Android device cannot accept the KNOX privacy notification (older devices S5/S6)

Chrissy Nield 26 Reputation points
2021-02-05T19:27:25.613+00:00

I am experiencing several issues with BYOD Android devices that are S5 and S6. The notice for accepting the KNOX privacy is displaying, but users attempt to accept and nothing happens. The devices remain not compliant, and as much as I can troubleshoot remotely, I believe that this is the cause. The work profile is created, but it is not usable (greyed out and tapping does not open).

This is very perplexing and very new to me. I find it most disturbing that no device information is shared, which also points to the privacy acceptance and being unable to accept by the user.

Do you have any related experience or resolutions for this type of issue? I did more reading and found that Secure Folder app was taking the place of KNOX for device encryption, but will it work for the establishment of the work profile? Will it require different settings in Intune to accommodate?

ETA: Device example
Phone - SM-G920R4
Android - 7.0
Knox - 2.7.2

Microsoft Security | Intune | Enrollment
{count} vote

Accepted answer
  1. Crystal-MSFT 53,991 Reputation points Microsoft External Staff
    2021-02-25T02:17:00.617+00:00

    @mfranklin , Thanks for sharing here. And I am glad to hear that it is working now. Congratulations!

    From the update I get from internal, I find the new company portal with fix deployed to Prod users publish in Google Play Store can fix our issue. @everyone, we can try to install the latest company portal to see if it is also working in our environment. Here are steps we can try:

    1. Un-enroll the device from Intune.
    2. Remove the old company portal from the Android 6.7 device.
    3. Download the new company portal from Google Play Store.
    4. Enroll our device into Intune again.

    Thanks for your time and have a nice day!

    1 person found this answer helpful.
    0 comments No comments

16 additional answers

Sort by: Most helpful
  1. Crystal-MSFT 53,991 Reputation points Microsoft External Staff
    2021-02-09T05:16:07.027+00:00

    @Chrissy Nield , Thanks for the reply.

    Here, I have find one Samsung knox device to test. Here are the process when I enroll the device via company portal. I find there's some change with the ELM. The screen I get are as below.

    65624-image.png
    After it is enrolled, I find this device shows as "Android personally owned work profile"
    65584-image.png

    Then I deploy a compliance policy for this device and choose "check device settings" in the company portal of the device. then it shows compliant in my portal.
    65518-image.png
    From the picture, I find the user principle name shows none, In my test, it is shows as the user I sign in.
    65653-image.png
    Could you sign in the user account into the company portal of this device and check device settings to see if the compliance policy can be applied.

    If there's anything unclear, feel free to let us know.

    0 comments No comments

  2. Kirby, Ryan 1 Reputation point
    2021-02-09T11:44:04.777+00:00

    What version of Android does your test device have Crystal? We aren't seeing the issue with newer devices. The one I'm working on now is a Note 5 with Android 7.0


  3. Chrissy Nield 26 Reputation points
    2021-02-09T13:31:01.687+00:00

    I am curious as to what Knox version is on the device that you are testing. I even had the user load the Secure Folder app in hopes that this would change the setup and that it would complete.

    I will ask the user to check the compliance in the portal. We did this prior, but I do not recall the exact wording. On another device, enrollment freezes entirely. The Work Profile does not create.

    Policies deployed. I did a check device several times on each of the 5 devices. The work profile policy does not clear because the privacy notification is never accepted for Knox. It is a strange glitch. Looks like I may have to take this one to MS for support. :-/


  4. Hemesh 6 Reputation points
    2021-02-10T08:57:25.063+00:00

    After I login with my work account, I get the following screenshots before I get the issue with the device waiting for the privacy notice to be accepted: 66240-screenshot-20210210-082546.png66332-screenshot-20210210-082552.png66300-screenshot-20210210-082609.png66345-screenshot-20210210-083010.png66268-screenshot-20210210-083048.png66307-screenshot-20210210-083058.png66333-screenshot-20210210-083104.png66361-screenshot-20210210-083109.png66259-screenshot-20210210-083117.png66335-screenshot-20210210-083124.png66336-screenshot-20210210-083128.png66371-screenshot-20210210-083206.png


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.