EMM solution

Samsung SDS EMM: full control of the mobile fleet from your own infrastructure

An Enterprise Mobility Management platform for organisations that need local control, verifiable security and deep integration with Samsung Knox. It manages Samsung, Android Enterprise and iOS/iPadOS devices from a single console, deployed on-prem, in a hybrid model or in the cloud.

Soldiers configuring radio equipment at a command post
1
console for Samsung, Android Enterprise and iOS/iPadOS
0
Internet dependencies in air-gap mode with Private Push
2
layers of encryption at rest with Knox DualDAR
+300,000
active devices supported per installation, according to the manufacturer
Deployment model

On-prem, hybrid or cloud: the project decides, not the vendor

With the Samsung EMM platform we can deploy on the client's own infrastructure, in a hybrid architecture or in a cloud managed by Samsung. The model is chosen on the basis of the information classification, the available connectivity and the requirements of the tender specification.

On-prem

Samsung SDS EMM On-Prem

EMM server in the organisation's data centre. Supports isolated networks with no Internet access through SDS Private Push. Recommended for defence, classified information and environments where data sovereignty is mandatory.

Hybrid

Private or government cloud

Console and data on your own infrastructure, with the Knox support services consumed from the cloud through a controlled gateway: firmware distribution with Knox E-FOTA and Knox Asset Intelligence. Clear segmentation of what leaves the organisation and what does not.

Cloud

Samsung cloud EMM (Knox Manage)

Service managed by Samsung for fleets without closed-network restrictions, with rapid start-up and no server maintenance. A suitable option for administrative units or projects with standard availability requirements.

The initial assessment determines the model. It is common to combine on-prem for operational units and cloud for administrative staff within the same organisation.

Certified Samsung SDS EMM Resell Partner badge
Certified partner

Certified Samsung SDS EMM Resell Partner

Blindium is a certified Samsung SDS Resell Partner for its EMM platform: official licensing and a direct line to the manufacturer for support and product evolution.

Architecture

EMM server inside the perimeter, devices under control on any network

The EMM server is installed on the organisation's infrastructure (own data centre, classified enclave or private cloud). The administration console, the database and the policy services never leave the perimeter.

Devices receive policies and commands through SDS Private Push, a private notification service that replaces the public push services of Google and Apple when there is no Internet access. Where connectivity exists, the system can use both channels.

Typical integrations: directory (LDAP/Active Directory), corporate PKI for device and user certificates, SIEM for traceability and mobile threat defence (MTD) tools.

Organisation perimeter EMM console EMM server Database SDS Private Push PKI / Directory SIEM App and firmware repository VPN gateway Managed devices Internet no dependency
fig.On-prem reference architecture with an isolated network
Components

Six parts, all inside your perimeter

Every component is installed on the organisation's own infrastructure. None of them needs an Internet connection to work.

EMM server (central console)

Unified administration of devices, policies, users and applications. Web console for the organisation's administrators, with roles and permissions.

SDS Private Push (Two-way Push)

Bidirectional notification engine on the internal network. Delivers encrypted commands instantly and with acknowledgement, without going through Google or Apple push services.

Knox E-FOTA On-Premises

Local repository for firmware and operating system patches: the version the organisation decides on is tested, approved and rolled out.

Gateway and App Tunnel

Per-app access to the internal network through encrypted tunnels with mutual TLS, without exposing services.

Database

Microsoft SQL Server or Oracle, on the same server or separated in a high-availability cluster.

Integrations

Directory (Active Directory, OpenLDAP, LDAPv3), corporate certificate authority and local SIEM.

Sizing

Single server or multi-server cluster

The same platform is installed in one of two ways, depending on fleet size and availability requirements.

  • Single server EMM, Private Push and database on one machine. Suitable for pilots, testing and small fleets.
  • Multi-server Push Proxy, EMM server and database on separate machines, with high availability. This is the production architecture for large fleets, and it separates the zone exposed to devices from the core.
  • Scale The manufacturer documents installations with more than 300,000 active devices.
SINGLE SERVER Devices EMM server Private Push Database Pilots and small fleets MULTI-SERVER HIGH AVAIL. Devices EXPOSED ZONE Push Proxy CORE EMM server Database Production and large fleets
fig.Single server versus multi-server cluster
Features

Six functional areas, one console

EMM goes beyond classic MDM: in addition to the device, it governs applications, identity, content and advanced security in COPE, COBO and BYOD scenarios.

Device management

Inventory, enrolment, profiles, compliance and remote control of Samsung, Android Enterprise and iOS/iPadOS devices. Remote lock and wipe, geolocation controlled by policy.

Application management

Controlled distribution of corporate and public applications, versions, permissions, allow and block lists, and prevention of unauthorised installations.

Identity and access

Authentication, user and device certificates, access policies conditional on compliance status and directory integration.

Content and data

Separation of corporate information, work containers and content protection with Knox Workspace.

Advanced security

Hardware and system restrictions, encryption, hardening with Knox Platform for Enterprise, tamper detection and automated response.

Operation and support

Remote support with screen sharing, session recording and file exchange. Reporting, auditing and lifecycle automation.

Management models

Corporate control or privacy: it depends on who owns the device

The platform applies a different model depending on who owns the device. In every case corporate data stays separate and under the organisation's control.

Android Enterprise

100% corporate

Fully managed organisation-owned device: control of features and the system, approved applications and no personal space.

Android Enterprise

Corporate with a personal profile

Organisation-owned device with a separate personal space. Policy governs the work profile without seeing private data.

Android Enterprise

BYOD with a work profile

Personal device with an encrypted corporate container. The container can be wiped without touching the rest of the device.

Android (legacy management)

Fleets predating Android Enterprise

Compatibility with legacy devices and deployments, keeping corporate and personal data separate.

iOS · Device Enrollment

Corporate device

Control of features and configuration (camera, screenshots, passcodes, Wi-Fi, VPN, mail) and application deployment.

iOS · User Enrollment

Personal device (BYOD)

Strict separation between personal and corporate data through a Managed Apple ID from Apple Business Manager.

Windows 10 (version 1703 or later) is managed from the same console, according to the manufacturer's data sheet.

Threats

From vulnerability to defence-grade security

Every common mobility risk has a concrete answer in the platform.

VulnerabilitySamsung SDS EMM response
Lost or stolen deviceRemote lock and wipe; remote management of the whole fleet
Leaks through consumer or compromised applicationsUse restricted to approved corporate applications
Data leakage through external storageBlocking of data exfiltration and encryption of corporate information
Communication threats and external attacksPrevention of leaks from the corporate network: managed VPN and per-app tunnels
Leaks into the personal spaceIsolation between the corporate and personal profiles
Unstable rollouts and bugs in internal applicationsMass, controlled rollout of policies and versions to the whole fleet
Access with unauthorised accountsSecure management of the corporate profile and credentials
Mapping taken from the manufacturer's documentation.
Samsung Knox ecosystem

Native Knox integration, from enrolment to firmware

Samsung SDS EMM is designed alongside the Knox security platform, built into the hardware of Galaxy devices. This allows controls to be applied that a generic MDM cannot reach.

  • Knox Mobile Enrollment (KME) Automatic, mandatory enrolment on first boot, with no user intervention, even after a factory reset.
  • Knox DualDAR Two layers of encryption for data at rest with independent keys; the second layer remains encrypted even when the device is unlocked.
  • Knox E-FOTA Firmware version control: the update is tested, approved and deployed when the organisation decides.
  • Galaxy Tactical Edition Devices with binaries and configurations specific to tactical scenarios: stealth mode, night vision, radio integration.
  • NFC provisioning with EMM Connect Regional settings, Wi-Fi and enrolment data transferred to the device by proximity for mass onboarding in the field.
06Operation 05VPN 04Apps and container 03EMM policies 02Enrolment 01Hardware
fig.Layers of control over a Galaxy device
Isolated networks

Air-gap operation: management with no Internet access

On an isolated network there are no Google or Apple push services. SDS Private Push acts as the organisation's own notification server: the EMM delivers commands, policies and applications to devices over the internal network, with no external connection whatsoever.

The Secure Setting feature allows predefined policy sets to be applied in disconnected environments, and applications and firmware are distributed from internal repositories.

This mode is the norm in classified enclaves, on ships, at deployed bases and in the control centres of critical infrastructure.

Closed network EMM + Private Push Devices policies and apps status and compliance Internet no connection
fig.Isolated network with a private notification server
Two ways to run on-prem

Private cloud or total isolation

Within an on-prem deployment there are two configurations, and you can move from one to the other.

Private or government cloud

The EMM server stays on your infrastructure and only the Knox support services (E-FOTA and Knox Asset Intelligence) are consumed from the cloud, through a gateway you control.

100% isolated network (air gap)

All Knox capabilities live inside the on-prem server, including firmware distribution. No connection to public clouds at all: the mode for classified environments.

Field staff

Features for those who operate outside the office

Kiosk mode

Wizard to lock the device to one or more applications, with a restricted interface and hardware.

Shared device

Several users per device, each with their own session through check-in / check-out: each shift's data stays isolated and fewer devices are needed.

Remote support

Diagnosis without physical presence: screen sharing, session recording and file transfer.

Controlled geolocation

Location and geofencing only where policy permits, with traceability of every query.

SecuCamera

Secure photo capture: the image is encrypted and sent to the central server without staying in the device gallery. For inspections, evidence and field operations (additional licence).

Group policies

Sets of security, connectivity and restriction rules assigned by unit, department or role and applied in bulk.

Lifecycle

From onboarding to retirement, every device with full traceability

A managed device passes through four states. The EMM records every transition and applies the corresponding policy automatically.

  • Onboarding Enrolment via KME, NFC or QR code; application of the unit profile; verification of integrity and firmware version.
  • Operation Continuous compliance, application and policy updates, remote support and auditing.
  • Incident Loss, theft or compromise: lock, selective or full wipe, certificate revocation and logging for the report.
  • Retirement Verified secure wipe, removal from Knox and from the inventory, and a retirement certificate for the file.
Onboarding Operation Incident Retirement Managed device
fig.States of a managed device
Operators and MSPs

Ready to operate at scale

Multi-tenant

Management of several organisations from a single installation with strict separation of data and administrators.

Staging and kitting

Samsung devices pre-configured and enrolled before delivery to the destination unit.

Dashboards

Per-tenant dashboards with compliance status, versions and activity.

Modules

Key features and licensed modules

Some capabilities come with the platform and others are licensed separately. We say which is which so the budget holds no surprises.

Included

Two-way Push

End-to-end encrypted commands to devices, executed immediately and with acknowledgement. Suitable for isolated networks with no dependency on public clouds.

Included

Group policies and shared mode

Uniform rules per role and multi-user sessions with check-in / check-out on the same device.

Additional licence

Knox DualDAR and VPN chaining

Two-layer encryption at rest and dual VPN tunnel for communications. The basis of CSfC-style architectures; FIPS 140-2 modules according to the manufacturer.

Additional licence

SecuCamera

Photos encrypted and sent to the central server without passing through the local gallery: leak prevention in the field.

Additional licence · Samsung

Knox E-FOTA

Centralised management of firmware and system updates, via cloud or air gap. Version control so that critical applications keep working.

Additional licence · Galaxy

Mobile Compliance Recording (MCR)

Native on-device recording of calls, SMS and other channels: encrypted, tamper-proof and independent of the carrier and the SIM. Chain of custody and legal hold, designed for MiFID II and for environments that require evidence.

Two-way Push, group policies and shared mode are part of the platform. Knox DualDAR/VPN chaining, SecuCamera, Knox E-FOTA and MCR are licensed separately; Knox E-FOTA and MCR apply to Samsung devices only.

Requirements

Server requirements and supported systems

ItemRequirement
Server operating systemWindows Server 2016, 2019 or 2022
DatabaseMicrosoft SQL Server 2016, 2019 or 2022, or Oracle Database
Identity directoryMicrosoft Active Directory, OpenLDAP or LDAPv3
ArchitectureSingle server (testing and small fleets) or multi-server cluster with high availability (production)
Mobile systemsAndroid 6.0 or later (Android Enterprise), iOS 15 or later and Windows 10 (1703 or later)
Samsung devicesKnox features (KME, DualDAR, E-FOTA, Tactical Edition) on Galaxy devices with Knox
According to the manufacturer's data sheet (September 2026). Exact versions are confirmed during the design of each project.
The manufacturer

Who is behind the platform: Samsung SDS

Samsung SDS has been the Samsung Group's information technology company since 1985: digital transformation, cloud, cybersecurity, enterprise mobility and logistics. Blindium is a certified Resell Partner for its EMM platform.

$10B
Annual revenue (2025)
40
Countries with a direct presence and 59 corporate branches
25,536
Employees worldwide; global headquarters in Seoul
18
Cloud data centres of its own

Corporate figures published by Samsung SDS (2024-2025), reproduced for information. They are not part of any product certification.

Frequently asked questions

About the platform

What does the platform include and what is contracted separately?

The platform includes the console, Private Push (Two-way Push), group policies, shared mode and the management of Android, iOS and Windows. Knox DualDAR and VPN chaining, SecuCamera, Knox E-FOTA and Mobile Compliance Recording are licensed separately, the last two for Samsung devices only. The assessment sets which modules each unit needs.

Does it only work with Samsung devices?

No. It manages Samsung devices, Android Enterprise devices from any manufacturer and iOS/iPadOS from the same console. Knox integration adds further controls on Galaxy devices, but the fleet can be mixed.

What happens if the server has no Internet access?

The system continues to manage devices through SDS Private Push, an internal notification service. This is the intended mode of operation for isolated networks.

Can we combine on-prem and cloud?

Yes. It is common to deploy on-prem for operational units and to use the Samsung cloud EMM for administrative staff. The assessment defines which model applies to each group.

How does it integrate with our directory and our PKI?

Through standard LDAP/Active Directory connectors and certificate issuance protocols (SCEP and similar). The corporate PKI remains the authority; the EMM distributes and renews the certificates on the devices.

Next step

Free MDM/EMM continuity assessment (45 minutes)

A technical session with a specialist to review your situation and return an actionable recommendation. No obligation.

  • Current architecture and number of devices
  • Data criticality and network or cloud constraints
  • Integration with Samsung Knox and mixed fleets
  • Transition options and deployment model (on-prem, hybrid or cloud)