to the blocklist.
*Pre-loaded system apps are identified by Android’s ApplicationInfo.FLAG_SYSTEM attribute. Apps without this flag are disabled by the allowlist unless added explicitly. Before applying an allowlist, verify that any app you want to permit either has this flag or is added to the allowlist.
API support for outgoing call controls
Knox Guard 26.10 introduces new endpoints that let you restrict a device’s ability to make outgoing calls. When enabled, the device user can only call numbers on the allowlist (up to 10). Emergency calls are exempt from this restriction.
If you have a Knox Guard Advanced license, use the Update outgoing call controls endpoint to apply restrictions to a specific device, or the corresponding Async endpoint to apply restrictions to up to 10,000 devices at once.
Updates
Get device info returns new fields
With Knox Guard 26.10, the Get device info endpoint response includes the following new fields:
| Field | Description |
|---|---|
latestFirmwareVersion |
The latest firmware or binary version available for the device. |
firstEnrolled |
The datetime Knox Guard was first activated on the device, in Unix timestamp format. Only returned for devices that have already activated Knox Guard. |
simControlPolicyId |
The ID of the SIM control policy assigned to the device. Only returned if SIM control settings are configured for the device. You can also retrieve this using the Get SIM control policy endpoint. |
appliedRelockTimestamp |
The relock timestamp currently applied on the device, in Unix timestamp format. Only returned for pay-as-you-go (PAYG) tenants. |
If you have a Knox Guard Advanced license, the response also includes:
| Field | Description |
|---|---|
isAppAllowTarget |
Whether the device is restricted to using only specific apps. |
allowedAppList |
If an app allowlist is applied to the device, returns an array listing the apps the device can access. |
appAccessNotification |
If a notification message is configured to display on devices with app access controls, returns the configured settings. |
isOutgoingCallRestrictionsTarget |
Whether outgoing call controls are configured for the device. |
isOutgoingCallRestrictionsApplied |
Whether outgoing call controls are applied to the device. |
outgoingCallRestrictions |
If outgoing call controls are configured for the device, returns the configured settings. |
In addition, the existing field descriptions for the deviceList array have been updated to more clearly and accurately reflect the information returned by this endpoint.
Blocked characters in message fields
As part of our ongoing commitment to strengthening product security, starting with Knox Guard 26.10, certain special characters are no longer supported in message fields and can’t be entered.
Blocked characters are: < > | ~ ` ^ \ =
This restriction impacts all endpoints with a message field in the request body, including:
Configurations set prior to the 26.10 release will continue to function without issue. However, setting a new configuration that has a blocked character in the request body will return an error.
Blocked characters may also be removed or modified from CSV file exports, so you may notice that values in an exported file differ from the original input. This sanitization applies even to legacy activity-log entries created before it was introduced. The original stored values aren’t modified.
Get device info by deviceId renamed to Get latest pay-as-you-go action
With Knox Guard 26.10, the Get device info by deviceId endpoint is renamed to Get latest pay-as-you-go action, and its description is updated to more clearly indicate its functionality.
Parameter and response descriptions are also updated across this endpoint for clarity. The endpoint’s path and behavior are unchanged.
Deprecations
Notice for removal of the app block policy endpoint
With the release of Update app access control policy, the existing Update the app block policy endpoint and its corresponding Async endpoint have been marked for deprecation and will be removed in a future release.
Use Update app access control policy instead, which supports both blocking and allowing apps.
See Knox Guard API reference for more information.
Back to release notesIs this page helpful?
Thank you for your feedback!