Menu

How to prevent container removal by an end user in Knox Manage

Environment

Knox Manage (KM)

Overview

KM allows an IT administrator to securely manage a device's work environment through a work profile. However, in certain deployments the end user has the option to remove the work profile container on their device.

Can I prevent a user from removing the Work Profile container on their device?

Due to an API limitation, KM cannot prevent container removal for devices configured in a Legacy deployment. The chart below details what will happen when a user tries to remove the work profile in different KM deployments: 

Android Enterprise (AE) mode

Legacy mode

Profile owner (PO): The user can remove the work profile.

Android O and above: The user can remove the work profile.

Device owner + profile owner (DO + PO): The user is unable to remove the work profile.

Android N and below: The user is unable to remove the work profile.

Additional Information

To learn more about how AE handles work profiles, see the Android Enterprise FAQs.