Applications and Device Policies are failing on Samsung Knox Devices -XenMobile

Applications and Device Policies are failing on Samsung Knox Devices -XenMobile

book

Article ID: CTX227292

calendar_today

Updated On:

Description

Experiencing issues with Samsung KNOX Enabled devices
- Enrolment loop encountered.
- Policies/ Apps Deployment failures.

 

  • If the devices are removed from KNOX KME portal. Reset done and manually enrolled, no issues encountered.

Environment

Citrix is not responsible for and does not endorse or accept any responsibility for the contents or your use of these third party Web sites. Citrix is providing these links to you only as a convenience, and the inclusion of any link does not imply endorsement by Citrix of the linked Web site. It is your responsibility to take precautions to ensure that whatever Web site you use is free of viruses or other harmful items.

Resolution

  • On the KNOX portal under jason removed the port to verify. After removing the port, apps and policies are getting pushed without any issue.

  • Ensure the firewall has exception for the following URLS :

Device’s region

URL

Port

Destination

All

https://gslb.secb2b.com

443

Global load balancer for Knox Mobile Enrollment initiation

All

http://gslb.secb2b.com

80

Global load balancer for Knox Mobile Enrollment initiation on some limited legacy devices

All

umc-cdn.secb2b.com

443

Samsung agent update servers

All

bulkenrollment.s3.amazonaws.com

80

Knox Mobile Enrollment customer EULAs

All

eula.secb2b.com

443

Knox Mobile Enrollment customer EULAs

All

us-be-api-mssl.samsungknox.com

443

Samsung servers for IMEI verification

United States

https://us-segd-api.secb2b.com

443

Samsung Enterprise Gateway for US region

Europe

https://eu-segd-api.secb2b.com

443

Samsung Enterprise Gateway for European region

China

https://china-segd-api.secb2b.com

443

Samsung Enterprise Gateway for China region

 
Important
For legal reasons, Samsung maintains two distinct server groups: Americas and EU.

US (United States) devices must register with a KNOX account on US region. EU devices, as well and devices from any other region except China, which is not supported, must register with a KNOX account on EU region.

Problem Cause

Configuration issues on KNOX portal

Issue/Introduction

The article summarises the steps required to verify if applications and policies are failing to be pushed on Knox enrolled devices

Additional Information

Samsung KNOX Bulk Enrollment