You must meet the following requirements to use the Knox Service Plugin (KSP) with your managed devices.
The first step to deploy a KSP policy is to create a DO or PO profile on your device. Without choosing one or the other, policies do not work and an error message is thrown.
In an Enterprise deployment, Google provides three modes of Android Enterprise, Managed Device (DO), Work Profile (PO) and Fully Managed with Work Profile .
KSP works with the following Android Enterprise deployment modes:
Your deployment must use policy configurations that are supported by KSP. KSP inherits its policies from the KPE framework. These can be either standard (free) or premium feature (paid). Paid features require a KPE Premium license. You can see the supported features and their classification on the feature overview page.
You need a UEM that supports Android Enterprise based deployments, device management APIs and is compliant with the OEMConfig specification. Check with your UEM to confirm which version of their UEM console you need to use with KSP. Some UEM’s offer more than one console. Some consoles may not support KSP.
|BlackBerry||Coming soon||Not supported|
|Citrix||Supported||To be supported|
|IBM MaaS360||Supported||To be supported|
|Knox Manage||Coming soon||To be supported|
||To be supported|
|MobileIron||Supported||To be supported|
|VMware Workspace ONE UEM||Supported||To be supported|
Note: All UEM partners continue to support KPE through their console. Customers need to use KSP only if their UEM solution provider does not support a Knox feature they plan to use. For more information, see Which policy should I use if duplicate policies exist?