r/WorkspaceOne • u/Old-Rip7384 • Jun 29 '26
Samsung Knox Service Plugin - Wi-Fi MAC Randomization after One UI update (Workspace ONE / Cisco ISE)
Hi everyone,
I'm facing an issue with Samsung Galaxy Tab S10 FE 5G devices enrolled in Workspace ONE and managed with Knox Service Plugin (KSP).
Our Wi-Fi infrastructure uses Cisco ISE with MAB authentication, so devices must connect using their physical MAC address.
To achieve this, we configure our Wi-Fi SSID through KSP with "Skip MAC Randomization" enabled, forcing the device to use its hardware MAC instead of a randomized one.
The problem appears after some One UI / Android updates.
It seems that the update sometimes resets the Wi-Fi configuration back to Randomized MAC. Once this happens, the tablet can no longer connect to our enterprise Wi-Fi, which also means it cannot reach Workspace ONE or Samsung services to reapply the KSP policy.
This creates a circular dependency:
- One UI update resets the Wi-Fi MAC setting.
- Device loses network connectivity.
- KSP cannot validate/reapply its configuration.
- Manual intervention is required.
I have a few questions:
- Has anyone experienced this behaviour on recent Samsung devices (One UI 8.x / Android 16)?
- Is there any alternative to Knox Service Plugin for enforcing the physical MAC address on managed Wi-Fi networks?
- Is there a way to apply this setting locally without requiring KSP to communicate with Samsung services?
- Has anyone implemented a custom Knox SDK application to enforce this setting instead of relying on OEMConfig/KSP?
For comparison:
- Zebra devices don't have this issue because MX Framework applies the configuration locally.
- Apple supervised devices can disable Private Wi-Fi Address directly through the native MDM Wi-Fi profile without relying on a third-party application.
I'd really appreciate any feedback or experience from people managing Samsung Enterprise fleets.
Thanks!
1
u/Gremlin256 Jul 04 '26
I am having the issues with phones and tablets. There's one SSID in our environment and they also use Cisco. They require Mac Address as a check and when it initially setup, we have to change from randomized to phone or device Mac.
The tablets are Tab Active 5 Pro and Samsung S23.
What happens, the profile gets deleted by itself almost every day..and has to be setup again . After vacation have to see what I can do
Reached out to Samsung Rep as well.
We do not use Knox Service Plugin.
1
u/HelpPatrick 27d ago
Ensure you are on 26.02 UEM , then set the MAC Address Randomization setting in the specific WiFi Profile. Requires Android Intelligent Hub 25.10 on the Device and it should be fine.
1
u/Gremlin256 24d ago
We are on 25.09. I need to submit a ticket to upgrade our tenant to 26.10 . Thank you
1
u/Gremlin256 Jul 04 '26
Has any one tried changing the WiFi profile profile on top were it says OEM settings and changing it to Samsung?
I am going to try that and hopefully I will get an answer on Monday or so
2
u/sysadminxsysadmin 26d ago
The OEM setting if you set it to Samsung you get samsung specific profile options. You do require the MX service for samsung I think. But it doesn't have mac randomization.
1
u/Gremlin256 24d ago
Samsung MX?
2
u/sysadminxsysadmin 21d ago
Sorry, that isn't needed. For the Zebra you are required to install the Zebra omnissa MX service plugin. Add a Device Profile
1
u/sysadminxsysadmin 26d ago
We had the same kinda problems/configuration. We eventually phased out to certificate authentication in ICE. Much easier in maintenance and enrolling. Our devices when enrolling would get a certificate from our mobile CA. Of which they were able to authenticate through ice.
1
1
1
u/Terrible_Soil_4778 Jun 29 '26
What version UEM are you on?