Defence and Armed Forces

Managed tactical mobility, with control inside your network

Deployed units need devices that work without coverage, protect classified information if they fall into the wrong hands and respond to orders from command within seconds. Blindium deploys Samsung SDS EMM on the network of the agency or unit, with Galaxy Tactical Edition, DualDAR dual encryption and mission-based policies.

Personnel setting up a communications antenna on a vehicle at dusk
Challenges

What a cloud MDM does not solve in defence

Isolated or degraded networks

Enclaves without Internet, intermittent satellite links, EMCON. Management cannot depend on public push services or on a console in a third party's cloud.

Classified information on the device

A device lost in an area of operations cannot be allowed to become a leak. Two-layer encryption, remote and emergency wipe, and evidence that the wipe was executed are required.

Evidence for accreditation

The accreditation authority asks for certifications (Common Criteria, STIG, FIPS) and traceability of every administrative action, not sales descriptions.

Integration with tactical systems

Radios, PTT, secure messaging, maps and situational awareness applications must coexist on the same device under a common policy.

Capabilities

What Blindium brings to a unit

On-prem EMM server on the agency's network

Console, database and policies inside the accredited perimeter. Air-gap management through SDS Private Push and Secure Setting to apply profiles without connectivity.

Galaxy Tactical Edition

Samsung devices with binaries specific to tactical use: stealth mode (no emissions or light), night vision compatibility, integration with radios and military accessories.

Knox DualDAR

Two independent layers of encryption for data at rest. The inner layer remains encrypted even when the device is unlocked, with separate keys and its own wipe policy.

Profiles by unit, mission and classification

Sets of policies, applications and certificates assigned by group. A device can change profile when it changes mission without re-enrolling.

Response to loss or compromise

Lock, selective or full wipe, certificate revocation and user-initiated emergency wipe. Every action is logged for the report.

Managed communications and encryption

Always-on and per-app VPN, dual tunnel for CSfC-style architectures, certificate distribution from the agency's PKI and validated cryptographic modules.

Silhouetted soldier keeping watch from a high position
Deployed units

The mission does not wait for coverage

Mission profiles, two-layer encryption and emergency wipe: the device is ready before leaving and stays under control even if the link is lost.

Request a security briefing

Priority sector

Designed for the Armed Forces and deployed units

Tactical mobility with local control: the EMM server is installed on the network of the unit or agency and continues to manage the devices with no Internet access. Samsung Galaxy Tactical Edition devices, DualDAR dual encryption and mission-based policies.

Organisation perimeter EMM console EMM server Database SDS Private Push PKI / Directory SIEM App and firmware repository VPN gateway Managed devices Internet no dependency
fig.Command post with an operator monitoring the situation on screen
Scenarios

Three typical situations

  1. Scenario A

    Base or barracks with a classified network

    EMM server in the accredited data centre, with no Internet access. Devices enrolled via KME and provisioned by NFC in the equipment store. Firmware updates approved with Knox E-FOTA from an internal repository.

  2. Scenario B

    Deployed unit with intermittent connectivity

    Devices operate with the last policy received and synchronise when a link is available. Situational awareness and secure messaging applications in a container encrypted with DualDAR. User-initiated emergency wipe.

  3. Scenario C

    Naval platform or isolated facility

    Complete EMM installation on board or at the facility, with local Private Push. Task and maintenance management on devices shared across shifts. Synchronisation with the central node on docking or over a scheduled link.

Evidence

Documentation delivered to the accreditation authority

  • NIAP Common Criteria certificate under MDM-PP v4.0 and its validation report.
  • DISA STIG for Samsung SDS EMM as applied, and the resulting configuration checklist.
  • Manufacturer references to NSA CSfC and FIPS 140-2 validation of the cryptographic module, with their source documents.
  • Map of controls against the ENS (High category) and the CCN-STIC guides for mobile devices, indicating which control is covered by the platform and which by procedure.
  • Reference architecture, network flow matrix and pilot test plan.

Blindium words these documents as "aligned with" or "helps to comply with" where no accredited certification exists. No certification is claimed that cannot be verified against an official source.

Frequently asked questions

Common questions from units

Can the platform operate without any external connection, including to Samsung?

Yes. In air-gap mode the EMM server, SDS Private Push and the application and firmware repositories reside on the agency's network. No connection to Samsung, Google or Apple services is required to manage the devices.

What about licensing on an isolated network?

Licensing is handled with licence files imported into the console. There is no mandatory online check. The details are agreed during the architecture phase.

Can it be integrated with our radio or PTT system?

The platform manages the device and the applications; third-party PTT and secure messaging solutions are distributed and configured from the EMM. The manufacturer documents deployments with PTT and messaging orchestration in military environments.

Who administers the console?

The agency's own staff, with defined roles and permissions. Blindium trains the administrators, delivers the procedures and can provide second-line support under whatever model the accreditation requires.

Deployment model

On-prem, hybrid or cloud: the project decides, not the vendor

With the Samsung EMM platform we can deploy on the client's own infrastructure, in a hybrid architecture or in a cloud managed by Samsung. The model is chosen on the basis of the information classification, the available connectivity and the requirements of the tender specification.

On-prem

Samsung SDS EMM On-Prem

EMM server in the organisation's data centre. Supports isolated networks with no Internet access through SDS Private Push. Recommended for defence, classified information and environments where data sovereignty is mandatory.

Hybrid

Private or government cloud

Console and data on your own infrastructure, with the Knox support services consumed from the cloud through a controlled gateway: firmware distribution with Knox E-FOTA and Knox Asset Intelligence. Clear segmentation of what leaves the organisation and what does not.

Cloud

Samsung cloud EMM (Knox Manage)

Service managed by Samsung for fleets without closed-network restrictions, with rapid start-up and no server maintenance. A suitable option for administrative units or projects with standard availability requirements.

The initial assessment determines the model. It is common to combine on-prem for operational units and cloud for administrative staff within the same organisation.

Next step

Request a security briefing

A technical session with a specialist to review your situation and return an actionable recommendation. No obligation.

  • Current architecture and number of devices
  • Data criticality and network or cloud constraints
  • Integration with Samsung Knox and mixed fleets
  • Transition options and deployment model (on-prem, hybrid or cloud)