App installation blocked on Samsung devices after Knox MDM migration: remove Knox profiles
Android
If you've migrated Samsung devices from Samsung Knox MDM to Esper and app installation is now failing, you likely have a residual Knox configuration profile still active on your devices. This article explains how to remove the Knox profile and re-provision your devices so app installation works correctly.
Before you begin
This issue occurs when:
- Your Samsung devices were previously enrolled in Samsung Knox MDM
- You migrated those devices to Esper without removing the Knox configuration profile from the Samsung Knox Mobile Enrollment (KME) portal
- App installation fails with a package permission error, or the Install Unknown Apps toggle is blocked and unavailable
- Remote Viewer sessions don't connect
You'll need administrator access to the Samsung Knox Mobile Enrollment (KME) portal at https://www.samsungknox.com/en/solutions/it-solutions/knox-mobile-enrollment.
Step 1: Remove Knox profiles from the KME portal
- Log in to the Samsung Knox Mobile Enrollment (KME) portal using your organization's Knox administrator credentials.
- Locate each affected device by its IMEI or serial number.
- Remove or disassociate all Knox configuration profiles from the affected devices. Ensure no active MDM profile points to the previous Knox MDM enrollment endpoint.
Step 2: Factory reset the device
If the Knox profile cannot be removed remotely from the KME portal, factory reset the device to clear the Knox enrollment state completely. Perform the factory reset after attempting to remove the Knox profile in the KME portal.
Step 3: Re-provision the device to Esper
- Re-provision the device using the standard QR code provisioning method.
- If the standard QR code fails, use the legacy/toggled QR code available in the Esper Console as a fallback.
Step 4: Update the Esper Agent
- In the Esper Console, go to Devices & Groups → [Device Name] → Compliance Policy / Software Updates.
- Update the Esper Agent to the latest available version. For detailed instructions, see Deploying Esper Software Updates.
Step 5: Retry app installation
- Go to Devices & Groups → [Device Name] → Apps → Install.
- Install the target app.
- Confirm the app shows status Installed in the Esper Console app inventory for the device.
- Test Remote Viewer to confirm it establishes a session successfully.
If app installation still fails
If you've removed the Knox profiles, factory reset the device, and re-provisioned it to Esper, but app installation continues to fail:
- Pull Esper Agent logs from the device using one of these methods:
- Via console: Devices & Groups → [Device Name] → Actions → Upload Logs
- Via ADB:
adb shell logcat -d > dpc_logs.txtand filter forPackageInstallorEsper Agenttags
- Check whether
REQUEST_INSTALL_PACKAGESis still being denied in the logs. This may indicate a secondary Knox policy or Samsung firmware-level restriction specific to your device model. - If the AutoBlocker setting is expected but absent from your device UI, your Samsung device's regional firmware variant may not support this setting.
Still need help?
If you've completed all the steps above and continue to experience issues, contact Esper Support. provide:
- Your device serial number and IMEI
- The Esper Agent version
- Esper Agent logs (from the steps above)
- Device firmware build number and region code
- Confirmation that the Knox profile has been removed from the KME portal
Please sign in to leave a comment.
Comments
0 comments