# Samsung Knox E-FOTA

> Configure Samsung Knox E-FOTA with Applivery to manage centralized OS updates on Samsung Devices with step-by-step instructions.

Source: https://docs.applivery.com/en/device-management/android/oem-configs/samsung-knox-efota/  •  Last updated: 2026-04-18

**Key topics:** Knox E-FOTA configuration, Applivery policy creation, Knox Service Plugin setup, Device enrollment in E-FOTA, Samsung, Knox E-FOTA, Applivery, Android, Knox Service Plugin, OEMConfig

---

**TL;DR:** Centrally manage Samsung device OS updates using Knox E-FOTA and Applivery by configuring a dedicated Android policy with the Knox Service Plugin.

Samsung Knox E-FOTA allows enterprise IT administrators to centrally control operating system versions and security updates on Samsung Sevices, without requiring any user intervention. This capability enables organizations to validate OS updates in advance, ensure compatibility with internal applications, and deploy security patches on a controlled schedule, significantly improving device stability and security posture across the fleet.

## Configuration

To begin, access the [Samsung Knox Admin Portal](https://samsungknox.com) and sign in using an administrator account with at least the **Common Admin** and **E-FOTA Admin** roles enabled.

:::info
This feature requires a valid **Knox Suite – Enterprise Plan license** in the Samsung Knox E-FOTA Portal. A free trial license can be issued for testing purposes using the **ACTIONS** button in the portal.
:::
![samsung knox](https://docs.applivery.com/int/_r2/media/09ac0a4e-3ad8-478f-9f15-3474973eec71/9b2d4df2-d57f-45a3-baf7-ee4f3b0b5de8.png)

### Preparing Applivery for Knox E-FOTA

To enroll compatible Samsung Devices in Knox E-FOTA through Applivery, you must create a dedicated Android Policy that includes the **Samsung Knox Service Plugin** (**OEMConfig**) application.

**Create a new Policy**

Once in the [**Applivery Dashboard**](https://dashboard.applivery.io/), [create a new Policy](https://docs.applivery.com/en/device-management/general-settings/create-device-policies/) from the **Policies** 1 section. This Policy should be used exclusively for Knox E-FOTA configuration.

Within the Policy, go to the **Apps** 2 section and click the **\+ Add App** button 3.

![add app](https://docs.applivery.com/int/_r2/media/09ac0a4e-3ad8-478f-9f15-3474973eec71/8977cec7-2eb9-4d52-93ae-577c8d0312fb.png)

**Add the Knox Service Plugin**

Search for the **Knox Service Plugin** app (package name: `com.samsung.android.knox.kpu`). Set the **Install Type** to **Force Installed** to ensure the App is automatically installed on any Device associated with the Policy.

**Configure the Knox Service Plugin**

Once the App appears in the list, click on it to expand all the managed properties and **assign a name to the configuration profile** 4.

![knox service plugin](https://docs.applivery.com/int/_r2/media/09ac0a4e-3ad8-478f-9f15-3474973eec71/580d3f7f-9075-4570-b98b-9ce003eabc06.png)

:::info
By default, the Knox Service Plugin app is hidden from users when managed configuration is applied. For testing or validation purposes, visibility can be enabled by activating the **Debug** 5 option within the managed configuration.
:::

### Enabling Firmware and E-FOTA controls

**Enable Device Policy Controls**

Continue scrolling to the **Do Policies** section and **Enable Device policy controls** 6.

![enable device policy controls](https://docs.applivery.com/int/_r2/media/09ac0a4e-3ad8-478f-9f15-3474973eec71/da04c7ce-bb29-4c25-83c0-7ad7273e8b06.png)

**Enable Firmware Controls and E-FOTA client installation & launch**

Then, in the **Do Fota Update** section, activate both **Enable firmware controls** 7 and **Enable E-FOTA client installation & launch** 8.

**Configure OTA Updates (Optional)**

Optionally, you can control whether Devices are allowed to receive standard OTA updates outside of Knox E-FOTA by configuring the **Allow firmware update over-the-air** 9 setting.

![do fota update](https://docs.applivery.com/int/_r2/media/09ac0a4e-3ad8-478f-9f15-3474973eec71/04e58702-3d4c-4fec-a1c9-fae4f2310e10.png)

**Assign the Policy**

Once completed, assign this Policy to the relevant Samsung Devices using your preferred assignment method.

:::info
Ensure this Knox E-FOTA Policy has **a higher priority** than your regular Android Policy to avoid configuration conflicts.
:::

## Device registration and Campaign management

After the Policy is applied, the Knox Service Plugin OEMConfig App is installed along with its managed configuration. This triggers the automatic installation of the **Knox E-FOTA Client**, and Devices are silently registered in the **Samsung Knox E-FOTA Portal**.

![samsung knox all devices](https://docs.applivery.com/int/_r2/media/09ac0a4e-3ad8-478f-9f15-3474973eec71/108bba6a-b713-4d61-8900-023012274a2c.png)

From this point forward, E-FOTA administrators can **create and manage update campaigns per device model**, **enforce specific OS or firmware versions**, and **apply update constraints** according to organizational requirements.

For additional information about Knox E-FOTA capabilities, refer to the [official Samsung documentation](https://docs.samsungknox.com/admin/knox-efota/).

For detailed instructions on creating and managing campaigns, refer [to this article](https://docs.samsungknox.com/admin/knox-efota/features/create-a-campaign/create-a-campaign/).
