Knox Service Plugin (KSP)
The Knox Service Plugin app allows the Knox Platform for Enterprise (KPE) features for Samsung devices. For more information, see KSP.
Prerequisites:
-
Latest Knox version.
-
Knox KSP support in Enterprise Mobility Management (EMM).
-
Register EMM with Google for Managed Access.
-
KSP License number <> and Expiration date <>
Register EMM with Google:
To check the registration status:
Login to VMware Workspace ONE UEM (fomerly AirWatch) > Groups & Setting > All Settings > Devices & Users > Android > Android EMM Registration > Android EMM Registration Status: Successful.
Enrolling the device:
To enroll a device:
-
Select Device & Users > Android > Enrollment Settings.
-
In the Current Setting, choose Override.
-
In the Work Managed Enrollment Type (non-G suite only), select USER-BASED.
-
In the Fully-Managed Device Enrollments, select WORK MANAGED DEVICE.
Configuring the Enterprise Mobility Management (EMM):
Perform the following:
-
Create a User.
Accounts> List view> Add (Drop Down)> Add User and enter details. -
Create an Assignment Group (AG).
-
Select Groups & Setting> Groups> Assignment Groups> Add Smart Group and provide a name.
-
Click on Devices Or Users, add the user created, and Save.
-
Create a Profile.
-
Select Devices> Profiles>Add (Drop Down)> Add profile> Android, click on General .
-
Enter the name created.
-
Add the Smart Group created.
-
-
Add a certificate (optional).
-
-
Select Credential> Configure> Credential Source (Upload)> Provide the Credential Name>upload the Certificate.
-
The certificate installed has a random alias name hence a manual installation of certificate in the workspace is recommended
-
Adding apps
-
Apps & Books> Native> Public> Add Application.
-
Platform> Android, Source> Search App Store> Knox Service Plugin→ select the Samsung KSP> Approve> Approve> Done.
-
Click Save & Assign.
-
Add Assignment> Click on Assignment Groups> Select the AG created earlier.
-
App Delivery Method> Auto.
-
Enable Managed Access.
-
Pre-Release Version> Beta.
-
App Configurations> Edit.
-
-
In the KSP Application Configuration, perform the following:
-
Profile Name: Enter a name.
-
KPE Premium Key: Enter the KSP premium key.
-
Debug Mode-Enable. This helps identify profile failures.
-
-
In Work Profile Policies (Profile Owner) section, add the following:
-
Enable work Profile configuration controls: Enable.
-
Allow adding apps from personal space to work profile: Enable.
-
VPN type: Work Profile.
-
Enable on-demand VPN: Disable.
-
Manage list of apps that can bypass VPN: list of samsung vpns.
-
Name of VPN profile to use: Ensure this is the same as the KSP application name provided.
-
Enable VPN Chaining: Disable.
-
-
In VPN Profiles (Premium) section, add the following:
-
Profile name: PulseVPN.
-
Vendor: Pulse Secure.
-
Host: Enter host details.
-
VPN Connection type: SSL.
-
Include UID/PID data: Disable.
-
Certalias: <Enter a name>.
-
-
In the Certificate management policies, select Enable in Allow applications to read private keys without alerting user (Configure profiles below).