Android device cannot accept the KNOX privacy notification (older devices S5/S6)

Chrissy Nield 26 Reputation points
2021-02-05T19:27:25.613+00:00

I am experiencing several issues with BYOD Android devices that are S5 and S6. The notice for accepting the KNOX privacy is displaying, but users attempt to accept and nothing happens. The devices remain not compliant, and as much as I can troubleshoot remotely, I believe that this is the cause. The work profile is created, but it is not usable (greyed out and tapping does not open).

This is very perplexing and very new to me. I find it most disturbing that no device information is shared, which also points to the privacy acceptance and being unable to accept by the user.

Do you have any related experience or resolutions for this type of issue? I did more reading and found that Secure Folder app was taking the place of KNOX for device encryption, but will it work for the establishment of the work profile? Will it require different settings in Intune to accommodate?

ETA: Device example
Phone - SM-G920R4
Android - 7.0
Knox - 2.7.2

Microsoft Intune Enrollment
Microsoft Intune Enrollment
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Enrollment: The process of requesting, receiving, and installing a certificate.
1,244 questions
{count} vote

Accepted answer
  1. Crystal-MSFT 42,956 Reputation points Microsoft Vendor
    2021-02-25T02:17:00.617+00:00

    @mfranklin , Thanks for sharing here. And I am glad to hear that it is working now. Congratulations!

    From the update I get from internal, I find the new company portal with fix deployed to Prod users publish in Google Play Store can fix our issue. @everyone, we can try to install the latest company portal to see if it is also working in our environment. Here are steps we can try:

    1. Un-enroll the device from Intune.
    2. Remove the old company portal from the Android 6.7 device.
    3. Download the new company portal from Google Play Store.
    4. Enroll our device into Intune again.

    Thanks for your time and have a nice day!

    1 person found this answer helpful.
    0 comments No comments

16 additional answers

Sort by: Most helpful
  1. Hemesh 6 Reputation points
    2021-02-09T13:03:46.46+00:00

    Hi,

    I have the same problem on my S6 - 920F (Android 7, Knox 2.7.1). The Company Portal App does not trigger the creation of the Work Profile for Samsung Knox, which is what I think the problem is. If that was triggered, then I'm sure it'd work fine.

    Therefore, I think this is a bug in the Company Portal App?

    1 person found this answer helpful.

  2. mfranklin 6 Reputation points
    2021-02-24T21:05:05.14+00:00

    Hi All - i worked with my company MDM team and they saw on another forum post that it looks like there has been movement from Microsoft (and possibly samsung) on this issue. i didnt need to install an older version of company portal fortunately. About 2 hrs ago, i removed my device (v7) from company portal, uninstalled company portal, rebooted my mobile, then re-installed company portal from google play. I registered my device and it worked fine and is showing as compliant in company portal. I was then able to access outlook, ms-teams, etc.

    Hope this works for all of you as well!

    1 person found this answer helpful.

  3. Mervyn S Morris 1 Reputation point
    2021-02-08T14:01:50.39+00:00

    @Crystal-MSFT
    I am not sure if this is appropriate or if I should open a new post. I have two devices in my organization, both Samsung devices running Android 7.0 with the same issue.

    The ELM Agent Privacy Policy was never presented to the devices or users.
    Company Portal states "You need to update settings on this device"
    Android Notification Bar states" Accept KNOX privacy notice to finish setting up your device". Clicking on the notification does nothing

    Phone - SM-N920A
    Android - 7.0
    Knox - 2.7.1

    65357-screenshot-20210208-071425.png
    65390-screenshot-20210208-083221.png
    65377-image.png


  4. Chrissy Nield 26 Reputation points
    2021-02-08T15:33:48.897+00:00

    As with MervynSMorris-6224 , the notification is the only area where the company portal prompt shows. It does not show the ELM in the enrollment process.

    65446-image.png

    But, because the ELM is not showing and only a notification (which when clicked, as mentioned, does nothing) the Work Profile Compliances does not evaluate. The Work Profile is created on the phone. The profile is disabled because of the unaccepted KNOX privacy ELM. The BYOD device is just sitting and waiting for the ELM to show during enrollment, and it never does. Only the notifications show the alert, but clicking on the alert does nothing.

    0 comments No comments