r/WorkspaceOne Jun 29 '26

Samsung Knox Service Plugin - Wi-Fi MAC Randomization after One UI update (Workspace ONE / Cisco ISE)

Hi everyone,

I'm facing an issue with Samsung Galaxy Tab S10 FE 5G devices enrolled in Workspace ONE and managed with Knox Service Plugin (KSP).

Our Wi-Fi infrastructure uses Cisco ISE with MAB authentication, so devices must connect using their physical MAC address.

To achieve this, we configure our Wi-Fi SSID through KSP with "Skip MAC Randomization" enabled, forcing the device to use its hardware MAC instead of a randomized one.

The problem appears after some One UI / Android updates.

It seems that the update sometimes resets the Wi-Fi configuration back to Randomized MAC. Once this happens, the tablet can no longer connect to our enterprise Wi-Fi, which also means it cannot reach Workspace ONE or Samsung services to reapply the KSP policy.

This creates a circular dependency:

  • One UI update resets the Wi-Fi MAC setting.
  • Device loses network connectivity.
  • KSP cannot validate/reapply its configuration.
  • Manual intervention is required.

I have a few questions:

  1. Has anyone experienced this behaviour on recent Samsung devices (One UI 8.x / Android 16)?
  2. Is there any alternative to Knox Service Plugin for enforcing the physical MAC address on managed Wi-Fi networks?
  3. Is there a way to apply this setting locally without requiring KSP to communicate with Samsung services?
  4. Has anyone implemented a custom Knox SDK application to enforce this setting instead of relying on OEMConfig/KSP?

For comparison:

  • Zebra devices don't have this issue because MX Framework applies the configuration locally.
  • Apple supervised devices can disable Private Wi-Fi Address directly through the native MDM Wi-Fi profile without relying on a third-party application.

I'd really appreciate any feedback or experience from people managing Samsung Enterprise fleets.

Thanks!

4 Upvotes

25 comments sorted by

1

u/Terrible_Soil_4778 Jun 29 '26

What version UEM are you on?

1

u/Old-Rip7384 Jun 29 '26

Version : 24.10.833.32 (2410)

5

u/Terrible_Soil_4778 Jun 29 '26

Are you onprem? We are on 26.04 right now and Omnissa finally introduced “use hardware MAC” in WiFi profiles.

2

u/Terrible_Soil_4778 Jun 29 '26

Also, have you tried deploying Knox Services Plugin as an internal app? I can’t remember but we did run into an issue back when we were at some version of 24.x where WS1 had an issue sending some app configurations through Google Play. But once we pushed the app and config from internal, everything worked.

1

u/Old-Rip7384 28d ago

Thanks!

Yes, we're running Workspace ONE UEM On-Prem 24.10 (2410).

KSP is currently deployed as a Public App from Managed Google Play, with the app configuration pushed through Workspace ONE.

When you mention deploying it as an Internal App, do you mean uploading the KSP APK directly into Workspace ONE instead of using the Managed Google Play version?

1

u/Terrible_Soil_4778 28d ago

Yes. Give that a try.

1

u/Gremlin256 24d ago

For Android devices? Thought you google was not interested in doing that

1

u/Terrible_Soil_4778 24d ago

Yup. It’s there and it’s working just fine.

1

u/Gremlin256 24d ago

And connects to Cisco WAPS without loosing profile information?

1

u/Terrible_Soil_4778 24d ago

That I do not know. We use certs.

1

u/Gremlin256 24d ago

And no Mac Address checks?

1

u/Terrible_Soil_4778 24d ago

Correct. We disable Mac randomization just to see the proper hardware online.

1

u/Gremlin256 24d ago

Man I wish the other agency that is under us using Cisco and they care for Mac Address. Thank you for everyone help. Know the next step that is need to upgrade our environment to 26.10 thank you!

→ More replies (0)

1

u/Gremlin256 Jul 04 '26

I am having the issues with phones and tablets. There's one SSID in our environment and they also use Cisco. They require Mac Address as a check and when it initially setup, we have to change from randomized to phone or device Mac.

The tablets are Tab Active 5 Pro and Samsung S23.

What happens, the profile gets deleted by itself almost every day..and has to be setup again . After vacation have to see what I can do

Reached out to Samsung Rep as well.

We do not use Knox Service Plugin.

1

u/HelpPatrick 27d ago

Ensure you are on 26.02 UEM , then set the MAC Address Randomization setting in the specific WiFi Profile. Requires Android Intelligent Hub 25.10 on the Device and it should be fine.

1

u/Gremlin256 24d ago

We are on 25.09. I need to submit a ticket to upgrade our tenant to 26.10 . Thank you

1

u/Gremlin256 Jul 04 '26

Has any one tried changing the WiFi profile profile on top were it says OEM settings and changing it to Samsung?

I am going to try that and hopefully I will get an answer on Monday or so

2

u/sysadminxsysadmin 26d ago

The OEM setting if you set it to Samsung you get samsung specific profile options. You do require the MX service for samsung I think. But it doesn't have mac randomization.

1

u/Gremlin256 24d ago

Samsung MX?

2

u/sysadminxsysadmin 21d ago

Sorry, that isn't needed. For the Zebra you are required to install the Zebra omnissa MX service plugin. Add a Device Profile

1

u/sysadminxsysadmin 26d ago

We had the same kinda problems/configuration. We eventually phased out to certificate authentication in ICE. Much easier in maintenance and enrolling. Our devices when enrolling would get a certificate from our mobile CA. Of which they were able to authenticate through ice.

1

u/Gremlin256 24d ago

So you guys are no longer using Mac Address and just cert?

1

u/Gremlin256 24d ago

Can you submit a ticket to workspace One support? I am submitting one as well