# How to prevent users from revoking management? Last updated: July 24, 2026 Corporate devices enrolled via Apple Business Manager, Zero Touch Enrollment, or KNOX Mobile Enrollment can't be removed from management even after a factory reset; devices using other methods can restrict this via Restrictions profiles. Since personal devices can't be fully locked down, admins can instead enable a notification under Enrollment settings to be alerted whenever a device becomes unmanaged, and review inactive devices in Reports. ## Description MDM must be present in the enrolled devices to be managed at all times. If a user tries to remove MDM, then the device is unmanaged and the error **User has revoked management** is displayed against the device, under **Remarks** in the **Enrollment** tab. To prevent the user from removing MDM, configure MDM as follows: ## Steps ### Corporate Devices The devices that are owned by the organization and provided to the employees must be managed at all times. The users must not have the permission to remove these devices from management. To prevent users from removing these devices management, these devices can be enrolled using the available corporate enrollment methods. These enrollment methods ensures that the devices cannot be removed from management even if they are factory reset. iOS/iPadOS devices 1. [Apple Business Manager](https://www.manageengine.com/mobile-device-management/help/enrollment/device_enrollment_program_ios_devices.html) Android Devices 1. [Zero Touch Enrollment](https://www.manageengine.com/mobile-device-management/help/enrollment/android_zero_touch_enrollment.html) 2. [KNOX Mobile Enrollment](https://www.manageengine.com/mobile-device-management/help/enrollment/knox_mobile_device_management.html) For iOS/iPadOS devices enrolled using other enrollment methods, users can be restricted from removing management by factory resetting devices by applying the [Restrictions](https://www.manageengine.com/mobile-device-management/help/profile_management/ios/mdm_restrictions.html?mdmpi) profile **Allow user to wipe device by erasing all content and settings.** In Android devices, users can be restricted from removing Self Service app (previously ME MDM app) by navigating to **Enrollment -> Android -> Self Service app (previously ME MDM app) -> Allow user to remove Self Service app (previously ME MDM app).** ### Personal Devices Since these devices are personally owned, we cannot completely restrict the users from revoking management, but we can ensure that the admin is notified when any device is removed from management. Follow the steps given below to enable these notifications: 1. On the console, navigate to **Enrollment -> Enrollment settings** 2. Enable the option **Notify when device becomes unmanaged** ![Enrollment settings](https://cdn.manageengine.com/mobile-device-management/images/enrolmentsettings.png) 3. Enter the email address that must receive the notifications 4. Save the settings In addition to individual notification, the admin can also view the devices that have not come into contact with the server for a period of time by navigating to **Reports -> Inactive devices**. It is also recommended to configure services and distribute enterprise apps only through MDM. Though MDM can be removed, it also results in the configurations and enterprise apps being removed from the managed devices. Thereby ensuring that the user's cannot access the corporate data once the management is revoked from these devices. [Conditional Exchange Access](https://www.manageengine.com/mobile-device-management/help/profile_management/mdm_conditional_exchange_access.html) also allows organizations keep their e-mails secure by ensuring only enrolled devices get access to the corporate e-mails. **Note:** Device management can be revoked by the user if the **Show unenrollment option in Self Service app (previously ME MDM app)** is enabled in the product console. ## Frequently asked questions ### How do I stop corporate-owned devices from being removed from MDM management? Enroll them using a corporate enrollment method - Apple Business Manager for iOS/iPadOS, or Zero Touch Enrollment/KNOX Mobile Enrollment for Android - since these methods prevent the device from being removed from management even after a factory reset. ### Why can't I fully prevent personal devices from being unenrolled? Personal devices are user-owned, so they can't be completely locked from revoking management. Instead, enable the **Notify when device becomes unmanaged** option under Enrollment -> Enrollment settings to get alerted whenever a device is removed from management, and check Reports -> Inactive devices to spot devices that haven't contacted the server. ### What happens if a user manages to revoke MDM management from their device? The device is marked unmanaged and shows **User has revoked management** under Remarks in the Enrollment tab. Since configurations and enterprise apps distributed through MDM are removed along with management, and Conditional Exchange Access blocks unenrolled devices from corporate email, the user loses access to corporate data and resources.