Keeping a fleet of mobile devices on verified, current firmware is one of those tasks that quietly gets harder as the fleet grows. You need the right version on the right devices at the right time—without disrupting your users or breaking a line-of-business app. And for organizations aligning with Zero Trust principles, every unpatched device has the potential of creating a compliance gap waiting to surface.
Knox Enterprise Firmware-Over-The-Air (E-FOTA) is Samsung’s solution for giving IT admins precise control over firmware and OS updates across their Galaxy fleet. You decide which version runs, when it rolls out, and under what conditions.
Now, Knox E-FOTA integrates with Microsoft Intune, so you can manage firmware directly from the Intune admin center, without leaving the environment you already know.
Table of contents:
Manage your firmware, where you already work
The Knox E-FOTA integration with Intune brings firmware campaigns directly into the Intune admin center, right alongside the device policies, app assignments, and compliance rules you already manage there. No context-switching, no second tool to learn, no separate workflow to maintain.
Your existing Intune device groups drive firmware targeting. When a device moves between groups, its firmware assignment follows automatically. When a device is removed from Intune, Knox E-FOTA removes it, too. One set of groups, one console, everything in sync.
For IT teams that have been splitting their time between platforms, that's fewer steps and one less place for things to fall out of alignment.

Samsung Knox E-FOTA connector within the Microsoft Intune admin center.
Test, schedule, and deploy on your terms
OS updates don’t just bring new features. They can introduce changes that affect how your line-of-business apps behave. Knox E-FOTA lets you test a firmware version before it reaches any production device and hold your fleet on the current version while testing is underway. Once the update passes your validation, you roll it out gradually, on your schedule.
Scheduling is granular. You choose exactly when updates install, down to specific device groups and time windows. That means installations happen during planned maintenance windows, after business hours, or overnight, not when your team is in the middle of their workday. You can also set conditions a device needs to meet before an update begins, like a minimum battery charge. And if the timing still isn’t right, users can postpone within limits you define.
When a critical security patch needs to go out, Knox E-FOTA lets you push it systematically across your fleet rather than waiting for each device to pick it up on its own. For teams operating under a Zero Trust model, that matters: running a validated, current firmware version can help strengthen device security and support compliance goals. Running a consistent firmware version also simplifies day-to-day support—you're troubleshooting known, deliberate versions, not guessing what a device picked up on its own.

Samsung Knox E-FOTA campaign interface within the Microsoft Intune admin center.

Samsung Knox E-FOTA deployment report within the Microsoft Intune admin center.
Learn more
If your organization runs Microsoft Intune and manages a Samsung Galaxy fleet, the Knox E-FOTA integration lets you manage firmware directly from the console you already work in. Watch how to configure Knox E-FOTA on Microsoft Intune.
For more on Knox E-FOTA, visit samsungknox.com. No license yet? Try Knox Suite for free for 90 days.
If you’re also looking to strengthen device integrity checks across your fleet, Samsung Knox On-Device Attestation is enabled by default in new Android App Protection Policies.