Skip to main content

December 10, 2024

Knox Profiles

Containerization of enterprise content provides you with a dual device experience, successfully splitting the enterprise functions of your device into an encrypted container. Configuring profiles helps you secure the corporate container with your Samsung Knox-enabled device. This allows you to use your phone as a personal and work device without threatening security.

Certain corporate-owned device scenarios support the creation of Container Only Mode which locks the device into to Knox container with no dual persona or personal side to the device. In this case, profiles only applies to the container. The prompt for configuring the device in Container Only Mode is selected during enrollment and the user cannot change this setting.

Device Access

Some device profiles configure the settings for accessing an Knox device. Use these profiles to ensure that access to a device is limited only to authorized users.

Some examples of device access profiles include:

Device Security

Ensure that your Knox devices remain secure through device profiles. These profiles configure the native Knox security features or configure corporate security settings on a device through AirWatch.

Device Configuration

Configure the various settings of your Knox devices with the configuration profiles. These profiles configure the device settings to meet your business needs.

  • Access a URL directly from an icon on the device's menu. For more information, see Bookmarks (Knox).

  • Set the date and time and the display format to provide your fleet with the appropriate regional format. For more information, see Set Date/Time (Knox).

  • Device Profiles and Container Profiles
    With containerization for Samsung Knox, it is still possible to have two different profiles on your device. You can deploy a device profile to a Knox- enabled device and this profile will only apply to the personal side of the device and not affect the Knox container.

  • Passcode Profile (Knox)
    As an extra line of defense for your corporate data and content, you can enforce a container passcode to secure the isolated business container on a Knox enabled device.

  • Enforce Browser Restrictions (Knox)
    Knox browser restrictions helps to minimize vulnerability and maximize security as end-users access the corporate container using the browser to view and use internal content.

  • Enable Per App VPN for Knox Container Applications
    A virtual private network (VPN) connection provides devices a secure and encrypted tunnel to an internal network, effectively allowing each device to function as seamlessly as if they were using the network on-site.

  • Activate Email Settings (Knox)
    You can configure email settings externally from Exchange Active Sync (EAS) by pushing an Email Settings profile payload.

  • Configure Exchange Active Sync Mail Client (Knox)
    To guarantee a secure connection to internal email, calendars, and contacts, Workspace ONE UEM uses the native email client to access EAS mail from the corporate container on Knox devices.

  • Configure Single Sign-On (Knox)
    Single Sign-on (SSO) allows your employees to move from application to application within the container without the hassle of repetitively signing in.

  • Deploy Credentials (Knox)
    Credentials profiles deploy corporate certificates for user authentication to managed devices.

  • Configure Application Control (Knox)
    Set parameters around your application deployments on devices by Preventing Installation of Blacklisted Apps and Only Allowing installation of Whitelisted Apps.

  • Implement Smart Card Authentication (Knox)
    You can require end-user identity verification using SmartCard authentication for browser and email access. End-users who try to authenticate without a Smart Card after this feature is enabled, cannot access their email.

  • Configure Firewall Rules
    The Firewall payload allows admins to configure firewall rules within the Knox container.

  • Set Restrictions (Knox)
    Prevent data leaks by enabling listed restrictions in the Knox container.

  • Create Custom Settings (Knox)
    The Custom Settings profile can be used when new Knox functionality or features that the Workspace ONE UEM console does not currently support or if there are any custom device changes you want implemented. Custom profiles can be used to maintain separate application groups for the device and container with XML code to enable or disable certain settings manually.

  • Bookmarks (Knox)
    Bookmarks function much like an app on a device, providing end users a simple way to access a URL directly from an icon on their device's menu. Admins can send bookmarks for users to access an important URL without having to switch to the personal container on the device.

  • Set Date/Time (Knox)
    Set the date and time and the display format to provide your fleet with the appropriate regional format.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…