Knox Service Plugin Setup
MDM-agnostic steps for setting up Samsung devices with Knox Service Plugin
In your MDM, navigate to the option to add applications through Managed Google Play Store, and add all desired BlueFletch applications plus two Samsung-specific apps:
Knox Service Plugin
BFE Knox Admin Helper
To find the latter, search "bluefletch" (quotation marks included) and select the Knox helper app
Locate the Managed App Config for Knox Service Plugin (consult MDM-specific documentation for help finding a managed app config)
Some MDMs (e.g. Intune) have the following settings under device OEM Config policies
Select "Knox Service Plugin" or "Samsung" as the OEM name
Configuration Name:
This can be any string
Profile name (version):
This can also be string. We recommend adding the date that you created this profile
Knox License Key:
Note: Feel free to reach out to BlueFletch for a Knox key to use for testing, but Samsung's recommendation is to use your EMM's key.
Following the Samsung guide Grant special permissions for an app, configure the following settings within the Knox Service Plugin app config:
Device-wide policies:
Enable device policy controls:
trueApplication management policies:
Enable application management controls:
trueEnable permission controls:
trueEnable Add applications for accessing the Knox SDK:
true(specifically required for Remote Control on Android 15+)*
Device Admin allowlisting:
Enable device admin controls:
trueAllowlisted DAs:
com.bluefletch.ems.emm.launcher
Return to the base level of the app config, and locate Add Applications for accessing the Knox SDK (specifically required for Remote Control on Android 15+)*
Create a group with the following fields configured:
Package name:
com.bluefletch.ems.emm.launcherScope:
REMOTE CONTROLThe signature is optional
Return to the base level of the app config, and locate Permission Controls. Add a group for each of the apps listed below:
com.bluefletch.ems.emm.launcher
All Files AccessAppear On Top
com.bluefletch.ems.emm.support
Appear On TopUsage Data AccessChange System Settings
com.bluefletch.ems.emm.remoteagent
Appear On Top
com.bluefletch.ems.emm.deviceinformation
Appear On Top
com.bluefletch.ems.emm.auth.msal (or other auth package)
Appear On Top
com.bluefletch.ems.emm.messaging
Appear On Top
*All the Remote Control-specific settings are derived from the Samsung guide How to authorize remote control permissions for Android 15 or higher.
Last updated