IBM Support

Android Enterprise and Samsung Knox harmonization

Release Notes


Abstract

Android Enterprise and Samsung Knox harmonization

Content

Background: Android Enterprise and Samsung Knox are being harmonized to work together on Samsung devices.

MaaS360 adds support for Samsung Harmonization. With this feature, MaaS360 allows administrators to leverage Samsung Knox APIs for corporate-owned Samsung devices enrolled in DO mode in addition to already supported Android Enterprise APIs. In 10.69, MaaS360 adds this capability as new policies for Samsung devices with a new support tag DO with KNOX under Android Enterprise in Android MDM Policy. Note: For existing DO enrollments on Samsung devices, users can enable ELM License from Corporate Settings to use this feature. The devices that enroll after 6.25 release are eligible for this feature by default. Supported on Samsung devices running Android OS version 6+.

Harmonization Impact

As a part of harmonization,

  • MaaS360 displays ELM license agreement during the Android Enterprise Work Managed Device (DO) enrollments to authorize the MaaS360 app to use Samsung APIs. MaaS360 only displays a toast message for devices running Knox 3.0 +.
  • MaaS360 adds support for remote control action and E-FOTA on Samsung devices enrolled in Android Enterprise Work Managed Device (DO) mode.
  • MaaS360 adds support for new policies for Samsung devices enrolled in DO mode. 

MaaS360 adds the following policies in Android MDM > Android Enterprise Settings:

Navigation Policy Description
Passcode Delay for Passcode prompt after lock screen Specifies the time delays after the entry of an invalid passcode at the Lock screen.
Security > Device Security
 
Allow Settings Changes Allow users to make changes modify settings through Settings application.
Enable Power Saving Mode Allows the use of power saving mode on the device.
Enable Samsung Device Attestation Triggers attestation check on the device every 24 hours as provided by Samsung.
Security > App Security Allow System Apps to be Stopped Allows users to force-stop apps signed by the system. 
Allow Widgets Allows users to add widgets on the device.
Allow Notifications Allows app notifications.
Security > Data Security Allow Clipboard Sharing between Apps If disabled, restricts the global clipboard between applications. In that case, each App will have its own individual clipboard. 
Security > Data Security Allow Clipboard Allows copying data to the clipboard.
Security > Data Security Allow Share List Disabling this setting disables the display of the Share Via List that is available to share data with other applications. 
Restrictions > Device Features Allow Audio Recording Allows audio recording on the device.
Allow Video recording Allows video recording on the device.
Allow Svoice Allow users to use the S Voice App on the device
Allowed Apps to manage certificates on Android TrustStore Comma-separated list of apps allowed to install/list/remove certificates to/in/from Android TrustStore
Restrictions > Network Restrictions  Allow Sbeam If disabled, restricts users from using S Beam to share content using near field communication (NFC) or Wi-Fi Direct.
Allow Wi-Fi Direct Allows the use of Wi-Fi Direct on the device.
Allow user to Mobile Data limit Allows users to set the mobile data limit.
Near Field Communication (NFC) Allows the use of Near Field Communication.
Restrictions > Developer Options  Allow Background Process Limit Allows users to set the background process limit by the user. When disabled, the background process limit is set to the maximum.
Allow Killing Activities on Leave On disabling this setting, the preference "Do not keep activities" in Developer Options of Settings application is unchecked, and the user cannot edit it.
Allow Google Crash Report Allows users to send a crash report to Google.
COSU (Kiosk Mode) Hide Navigation Bar Disables navigation bar (Home, Back, etc.). Applicable for Tablets only. Disable navigation bars (available as soft keys) - Home, Back, Recent Apps, Screenshot.
Hide System Bar Disables Status bar on phones. On tablets, disables Navigation bar and Status bar.
Block Hardware Keys Blocks supported hardware keys.
APN Settings All Policies Allows users to configure APN Settings
Firewall Settings All Policies Allows users to configure Firewall settings

Enabling ELM License for existing enrollments 

The existing users that have Samsung devices enrolled in Android Enterprise can enable Samsung ELM License through Corporate Settings.

To enable the ELM License,

  1. Navigate to Settings > Corporate Settings and then tap Activate Samsung ELM License.

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSYSXX","label":"IBM MaaS360"},"Component":"","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"10.69","Edition":"","Line of Business":{"code":"LOB24","label":"Security Software"}}]

Document Information

Modified date:
29 November 2018

UID

ibm10743195