Android device cannot accept the KNOX privacy notification (older devices S5/S6)

Chrissy Nield 26 Reputation points
2021-02-05T19:27:25.613+00:00

I am experiencing several issues with BYOD Android devices that are S5 and S6. The notice for accepting the KNOX privacy is displaying, but users attempt to accept and nothing happens. The devices remain not compliant, and as much as I can troubleshoot remotely, I believe that this is the cause. The work profile is created, but it is not usable (greyed out and tapping does not open).

This is very perplexing and very new to me. I find it most disturbing that no device information is shared, which also points to the privacy acceptance and being unable to accept by the user.

Do you have any related experience or resolutions for this type of issue? I did more reading and found that Secure Folder app was taking the place of KNOX for device encryption, but will it work for the establishment of the work profile? Will it require different settings in Intune to accommodate?

ETA: Device example
Phone - SM-G920R4
Android - 7.0
Knox - 2.7.2

Microsoft Intune Enrollment
Microsoft Intune Enrollment
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Enrollment: The process of requesting, receiving, and installing a certificate.
1,254 questions
{count} vote

Accepted answer
  1. Crystal-MSFT 43,381 Reputation points Microsoft Vendor
    2021-02-25T02:17:00.617+00:00

    @mfranklin , Thanks for sharing here. And I am glad to hear that it is working now. Congratulations!

    From the update I get from internal, I find the new company portal with fix deployed to Prod users publish in Google Play Store can fix our issue. @everyone, we can try to install the latest company portal to see if it is also working in our environment. Here are steps we can try:

    1. Un-enroll the device from Intune.
    2. Remove the old company portal from the Android 6.7 device.
    3. Download the new company portal from Google Play Store.
    4. Enroll our device into Intune again.

    Thanks for your time and have a nice day!

    1 person found this answer helpful.
    0 comments No comments

16 additional answers

Sort by: Most helpful
  1. Tom Storm 1 Reputation point
    2021-02-23T19:13:50.947+00:00

    We are experiencing the same issue with multiple Android 7 tablets (Samsung S2) in our company. Also opened a MS ticket, but the recommendation for now is to allow these devices for and exception to go back to Device Administrator instead of AE.


  2. Hemesh 6 Reputation points
    2021-02-24T08:33:46.747+00:00

    So I will repost my workaround for my S6 (Android 7, Knox 2.7.1)

    I managed to get this working now. I used a web site (googled for old versions of the Company Portal) that had an APK for version 5.0.4731.0.

    • Install the older company portal APK manually
    • Use this app to register your device
    • Update the Company Portal from the Google Play store
    • Continue to add in other Apps required for work

    This all now works, so I can confirm it's something broken in more recent versions of the Company Portal from MS!

    0 comments No comments

  3. 2021-02-25T16:31:57.637+00:00

    It's working now! thanks!

    0 comments No comments

  4. Lamaster, Robert 1 Reputation point
    2021-03-04T17:13:59.793+00:00

    Unfortunately, I'm still seeing the issue, and I'm on Android 9 with Company Portal 4.0.5067.0. (Samsung Galaxy S8+). During enrollment, I get the dreaded, "Accept KNOX privacy notice to finish setting up your device" notification from Company Portal that does nothing when you click it. In Company Portal, "Device Details", it says, "You need to update settings on this device". If you click on that, you see the "Update device settings" screen in the Company Portal, which says:

    *You need to update settings on this device
    Last checked: March 4, 9:55 AM
    Your company needs you to adjust these settings to comply with organizational policies. Tap Confirm Device Settings to recheck these settings.

    No compliance policies have been assigned
    Your IT department has not configured Intune to evaluate your device for compliance. Please contact your helpdesk.*

    To me, that means that the "MDM Android Compliance Policy" we have set up in Intune does not appear to be applicable to the device. However, the account I'm using to log into the Company Portal is in the user group assigned to the policy. The policy in Intune is:

    Profile type: Personally-owned work profile
    Platform supported: Android Enterprise
    Assigned: Yes
    Groups assigned: 1
    Groups Excluded: 0

    We are just starting our journey into Intune, and I am in the pilot group (selected to apply the policy to). My device is a personally-owned Android 9. Are the selections for the Intune policy (above) correct to get this policy to apply to my device?