Application: Nomid MDM
Document: V1.0.0
Last updated: 02/07/2026
Editorial owner: Nomid MDM Documentation
Last editorial review: 02/07/2026
Editorial language: en-US
Samsung Knox Mobile Enrollment (KME) is a Samsung service designed to facilitate the registration and initial setup of the brand's Android devices, especially in corporate environments. Through KME, it's possible to pre-define a management profile that will be automatically applied to the device as soon as it's turned on for the first time (or after a factory reset) and connected to the internet.
This process allows the device to be automatically associated with an enterprise mobility management (MDM) solution, such as Nomid MDM, without the need for manual intervention from the user or IT team during the initial setup.
This document aims to present, in detail, how KME works, the necessary steps to create and apply a provisioning profile, the available methods for associating devices, and how to use the QR Code to facilitate activation. The material is intended for technical teams who wish to understand the end-to-end process and ensure a correct and efficient implementation of corporate management on Samsung devices.
Important: Knox Admin Portal screens change periodically, and the screenshots in this guide use the English interface. Confirm the current field names before deployment at scale.
- A corporate account with access to Knox Admin Portal and Knox Mobile Enrollment.
- Compatible Samsung devices and a region where KME is available.
- A Samsung-approved reseller for OOBE, or devices running Android 10 or higher for QR code enrollment.
- Access to enrollment data supplied by Nomid, plus a validated pilot policy.
- Required firewall exemptions for communication with Samsung and Google services.
Before creating the KME profile, generate or copy the data in Nomid:
- Open New device and choose Android Company.
- Select the validated pilot policy.
- Open the automated enrollment option for Samsung KME.
- Copy the EMM agent address and the JSON containing the enrollment token without changing property names or structure.
The token, JSON, and QR Code are enrollment credentials. Store them only in an approved location, do not send them in open chats or tickets, limit printed QR codes to the usage window, and regenerate enrollment if leakage, copy error, or improper use is suspected. If the QR includes Wi-Fi, also treat SSID and password as sensitive data.
- Access the Knox portal: https://portal.samsungknox.com. You need to have a Samsung Knox account with KME activated.
- Go to "Knox Mobile Enrollment" > "Profiles".
- This is the section where you will create and manage device provisioning profiles.
- Click "Create profile" to start creating the new profile.
- Choose "Android Enterprise" type.
- This configures the device as fully managed (Device Owner), ideal for corporate use.
- Profile Name: Profile identifier name. Use something descriptive like "Nomid Android - Sales Team".
- Company Name: Company name that will be displayed on the device during enrollment.
- Support Email/Phone: Contact details for support, which will be presented to the user if there are issues.

Profile creation screen with fields filled in
- Choose MDM: Select "Nomid MDM" if listed. Otherwise, select "Other".
- APK: Provide the public link to the Nomid MDM agent APK. If using the default Android Enterprise agent, the default URL is provided by the system itself.
- MDM Server URI: Leave blank, unless Nomid provides a custom URI.

APK and URI configuration screen
Enter the JSON provided by Nomid, which contains the enrollment token:
{
"com.google.android.apps.work.clouddpc.EXTRA_ENROLLMENT_TOKEN": "ABCDEF123"
}
This token links the device to your organization in Nomid MDM.
If the token expires, is replaced in Nomid, or belongs to another policy/company, the device may not appear in the correct inventory. When in doubt, generate a new enrollment and update the KME profile before starting the batch.

JSON input screen
- Click "Add QR Code".
- Check "Also allow QR enrollment for devices not uploaded" to allow enrollment of devices not purchased from official resellers.
- Optionally, add Wi-Fi network details (SSID, security, password) to facilitate automatic connection.

QR Code configuration screen
- Click "Create" to save the profile.
- Make a note of the profile name to link it to devices later.
¶ Step 2: Generating and Using the QR Code
- Access the created profile and locate the "QR Code" option.
- Download or print the QR Code.
This code contains:
- The KME profile identifier
- The enrollment token (JSON)
- Wi-Fi settings (if provided)

QR Code generated in the portal
Use this QR to enroll devices directly, even if they are not pre-loaded in KME.
- Devices purchased from authorized Samsung partners automatically appear in the KME console.
- QR code: enrolls Samsung devices running Android 10 or higher into the EMM, including devices not previously uploaded by a reseller when that profile option is enabled.
- Knox Deployment App: may be available for specific Samsung workflows, depending on device compatibility and the subscribed service.
Customer administrators should not treat CSV upload as direct KME registration. In the standard flow, an approved reseller uploads device identifiers and the administrator approves the batch in Knox Admin Portal.

Portal screen with device list
- Access the "Devices" tab in the KME portal.
- Select the desired devices.
- Click on "Assign profile" and select the created profile.
In the details panel, confirm the selected profile and save. For large fleets, use the portal's bulk actions and validate a sample before applying the change to the entire inventory.
Note: Devices enrolled via QR Code with permission for non-pre-registered devices automatically receive the profile.
- Turn on the device and select the language.
- On the welcome screen, draw the '+' sign with your finger to activate the QR reader.
The KME flow runs during Android initial setup. Use a new or factory-reset device only after backup, asset-owner authorization, and validation of applicable account/FRP handling.

- Point the camera at the QR Code.
- Connect to the internet (Wi-Fi or SIM card with data).
- The MDM app is automatically downloaded and installed.
- The device enrolls in Nomid MDM, with or without user interaction (as configured).
- Confirm that the token/JSON used in KME is the same one generated in Nomid for the selected policy.
- Confirm that the expected enrollment type is Device Owner/Fully managed.
- Check whether the APK or agent used is correct for the approved flow.
- After the first device, confirm in Devices that the equipment appeared in the correct company and policy before expanding the batch.
If necessary, consult Nomid technical support to confirm the data.
To understand where to create policies and monitor enrolled equipment, see Policies and Devices.
¶ Step 7: Validation and Troubleshooting
- Device not appearing in Nomid:
- Check if the token is correct and still valid
- Authentication error:
- Confirm login and password (if required) or regenerate the token
- Device ignores KME:
- Check if a complete factory reset was performed and if the device is online
- QR scanning error:
- Incorrect generation or unchecked permissions in the profile
This guide provides a detailed step-by-step process for automatically configuring Samsung devices with Nomid MDM via KME.
Benefits include:
- Reduced manual effort
- Ensured compliance and security
- Agility in the activation process