App install fails with "Admin doesn't allow installation from unknown sources" error during Blueprint convergence
Android
When Samsung Knox Mobile Enrollment (KME) devices converge to a Blueprint, app installation fails with the error Admin doesn't allow installation from unknown sources, leaving required apps uninstalled and devices in a non-compliant state.
Why this happens
Samsung KME enrolls devices with a Knox-enforced profile that restricts the Esper Agent from installing apps from sources outside the Google Play Store. Because Esper manages app installation directly through the agent, this Knox restriction blocks the process entirely. Removing the device from the Knox portal and resetting it clears the enforced profile, after which the correct Blueprint permissions allow enrollment to succeed.
Steps to resolve
- Remove the affected devices from your Knox portal. Log in to your Samsung Knox Mobile Enrollment portal, search for the serial numbers of the affected devices, and delete each entry. Removing devices from Knox releases the enforced profile that is blocking the install permission.
-
Factory reset each affected device. From the Esper provisioning screen, tap Reset if the button is available. If it is not, use the hardware key combination for recovery mode on your Samsung model to perform a factory reset.
- Alternative: If the device has an active network connection, apply a temporary Blueprint that re-enables access to Android Settings, then navigate to Settings → General Management → Reset → Factory Data Reset from within the OS instead of using the key combination.
- Confirm the Blueprint includes the correct install permission. In the Esper Console, open Blueprints and locate the blueprint assigned to these devices. Verify that the Install unknown apps permission is granted for the Esper Agent. If it is missing, edit the blueprint to add it and save the change. This permission is what allows the Esper Agent to sideload and manage apps outside the Play Store.
- Verify the permission is active on a test device before re-enrolling the fleet. On a freshly reset device, navigate to Android Settings → Apps & Notifications → Esper Agent → Install unknown apps and confirm that Allow from this source is toggled ON.
- Re-enroll the affected devices using your standard QR code or KME provisioning flow, applying the updated blueprint during enrollment.
Admin doesn't allow installation from unknown sources error. All target apps appear as Installed in Devices & Groups → [Device Name] → Apps within 10 minutes of enrollment completing.
If this doesn't resolve it
Before contacting support, collect the following:
-
If only some devices in the batch fail: Pull the Esper Agent enrollment log from both a failing and a successful device for comparison. On each device, run:
adb logcat -d > esper_agent_log.txt - If the Knox portal shows no conflicting entries: Note the device model, Android firmware version, and Knox enrollment profile XML if available — the restriction may be originating from an OEM-level policy or Samsung firmware setting.
- If the device cannot be factory reset: The device may have a carrier or OEM lock. Collect the Esper Agent log via ADB as above before reaching out.
Contact Esper Support with the logs and device details listed above.
--- **Improved title:** App install fails with "unknown sources" error on Samsung KME devices during Blueprint convergenceStill need help?
If the steps above don't resolve the issue, submit a support ticket with your device model, Android version, Esper Agent version, and a description of what you've already tried — this helps the support team investigate without a follow-up.
Please sign in to leave a comment.
Comments
0 comments