Samsung SDS EMM: full control of the mobile fleet from your own infrastructure
An Enterprise Mobility Management platform for organisations that need local control, verifiable security and deep integration with Samsung Knox. It manages Samsung, Android Enterprise and iOS/iPadOS devices from a single console, deployed on-prem, in a hybrid model or in the cloud.

On-prem, hybrid or cloud: the project decides, not the vendor
With the Samsung EMM platform we can deploy on the client's own infrastructure, in a hybrid architecture or in a cloud managed by Samsung. The model is chosen on the basis of the information classification, the available connectivity and the requirements of the tender specification.
Samsung SDS EMM On-Prem
EMM server in the organisation's data centre. Supports isolated networks with no Internet access through SDS Private Push. Recommended for defence, classified information and environments where data sovereignty is mandatory.
Private or government cloud
Console and data on your own infrastructure, with the Knox support services consumed from the cloud through a controlled gateway: firmware distribution with Knox E-FOTA and Knox Asset Intelligence. Clear segmentation of what leaves the organisation and what does not.
Samsung cloud EMM (Knox Manage)
Service managed by Samsung for fleets without closed-network restrictions, with rapid start-up and no server maintenance. A suitable option for administrative units or projects with standard availability requirements.
The initial assessment determines the model. It is common to combine on-prem for operational units and cloud for administrative staff within the same organisation.

Certified Samsung SDS EMM Resell Partner
Blindium is a certified Samsung SDS Resell Partner for its EMM platform: official licensing and a direct line to the manufacturer for support and product evolution.
EMM server inside the perimeter, devices under control on any network
The EMM server is installed on the organisation's infrastructure (own data centre, classified enclave or private cloud). The administration console, the database and the policy services never leave the perimeter.
Devices receive policies and commands through SDS Private Push, a private notification service that replaces the public push services of Google and Apple when there is no Internet access. Where connectivity exists, the system can use both channels.
Typical integrations: directory (LDAP/Active Directory), corporate PKI for device and user certificates, SIEM for traceability and mobile threat defence (MTD) tools.
Six parts, all inside your perimeter
Every component is installed on the organisation's own infrastructure. None of them needs an Internet connection to work.
EMM server (central console)
Unified administration of devices, policies, users and applications. Web console for the organisation's administrators, with roles and permissions.
SDS Private Push (Two-way Push)
Bidirectional notification engine on the internal network. Delivers encrypted commands instantly and with acknowledgement, without going through Google or Apple push services.
Knox E-FOTA On-Premises
Local repository for firmware and operating system patches: the version the organisation decides on is tested, approved and rolled out.
Gateway and App Tunnel
Per-app access to the internal network through encrypted tunnels with mutual TLS, without exposing services.
Database
Microsoft SQL Server or Oracle, on the same server or separated in a high-availability cluster.
Integrations
Directory (Active Directory, OpenLDAP, LDAPv3), corporate certificate authority and local SIEM.
Single server or multi-server cluster
The same platform is installed in one of two ways, depending on fleet size and availability requirements.
- Single server EMM, Private Push and database on one machine. Suitable for pilots, testing and small fleets.
- Multi-server Push Proxy, EMM server and database on separate machines, with high availability. This is the production architecture for large fleets, and it separates the zone exposed to devices from the core.
- Scale The manufacturer documents installations with more than 300,000 active devices.
Six functional areas, one console
EMM goes beyond classic MDM: in addition to the device, it governs applications, identity, content and advanced security in COPE, COBO and BYOD scenarios.
Device management
Inventory, enrolment, profiles, compliance and remote control of Samsung, Android Enterprise and iOS/iPadOS devices. Remote lock and wipe, geolocation controlled by policy.
Application management
Controlled distribution of corporate and public applications, versions, permissions, allow and block lists, and prevention of unauthorised installations.
Identity and access
Authentication, user and device certificates, access policies conditional on compliance status and directory integration.
Content and data
Separation of corporate information, work containers and content protection with Knox Workspace.
Advanced security
Hardware and system restrictions, encryption, hardening with Knox Platform for Enterprise, tamper detection and automated response.
Operation and support
Remote support with screen sharing, session recording and file exchange. Reporting, auditing and lifecycle automation.
Corporate control or privacy: it depends on who owns the device
The platform applies a different model depending on who owns the device. In every case corporate data stays separate and under the organisation's control.
100% corporate
Fully managed organisation-owned device: control of features and the system, approved applications and no personal space.
Corporate with a personal profile
Organisation-owned device with a separate personal space. Policy governs the work profile without seeing private data.
BYOD with a work profile
Personal device with an encrypted corporate container. The container can be wiped without touching the rest of the device.
Fleets predating Android Enterprise
Compatibility with legacy devices and deployments, keeping corporate and personal data separate.
Corporate device
Control of features and configuration (camera, screenshots, passcodes, Wi-Fi, VPN, mail) and application deployment.
Personal device (BYOD)
Strict separation between personal and corporate data through a Managed Apple ID from Apple Business Manager.
Windows 10 (version 1703 or later) is managed from the same console, according to the manufacturer's data sheet.
From vulnerability to defence-grade security
Every common mobility risk has a concrete answer in the platform.
| Vulnerability | Samsung SDS EMM response |
|---|---|
| Lost or stolen device | Remote lock and wipe; remote management of the whole fleet |
| Leaks through consumer or compromised applications | Use restricted to approved corporate applications |
| Data leakage through external storage | Blocking of data exfiltration and encryption of corporate information |
| Communication threats and external attacks | Prevention of leaks from the corporate network: managed VPN and per-app tunnels |
| Leaks into the personal space | Isolation between the corporate and personal profiles |
| Unstable rollouts and bugs in internal applications | Mass, controlled rollout of policies and versions to the whole fleet |
| Access with unauthorised accounts | Secure management of the corporate profile and credentials |
Native Knox integration, from enrolment to firmware
Samsung SDS EMM is designed alongside the Knox security platform, built into the hardware of Galaxy devices. This allows controls to be applied that a generic MDM cannot reach.
- Knox Mobile Enrollment (KME) Automatic, mandatory enrolment on first boot, with no user intervention, even after a factory reset.
- Knox DualDAR Two layers of encryption for data at rest with independent keys; the second layer remains encrypted even when the device is unlocked.
- Knox E-FOTA Firmware version control: the update is tested, approved and deployed when the organisation decides.
- Galaxy Tactical Edition Devices with binaries and configurations specific to tactical scenarios: stealth mode, night vision, radio integration.
- NFC provisioning with EMM Connect Regional settings, Wi-Fi and enrolment data transferred to the device by proximity for mass onboarding in the field.
Air-gap operation: management with no Internet access
On an isolated network there are no Google or Apple push services. SDS Private Push acts as the organisation's own notification server: the EMM delivers commands, policies and applications to devices over the internal network, with no external connection whatsoever.
The Secure Setting feature allows predefined policy sets to be applied in disconnected environments, and applications and firmware are distributed from internal repositories.
This mode is the norm in classified enclaves, on ships, at deployed bases and in the control centres of critical infrastructure.
Private cloud or total isolation
Within an on-prem deployment there are two configurations, and you can move from one to the other.
Private or government cloud
The EMM server stays on your infrastructure and only the Knox support services (E-FOTA and Knox Asset Intelligence) are consumed from the cloud, through a gateway you control.
100% isolated network (air gap)
All Knox capabilities live inside the on-prem server, including firmware distribution. No connection to public clouds at all: the mode for classified environments.
Features for those who operate outside the office
Kiosk mode
Wizard to lock the device to one or more applications, with a restricted interface and hardware.
Shared device
Several users per device, each with their own session through check-in / check-out: each shift's data stays isolated and fewer devices are needed.
Remote support
Diagnosis without physical presence: screen sharing, session recording and file transfer.
Controlled geolocation
Location and geofencing only where policy permits, with traceability of every query.
SecuCamera
Secure photo capture: the image is encrypted and sent to the central server without staying in the device gallery. For inspections, evidence and field operations (additional licence).
Group policies
Sets of security, connectivity and restriction rules assigned by unit, department or role and applied in bulk.
From onboarding to retirement, every device with full traceability
A managed device passes through four states. The EMM records every transition and applies the corresponding policy automatically.
- Onboarding Enrolment via KME, NFC or QR code; application of the unit profile; verification of integrity and firmware version.
- Operation Continuous compliance, application and policy updates, remote support and auditing.
- Incident Loss, theft or compromise: lock, selective or full wipe, certificate revocation and logging for the report.
- Retirement Verified secure wipe, removal from Knox and from the inventory, and a retirement certificate for the file.
Ready to operate at scale
Multi-tenant
Management of several organisations from a single installation with strict separation of data and administrators.
Staging and kitting
Samsung devices pre-configured and enrolled before delivery to the destination unit.
Dashboards
Per-tenant dashboards with compliance status, versions and activity.
Key features and licensed modules
Some capabilities come with the platform and others are licensed separately. We say which is which so the budget holds no surprises.
Two-way Push
End-to-end encrypted commands to devices, executed immediately and with acknowledgement. Suitable for isolated networks with no dependency on public clouds.
Group policies and shared mode
Uniform rules per role and multi-user sessions with check-in / check-out on the same device.
Knox DualDAR and VPN chaining
Two-layer encryption at rest and dual VPN tunnel for communications. The basis of CSfC-style architectures; FIPS 140-2 modules according to the manufacturer.
SecuCamera
Photos encrypted and sent to the central server without passing through the local gallery: leak prevention in the field.
Knox E-FOTA
Centralised management of firmware and system updates, via cloud or air gap. Version control so that critical applications keep working.
Mobile Compliance Recording (MCR)
Native on-device recording of calls, SMS and other channels: encrypted, tamper-proof and independent of the carrier and the SIM. Chain of custody and legal hold, designed for MiFID II and for environments that require evidence.
Two-way Push, group policies and shared mode are part of the platform. Knox DualDAR/VPN chaining, SecuCamera, Knox E-FOTA and MCR are licensed separately; Knox E-FOTA and MCR apply to Samsung devices only.
Server requirements and supported systems
| Item | Requirement |
|---|---|
| Server operating system | Windows Server 2016, 2019 or 2022 |
| Database | Microsoft SQL Server 2016, 2019 or 2022, or Oracle Database |
| Identity directory | Microsoft Active Directory, OpenLDAP or LDAPv3 |
| Architecture | Single server (testing and small fleets) or multi-server cluster with high availability (production) |
| Mobile systems | Android 6.0 or later (Android Enterprise), iOS 15 or later and Windows 10 (1703 or later) |
| Samsung devices | Knox features (KME, DualDAR, E-FOTA, Tactical Edition) on Galaxy devices with Knox |
Who is behind the platform: Samsung SDS
Samsung SDS has been the Samsung Group's information technology company since 1985: digital transformation, cloud, cybersecurity, enterprise mobility and logistics. Blindium is a certified Resell Partner for its EMM platform.
Corporate figures published by Samsung SDS (2024-2025), reproduced for information. They are not part of any product certification.
About the platform
What does the platform include and what is contracted separately?
The platform includes the console, Private Push (Two-way Push), group policies, shared mode and the management of Android, iOS and Windows. Knox DualDAR and VPN chaining, SecuCamera, Knox E-FOTA and Mobile Compliance Recording are licensed separately, the last two for Samsung devices only. The assessment sets which modules each unit needs.
Does it only work with Samsung devices?
No. It manages Samsung devices, Android Enterprise devices from any manufacturer and iOS/iPadOS from the same console. Knox integration adds further controls on Galaxy devices, but the fleet can be mixed.
What happens if the server has no Internet access?
The system continues to manage devices through SDS Private Push, an internal notification service. This is the intended mode of operation for isolated networks.
Can we combine on-prem and cloud?
Yes. It is common to deploy on-prem for operational units and to use the Samsung cloud EMM for administrative staff. The assessment defines which model applies to each group.
How does it integrate with our directory and our PKI?
Through standard LDAP/Active Directory connectors and certificate issuance protocols (SCEP and similar). The corporate PKI remains the authority; the EMM distributes and renews the certificates on the devices.
Free MDM/EMM continuity assessment (45 minutes)
A technical session with a specialist to review your situation and return an actionable recommendation. No obligation.
- Current architecture and number of devices
- Data criticality and network or cloud constraints
- Integration with Samsung Knox and mixed fleets
- Transition options and deployment model (on-prem, hybrid or cloud)


