samsung knox enrollment failing with error 1001 in intune
Fixes Samsung Knox enrollment failing with error 1001 in Intune: checking Knox services, time sync, and enrollment prerequisites. Use when Samsung devices fail Knox enrollment with this code. Not for non-Samsung Android or generic work profile errors.
TL;DR
Error 1001 is the Knox layer failing before Intune ever gets involved. Confirm the device supports Knox, the clock is correct, Knox services can reach Samsung, and then re-run enrollment from a clean state.
The query
samsung knox enrollment failing with error 1001 in intuneUse this when
- Samsung enrollment fails with error 1001
- Knox-specific step fails while standard Android enrollment works
- the error appears on the Knox terms or activation screen
Not for
- non-Samsung Android enrollment failures
- Intune-side errors after Knox succeeds
- Knox warranty-bit or hardware attestation failures
Steps
- Confirm the device model actually supports Samsung Knox enrollment. Expected output: the model is on the supported list.
- Verify the device date, time, and time zone are correct and automatic. Expected output: time syncs correctly.
- Check that the device can reach Samsung Knox services: no firewall, VPN, or ad-blocker interfering. Expected output: Knox service connectivity is confirmed.
- Remove any partial Knox or work profile enrollment state from the device. Expected output: no stale enrollment artifacts remain.
- Re-run enrollment through the Company Portal. Expected output: Knox activates and Intune enrollment completes.
Applies to
Samsung Knox devices, Microsoft Intune, Knox Mobile Enrollment where used, current versions.
Variant phrasings
1001 on devices from a carrier
Carrier firmware variants sometimes lag Knox support; check the exact model number, not just the marketing name.
1001 after a Knox cloud outage
Samsung-side incidents produce fleet-wide 1001s; check Samsung status before rebuilding devices.
Why it happens
Knox enrollment attests the device with Samsung before Intune management begins. Anything blocking that attestation, from time skew to filtered traffic, surfaces as 1001.
Edge cases
- Rooted or custom-ROM devices fail Knox attestation by design; no admin fix exists.
- Knox Mobile Enrollment profiles can conflict with manual enrollment; use one path.
- Keep a known-good Samsung device for testing whether the failure is fleet-wide.
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_fAR3iK59slqY5mdrel0a2g
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.