Why do I keep seeing the alert "attestation failed"?

When enroll the Spreadtrum chipset device with Knox Manage, there are repeat attestation "Failed policy" alerts.

Root cause ::

Your device does not TrustZone. Which is the driver of  the frequent attestation checks.

When you enroll a device, the KM agent pushes the "initial policy". Attestation is checked through this Initial policy. 

It's not related to whether an attestation policy is applied to device or not. 

Resolution/Countermeasure :