Edit

Samsung Knox E-FOTA integration with Microsoft Intune

Samsung Knox E-FOTA (Firmware Over-the-Air) lets IT administrators remotely deploy firmware updates to corporate-owned Samsung devices. Administrators can select firmware versions and schedule downloads and installations to reduce device downtime. After registration, firmware deployments don't require user interaction.

The Microsoft Intune integration brings Knox E-FOTA capabilities into the admin center. Before you begin, review the device, network, licensing, role, tenant, and cloud prerequisites. With this integration, you can:

  • Launch, manage, and monitor firmware update campaigns for Samsung devices from the admin center.
  • Lock devices to a specific operating system (OS) version or selected firmware.
  • Schedule download and install windows to minimize device downtime.

Prerequisites

Device platform requirements

Samsung Knox E-FOTA updates are supported on Android Enterprise devices enrolled in Intune. This support includes the following enrollment types:

  • Android Enterprise corporate-owned dedicated (COSU)
  • Android Enterprise corporate-owned fully managed (COBO)
  • Android Enterprise corporate-owned with a work profile (COPE)

For information about which devices are supported by Samsung Knox, see Devices Secured by Knox.

Network and connectivity requirements

For information about service ports and endpoints used by Samsung Knox, see Samsung Knox firewall exceptions.

Licensing requirements

You need a Samsung Knox E-FOTA license to use the service. For more information, see Samsung Knox E-FOTA.

You also need at least a Microsoft 365 E3 plan to use the service.

Roles requirements

The required permissions depend on the task.


To set up the Samsung connector, sign in with an account assigned the Intune Administrator role.

You also need a Samsung Knox administrator account to connect Intune to Samsung Knox E-FOTA. For more information, see Manage admins.

If your organization uses Microsoft Entra Privileged Identity Management (PIM), activate the Intune Administrator role only when you configure the connector.


To configure devices and manage Samsung Knox E-FOTA deployments, use an account with at least the following permissions:

  • Android FOTA (to register devices with Samsung Knox E-FOTA and manage their firmware updates)
  • Mobile apps (to deploy the required apps to the devices)
  • Device configurations (to configure the devices by using an OEM configuration template)

Tenant configuration requirements

You must configure Managed Google Play for your tenant. For setup instructions, see Set up Managed Google Play.

Cloud requirements

Samsung Knox E-FOTA updates are supported in the public cloud.

Process overview

The process for using Samsung Knox E-FOTA through Intune is as follows:

  1. Set up the Samsung connector.
  2. Deploy the required apps to the devices.
  3. Configure the devices by using an OEM configuration template.
  4. Sync devices with Samsung.
  5. Complete device registration.

After the devices are registered with Samsung, you can create an E-FOTA deployment to manage firmware updates for the devices.

 Set up the Samsung connector

In the Microsoft Intune admin center, link Intune and Samsung Knox E-FOTA by creating a connector. The connector allows Intune to communicate with Samsung Knox E-FOTA and manage firmware updates for eligible Samsung devices.

  1. Sign in to the Microsoft Intune admin center.
  2. Select Tenant administration > Connectors and tokens > Firmware over-the-air update.
  3. Select Samsung.
  4. Select Connect, and then select Connect again to confirm. The Samsung Knox E-FOTA portal opens. Sign in with a Samsung Knox administrator account and authorize the connection.
  5. After the connection is established, you're redirected to the Intune admin center. The connector is listed as Connected.

 Deploy the required apps to the devices

Samsung Knox requires the following apps on each device to enroll it in the E-FOTA service:

  • Knox E-FOTA (com.samsung.android.knox.efota)
  • Knox Service Plugin (com.samsung.android.knox.kpu)

Add both apps to your tenant through Managed Google Play. Assign the apps as Required to the security groups that contain the Samsung devices you want to register. Intune then deploys the apps to those devices.

For more information, see Add and assign Managed Google Play apps to Android Enterprise devices.

 Configure the devices by using an OEM configuration template

To manage firmware updates through the E-FOTA service, configure the devices by using an OEM configuration template.

  1. Sign in to the Microsoft Intune admin center.
  2. Select Devices > Configuration.
  3. Under Policies, select Create.
  4. In Create profile, use the following settings and select Create:
    • Platform: Android Enterprise
    • Profile type: Templates
    • Template name: OEMConfig
  5. Under Configuration settings, select:
    • Enable device policy controls: true
    • Enable firmware controls: true
    • Enable E-FOTA client installation & launch: true
  6. Assign the device configuration to the same security group that contains the devices you registered with Samsung.
  7. Select Next.

 Sync devices with Samsung

To manage firmware updates for Samsung devices with Intune, register the devices with Samsung Knox E-FOTA. Assign the security groups that contain these devices to the Samsung connector.

To register the devices with Samsung:

  1. Sign in to the Microsoft Intune admin center.
  2. Select Tenant administration > Connectors and tokens > Firmware over-the-air update.
  3. Select Samsung to open the Samsung Knox E-FOTA connector setup.
  4. Select Add groups, and then select the security groups that contain the Samsung devices to manage by using E-FOTA.
  5. Select Register.
  6. The devices are uploaded to Samsung. Use the Samsung Knox administrator account to view them in the Knox Admin Portal.

 Complete device registration

On each targeted Samsung device, open the Knox E-FOTA app. A device user must accept the terms and conditions to complete registration with Samsung Knox E-FOTA.

Create an E-FOTA update campaign

After you register the devices with Samsung Knox E-FOTA, you can create a deployment to manage the firmware updates for the devices you registered. Samsung Knox E-FOTA deployments are also called campaigns.

  1. Sign in to the Microsoft Intune admin center.
  2. Select Devices > Android > Manage updates > Android FOTA deployments.
  3. Select Create.
  4. In the Create deployment - Basics pane, select the device model, sales code, CSC, and firmware version.
  5. In the Create deployment - Settings pane, configure the deployment schedule, installation schedule, and device condition.
  6. Assign the deployment to the group of devices you registered with Samsung.
  7. On the Monitor tab, review the campaign summary and status. From the summary, you can edit, cancel, or delete the campaign and open the campaign report. Status data from Samsung refreshes every hour.

You can also review the campaign in the Knox Admin Portal. After you assign the campaign, verify its status on a targeted Samsung device in the Knox E-FOTA app.

Device registration status report

You can view the device registration status for devices registered with Samsung Knox E-FOTA in the Intune admin center. The report refreshes every hour with device status from Samsung.

To view the device registration status report:

  1. Sign in to the Microsoft Intune admin center.
  2. Select Tenant administration > Connectors and tokens > Firmware over-the-air update.
  3. Select Samsung.
  4. Select the Monitor tab to view the device registration status report.
  5. To view the list of devices registered with Samsung, select View devices. The device registration status report shows the following information for each device:
    • Device name
    • Registration status
    • Status detail
    • Last status update (UTC)

Disconnect the Samsung connector

To disconnect the Samsung connector, follow these steps:

  1. Sign in to the Microsoft Intune admin center.
  2. Select Tenant administration > Connectors and tokens > Firmware over-the-air update.
  3. Select Samsung.
  4. Select Disconnect and confirm the disconnection. This action disconnects your Intune tenant from Samsung Knox E-FOTA.

Next step