Samsung Knox Manage MDM
Samsung Knox Suite is an all‑in‑one, enterprise mobility management and security platform designed to help organizations secure, deploy, manage, and maintain Samsung devices at scale throughout their entire lifecycle. It is built on Samsung’s hardware‑backed security architecture, integrated directly into supported Galaxy smartphones, tablets, and rugged devices.
Features
- Easy Onboarding to provide users with automated device enrolment
- App distribution and configuration
- Reporting for in depth visibility and control of managed devices
- Remote device locking
- Location Tracking
- Kiosk Mode
- Event based policy enforcement
- Pre-configuration of device settings
- Multiple OS support
- Granular over the air Android OS version control & update
Benefits
- Defence-Grade Security (Built-in)
- Comprehensive Data Protection (AES-256 encryption and containerisation)
- Instant Deployment (Knox Mobile Enrollment)
- Advanced Remote Support - control for support teams
- Granular Device & App Management, hundreds of policies and controls
- Kiosk Mode Customisation
- Real-time Device Tracking & Geofencing
- Remote Data Wiping & Lost Mode
- Actionable Device Analytics
- Stay compliant without causing app compatibility issues
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
2 6 0 5 3 0 1 0 1 2 3 6 9 6 9
Contact
CW Systems Integration Limited
Robin Tyerman
Telephone: 07840839576
Email: robin.tyerman@cwsisecurity.com
About your service
- Service categories
-
Systems Infrastructure Software
Endpoint management
Output management
- Device Management
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
-
Knox E_FOTA
Knox Asset Intellegence
Knox Configure
Knox Capture
Knox Remote Control
Knox Authentication Manager. - Cloud deployment model
- Public cloud
- Service constraints
- For stable service, we recommend to set the user count under 100,000 per tenant which is the unit of Knox Manage service
- System requirements
-
- Microsoft Windows XP and higher
- MacOS 13 (Ventura) and higher
- Google Chrome version 41 and higher
- Mozilla Firefox version 37 and higher
- Microsoft Edge version 95 and higher
User support
- Email or online ticketing support
- Yes
- Support response times
- P1 & P2 Respond within 15 minutes P3 Respond within 30 minutes P4 Respond within 60 minutes
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), 7 days a week
- Web chat support accessibility standard
- None or don’t know
- How the web chat support is accessible
- Currently meets WCAG 2.2AA standards with our platform provider, Atlassian, actively working to achieve WCAG 2.1AA as soon as possible
- Web chat accessibility testing
- Testing completed by our ITSM platform provider Atlassian
- Onsite support
- Yes, at extra cost
- Support levels
- Assurance Support provides simple break fix support with the addition of 8 hours per annum Experts on Demand for advice, problem solving and minor Professional Services/Technical tasks. Retained Expertise is pre-packaged block of professional services time that can be easily consumed and used across all areas of our expertise during a 12 month period. Managed Service contracts provide a complete proactive service, providing break-fix support, platform management, change requests and 16 hours of experts on demand. Services can be provided during Standard Business Hours, Extended Business Hours and 24x7x365. All managed service customers are allocated a Service Assurance Manager and a Technical Account Manager.
- Support available to third parties
- Yes
- AI chatbot
- No
Onboarding and offboarding
- Getting started
- CWSI provides a full range of professional services from consulting, health checks and assessments to implementation & configuration of the Ivanti Neurons MDM platform. We work with our customers to help define their security and compliance strategies, creating a roadmap that aligns to industry best practice standards. We also offer migration services to support customers moving their devices from an existing MDM platform. Training services are available for customers administrators or a range of support and managed services is available to compliment customers own IT Teams capabilities.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- Customer IT-admin Can Extract device information and configuration data in Portal
- End-of-contract process
- At the end of a contract customers have 30 days grace to remove devices before the Samsung platform is inaccessible. The customer is responsible for extracting any data and configuration information they require from the platform before this period ends. If the customer requires any assistance with migration activities, this can be provided by CWSI as a chargeable professional services activity.
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- Service support is provide by CWSI's managed service team utilising our JIRA ITSM platform
- Accessibility standards
- None or don’t know
- Description of accessibility
- Our ITSM platform currently meets WCAG 2.2AA standards and our JIRA ITSM platform provider, Atlassian, is actively working towards WCAG 2.2AA standards as soon as possible.
- Accessibility testing
- Testing completed by our JIRA platform provider Atlassian.
- API
- Yes
- What users can and can't do using the API
-
Full description here:
https://docs.samsungknox.com/dev/knox-manage/api/ - API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- API sandbox or test environment
- No
- Customisation available
- No
Scaling
- Independence of resources
- By default, when the load spikes, the Knox Manage servers are configured to auto‑scale out, ensuring availability.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Licence consumption
- Reporting types
-
- Real-time dashboards
- Regular reports
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller providing extra support
- Organisation whose services are being resold
- Samsung
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
- Other
- Other data at rest protection approach
- Managed by a third party (Data is encrypted by default using the features provided by AWS and stored in AWS Storage.)
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
- Data Erasure
Data importing and exporting
- Data export approach
- Customer IT-admin can extract device information and configuration data in Portal
- Data export formats
-
- CSV
- Other
- Other data export formats
- .XLS
- Data import formats
-
- CSV
- Other
- Other data import formats
- .XLS
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- Not Published
- Approach to resilience
-
Knox Manage leverages multiple AWS Availability Zones (AZs) so that the service can continue operating without interruption even if a disaster occurs.
The Recovery Point Objective (RPO) and Recovery Time Objective (RTO) are each 5 minutes.
AWS places several AZs within the same region, keeping the distance between AZs on the order of a few kilometers (roughly 5 – 50 km). The exact distances and locations are not disclosed for security reasons. - Outage reporting
- Via Samsung Knox Console and email alerts
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- Access is restricted by Roles and Groups within the solution to ensure only those authorised can access the system via management interfaces and support channels
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
- Multi-Factor Authentication (MFA)
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- Other
- Other security governance standards
- SOC2
- Information security policies and processes
- The policy of the information security department of Samsung SDS
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- After sufficient testing in the stage environment in advance, the change is carried out with the approval of the authorized manager, including the purpose of the work, detailed plans, and minutes of the pre-change review, and is completed by checking after the work.
- Vulnerability management type
- Undisclosed
- Vulnerability management approach
- We scan for open-source security vulnerabilities daily using tools, and identify and address vulnerabilities through regular penetration testing and before release.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
Based on the list of security vulnerabilities provided by the information protection organization within the company and the recommendations for measures provided by AWS, the target that needs to be applied to the service is selected, and the application plan is established according to the priority and impact.
In addition, as one of the SOC2 inspection items, risk factors are identified in advance every year, and action plans are established and measures are taken. - Incident management type
- Supplier-defined controls
- Incident management approach
- With notice service https://status.samsungknox.com/
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 2.5%
- Between £2,500,001 and £5,000,000
- 3.75%
- Over £5,000,001
- 5%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- BSI
- ISO/IEC 27001 accreditation date
- Thursday 25 April 2019
- What the ISO/IEC 27001 doesn’t cover
- Nothing
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- None of the criteria
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- E643ad5f-ba03-4c75-a554-5a44532480e6
- Other security certifications
- Yes
- Any other security certifications
- Cybersecurity Made in Europe (CSME)
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Actions to invest in the physical and mental health and wellbeing of the contract workforce
-