In order to support the unified solution, EMMs will need to do the following:
NOTE –To support the unified solution, EMM agents must leverage Android method to create a managed profile and device owner. Knox creation methods are not valid for the unified solution. Please see the Android EMM guide for details:
The EMM agent, as Device Owner or Profile Owner, needs to activate a Knox License in order to call Knox APIs.
The Unified solution supports two Knox License types:
A Device Owner can activate an ELM license and gain access to Knox standard MDM APIs.
A Device Owner can activate a KLM License and gain access to Knox premium APIs.
A Profile Owner must activate both ELM and KLM licenses in order to gain access to Knox APIs.
The license activation process remains the same in Knox 3.0 as in previous versions of Knox. For details, see the following:
Note: For the COMP configuration where there is both DO and PO privileges on the device only one Knox License activation is required. The package name of DO and PO must be the same.
As per earlier versions of Knox, a device admin can deactivate the KLM license.
The IT admin can reactivate a KLM license in order to continue using Knox.
If a device needs to be repurposed, the IT admin has the following options:
EMM consoles currently provide IT admins with the option to either setup Knox or Android Enterprise on their end users’ devices. IT admins have to pick between Knox or Android configurations.
With unification, IT admins no longer have to pick between Android and Knox. They can set up one configuration for their devices which includes policies from both Knox and Android.
Subsequently, the EMM console needs to provide the IT admin with the following options: