Migrating devices from third-party kiosk software to Esper: technical limitation and alternatives
Android
This article explains why you cannot remotely migrate devices from third-party kiosk software (such as Fully Kiosk) to Esper, and outlines your options for moving forward with your deployment.
Why remote migration isn't supported
Esper requires Device Owner privileges to manage an Android device. When a third-party kiosk app is installed as a standard application (not as Device Owner), Esper has no way to remotely access the device, remove the existing software, or claim Device Owner rights. There is no remote management channel available until Esper is already enrolled on the device.
This is a fundamental limitation of Android Enterprise security architecture—you must either have physical access to the device or use a pre-existing remote management capability to move forward.
Before you begin
You will need one of the following:
- Physical access to each device to perform a factory reset, or
- A way to trigger a remote factory reset through your existing kiosk software (if that feature is available), or
- A plan to have on-site personnel perform factory resets
For Samsung devices, you can streamline re-enrollment using Knox Mobile Enrollment (KME).
Step 1: Check if your kiosk software supports remote factory reset
Log into your third-party kiosk software's admin portal and determine whether it has a remote wipe or factory reset command. If it does, you can trigger resets without physical access to each device. If not, you will need on-site staff or physical access to perform manual resets.
Step 2: For Samsung devices, register them in Knox Mobile Enrollment
Samsung devices can use Knox Mobile Enrollment (KME) to automate enrollment into Esper after a factory reset.
- Go to the Knox Mobile Enrollment portal
- Upload the IMEI or serial numbers of all Samsung devices you plan to migrate
- Configure the KME profile to enroll devices into Esper. See Esper Console → Provisioning Templates → Knox Mobile Enrollment for setup instructions
- Complete this registration before you trigger any factory resets
Step 3: Perform factory resets
Choose one of the following approaches:
- Remote reset: If your kiosk software supports remote factory reset, trigger it for all devices through the vendor's admin portal.
- Manual reset: If remote reset is not available, have on-site personnel perform a factory reset on each device by navigating to Settings → General Management → Reset → Factory Data Reset
Step 4: Verify enrollment in Esper
After factory reset and first boot, devices registered in KME will automatically receive the Esper provisioning profile and enroll into your enterprise.
Confirm enrollment by going to Esper Console → Devices & Groups and checking that:
- All devices appear in your device list
- Each device shows status Online
- The correct Blueprint is applied
Alternative: QR code provisioning without KME
If KME is not suitable for your deployment, on-site staff can manually enroll devices using a QR code after factory reset.
- In the Esper Console, go to Provisioning Templates → [Your Template Name] → Download QR Code
- After factory reset, have on-site personnel open the device setup wizard and scan the QR code when prompted
- The device will enroll into Esper and download your Blueprint configuration
Troubleshooting
KME enrollment fails after factory reset: Verify that device serial numbers or IMEIs were correctly uploaded to the Knox portal before the factory reset was triggered. KME enrollment must be registered in advance—devices won't be recognized if registration occurs after a reset.
Device remains in admin or kiosk mode: Some kiosk apps configure Device Owner or Device Admin privileges. If so, a factory reset is mandatory. You can confirm this by checking Settings → General Management → Device Admin Apps before reset to see what software has elevated privileges.
Still need help?
If you need assistance planning your migration or configuring KME, contact Esper Support. Our team can help you determine the best path forward for your deployment size and on-site access constraints.
Please sign in to leave a comment.
Comments
0 comments