## TL;DR
Error 1001 is the Knox layer failing before Intune ever gets involved. Confirm the device supports Knox, the clock is correct, Knox services can reach Samsung, and then re-run enrollment from a clean state.

## The query
```text
samsung knox enrollment failing with error 1001 in intune
```

## Use this when
- Samsung enrollment fails with error 1001
- Knox-specific step fails while standard Android enrollment works
- the error appears on the Knox terms or activation screen

## Not for
- non-Samsung Android enrollment failures
- Intune-side errors after Knox succeeds
- Knox warranty-bit or hardware attestation failures

## Steps
1. Confirm the device model actually supports Samsung Knox enrollment. Expected output: the model is on the supported list.
2. Verify the device date, time, and time zone are correct and automatic. Expected output: time syncs correctly.
3. Check that the device can reach Samsung Knox services: no firewall, VPN, or ad-blocker interfering. Expected output: Knox service connectivity is confirmed.
4. Remove any partial Knox or work profile enrollment state from the device. Expected output: no stale enrollment artifacts remain.
5. Re-run enrollment through the Company Portal. Expected output: Knox activates and Intune enrollment completes.

## Applies to
Samsung Knox devices, Microsoft Intune, Knox Mobile Enrollment where used, current versions.

## Variant phrasings
### 1001 on devices from a carrier
Carrier firmware variants sometimes lag Knox support; check the exact model number, not just the marketing name.

### 1001 after a Knox cloud outage
Samsung-side incidents produce fleet-wide 1001s; check Samsung status before rebuilding devices.

## Why it happens
Knox enrollment attests the device with Samsung before Intune management begins. Anything blocking that attestation, from time skew to filtered traffic, surfaces as 1001.

## Edge cases
- Rooted or custom-ROM devices fail Knox attestation by design; no admin fix exists.
- Knox Mobile Enrollment profiles can conflict with manual enrollment; use one path.
- Keep a known-good Samsung device for testing whether the failure is fleet-wide.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_fAR3iK59slqY5mdrel0a2g
