Disable Updates Policy Blocks Samsung One UI Upgrades on Knox-Enabled Devices
Android
Improved Title: Disable Updates policy blocks Samsung One UI upgrades via KnoxWhen you apply a Disable Updates policy in an Esper Blueprint to a Samsung device, both Android OS version upgrades and Samsung One UI layer upgrades are blocked — but only when Samsung Knox is active on the device.
Why this happens
Esper enforces the Disable Updates policy on Samsung hardware by calling Samsung Knox device management APIs directly. When Knox is active, these APIs restrict system update downloads and installations at the OS level, which covers both the underlying Android version and the Samsung One UI layer that sits on top of it. On Samsung devices where Knox is not active or licensed, the Knox API layer is unavailable and the policy cannot be enforced.
Before you begin
Confirm the following before applying the policy:
- The device is a Samsung model with Knox support (for example, Samsung Galaxy S10 FE+).
- Knox is activated and licensed on the device after enrollment.
- The device is enrolled in Esper and assigned to a device group.
How to apply the Disable Updates policy
- In the Esper Console, navigate to Blueprints and select an existing blueprint assigned to your target device group, or create a new one. Applying the policy through a blueprint ensures it is consistently enforced across every device in the group.
- Within the blueprint editor, locate the System Updates section.
- Set the update policy to Disable Updates.
- Save and publish the blueprint.
- Navigate to Devices & Groups → [Group Name], select the Blueprint tab, and apply the updated blueprint to your target device group. This pushes the policy to all enrolled devices in that group.
Important notes
- Knox is required. This policy only takes effect on Samsung devices with active Knox APIs. On non-Samsung devices, update blocking behavior may differ depending on the OEM.
- Policy persists until changed. The Disable Updates policy remains in effect for as long as the blueprint is applied. Changing the policy to Allow Updates or removing the blueprint will re-enable system updates on the device.
- No rollback. This policy prevents future updates only. It does not remove or roll back an OS version that is already installed on the device.
If this doesn't resolve it
If the device continues to receive or install updates after the policy is applied:
- Confirm Knox is active on the device by checking the Knox status in Devices & Groups → [Device Name] → Device Info. The policy cannot be enforced if Knox is inactive or unlicensed.
- Check the blueprint compliance status at Devices & Groups → [Device Name] → Blueprint. A Non-Compliant or Pending status indicates the policy has not been successfully applied to the device.
- If Knox is confirmed active and the blueprint shows as compliant but updates are still occurring, contact Esper Support with the following information:
- Device serial number
- Blueprint ID
- Knox version installed on the device
- A screenshot of the blueprint compliance status from the Esper Console
Still need help?
If the steps above don't resolve the issue, submit a support ticket with your device model, Android version, Esper Agent version, and a description of what you've already tried — this helps the support team investigate without a follow-up.
Please sign in to leave a comment.
Comments
0 comments