Knox Email permissions - Galaxy Note 3 Q&A, Help & Troubleshooting

Ok, these permissions required for Corporate Email is absolutely ridiculous. The account wants full admin access over my phone. Basically if i give it permission my IT guy can factory reset my phone, add and change email accounts, enable/disable wifi, network access see my files, incoming/outgoing calls, messages, etc..
thats NOT going to happen. My question is, since Im using Knox, and im using the Email on Knox, and Knox is just a VM... will those permissions only apply to the VM container? Meaning the admin will not technically be able to factory reset my entire phone, (or view my entire phone contents) Just the "things" in the KNOX container? so a factory reset (if i get fired for instance) would only "factory reset" the knox container??
I searched for clarification on this but couldnt find anything. Thanks for the help

Mad_Scientist_565 said:
Ok, these permissions required for Corporate Email is absolutely ridiculous. The account wants full admin access over my phone. Basically if i give it permission my IT guy can factory reset my phone, add and change email accounts, enable/disable wifi, network access see my files, incoming/outgoing calls, messages, etc..
thats NOT going to happen. My question is, since Im using Knox, and im using the Email on Knox, and Knox is just a VM... will those permissions only apply to the VM container? Meaning the admin will not technically be able to factory reset my entire phone, (or view my entire phone contents) Just the "things" in the KNOX container? so a factory reset (if i get fired for instance) would only "factory reset" the knox container??
I searched for clarification on this but couldnt find anything. Thanks for the help
Click to expand...
Click to collapse
bump!! still wondeirng the answer to this one.

Mad_Scientist_565 said:
bump!! still wondeirng the answer to this one.
Click to expand...
Click to collapse
+1
Interesting thought. I want to know that too. Can anyone test this? I can volunteer if you need people to test this. I have stock Note 3 and working knox that I can set up. I don't have any data I care about on my phone if it is wiped.

rahulisola said:
+1
Interesting thought. I want to know that too. Can anyone test this? I can volunteer if you need people to test this. I have stock Note 3 and working knox that I can set up. I don't have any data I care about on my phone if it is wiped.
Click to expand...
Click to collapse
i dont even know how one would have access to this. i mean there must be some kind of software or something that goes along with the microsoft exchange server that allows them to "see" your device, and control it.. i obviously dont have that software.. I do have google apps for my email, and i know it can remote wipe users phones, but i dont think its the same "level" of wipe.
rahu... in stall the app "google apps device policy" im going to set you up an email/password under my domain, that you can then use to configure your email under knox. We can give it a shot.

Mad_Scientist_565 said:
Ok, these permissions required for Corporate Email is absolutely ridiculous. The account wants full admin access over my phone. Basically if i give it permission my IT guy can factory reset my phone, add and change email accounts, enable/disable wifi, network access see my files, incoming/outgoing calls, messages, etc..
thats NOT going to happen. My question is, since Im using Knox, and im using the Email on Knox, and Knox is just a VM... will those permissions only apply to the VM container? Meaning the admin will not technically be able to factory reset my entire phone, (or view my entire phone contents) Just the "things" in the KNOX container? so a factory reset (if i get fired for instance) would only "factory reset" the knox container??
I searched for clarification on this but couldnt find anything. Thanks for the help
Click to expand...
Click to collapse
As far as I know one of the permissions for the Knox admin is to full-wipe the phone not just the Knox container - so that WILL factory-reset your phone (just like Samsung can do that from the samsung account). I remember seeing at least one guy on the web complaining about exactly that happening to him from Knox when he moved to another job.

If anyone wants to test a phone wipe, send me a pm. I could set something up temporarily.
Sent from my SM-N9005 using xda app-developers app

Related

How can I unsynchronize my gmail with my G1?

I'm going to guess it is with a hard reset, but I don't want to mess with all the apps I downloaded. I was able to delete all my contacts so it is fine, but I'm thinking it might automatically sync up with my gmail and download my contacts or erase my contacts online after I sell the phone. What are my options?
or maybe I can set it to a different gmail, but how do I do that? Or maybe it is really simple, just change the password on my gmail account, that should work right?
Ok, changing my password worked, but now it seems to be stuck on asking for my password, but not giving the next person the option to change accounts, or how can I manually change it to a different gmail?
if you want to remove your details before selling the phone, try a factory reset. or you can go into the google app data in the applications management and clear the data there.
Yeah, I was able to clear all data, but was just concerned the phone would have my gmail password and access my data again so changing the password worked. It just got stuck asking for my password when I pretended to want to add phone number by syncing. I'm rebooting now too see what it asks for now.
But I guess there is no way to connect it to another gmail account without doing a factory reset? Doesn't a factory reset eliminate all the programs I installed that are non market? I can reinstall, but if I sell it to a noob they might have a problem.
Are you rooted? If so, there should be a setting in the development app to unsync with google. (I might be wrong though, deleted the app, lol).
jeffrimerman said:
Yeah, I was able to clear all data, but was just concerned the phone would have my gmail password and access my data again so changing the password worked. It just got stuck asking for my password when I pretended to want to add phone number by syncing. I'm rebooting now too see what it asks for now.
But I guess there is no way to connect it to another gmail account without doing a factory reset? Doesn't a factory reset eliminate all the programs I installed that are non market? I can reinstall, but if I sell it to a noob they might have a problem.
Click to expand...
Click to collapse
AFAIK, that's a deliberate feature so that you can't pay for an app on one account and sign in with it on multiple phones, then unsync and keep the apps (thereby stopping people from getting apps from their friends for free).
Dude wtf? Just do a hard reset and it will ask you to log back into google. As long as you DON'T log back in, what on earth makes you think it's going to sync your contacts back up?
r3s-rt said:
Dude wtf? Just do a hard reset and it will ask you to log back into google. As long as you DON'T log back in, what on earth makes you think it's going to sync your contacts back up?
Click to expand...
Click to collapse
WTF r3s-rt!! wanna make something out of it, hehe jk. I guess you weren't reading the posts. It was already taken care of with changing my password in the edit. Also, I'm guessing you're a noob and don't realize a hard reset will put it into it's factory settings and I specifically said when selling it, I didn't want to give them a phone with nothing on it. It's all set up with wifi tether and a bunch of other cool things. I'll let the new buy purchase and decide what they want to do. Also, yes if just deleting all the info and not changing my password, but leaving it linked to my google it would indeed sync to my gmail if the new user so chose. I killed to birds by simply changing my gmail password. Of course it wouldn't sync after doing a hard reset, wtf!! geez
jeffrimerman said:
WTF r3s-rt!! wanna make something out of it, hehe jk. I guess you weren't reading the posts. It was already taken care of with changing my password in the edit. Also, I'm guessing you're a noob and don't realize a hard reset will put it into it's factory settings and I specifically said when selling it, I didn't want to give them a phone with nothing on it. It's all set up with wifi tether and a bunch of other cool things. I'll let the new buy purchase and decide what they want to do. Also, yes if just deleting all the info and not changing my password, but leaving it linked to my google it would indeed sync to my gmail if the new user so chose. I killed to birds by simply changing my gmail password. Of course it wouldn't sync after doing a hard reset, wtf!! geez
Click to expand...
Click to collapse
Most Rom's let you skip the signing google part, but it wont let you download anything from the market so you can install via adb
jeffrimerman said:
WTF r3s-rt!! wanna make something out of it, hehe jk. I guess you weren't reading the posts. It was already taken care of with changing my password in the edit. Also, I'm guessing you're a noob and don't realize a hard reset will put it into it's factory settings and I specifically said when selling it, I didn't want to give them a phone with nothing on it. It's all set up with wifi tether and a bunch of other cool things. I'll let the new buy purchase and decide what they want to do. Also, yes if just deleting all the info and not changing my password, but leaving it linked to my google it would indeed sync to my gmail if the new user so chose. I killed to birds by simply changing my gmail password. Of course it wouldn't sync after doing a hard reset, wtf!! geez
Click to expand...
Click to collapse
Will the new user not therefore be able to use their own Gmail without losing the apps you installed?

[Q] Encrypted Nexus 10. Decrypt worked twice and no longer accepts pin.

I have a Nexus 10. I wanted to add my corporate email to the device. When I did I was told I had to add a pin number and encrypt the device. I performed both of these actions no problem. I rebooted the device twice during all of this and was able to enter my pin successfully and use the device.
Fast forward to this afternoon. After using the device for awhile I determined that the slowness caused by the encryption was no longer worth having my corporate account on the device.
I go into Settings and delete the corporate account. I tried to go into Security to remove the pin and encryption but both were greyed out. I thought all I had to do was reboot the device and I would be able to disable both.
I rebooted and now I'm stuck at the "Type password to decrypt storage". My pin no longer works on this screen. It keeps giving me a response of "Try again."
Does anyone know what's going on or how I can fix this?
I'm guessing the security is messed up (somehow, don't know how) from removing the corporate account.
But, just for future reference, the only way to remove encryption from an Android device is to factory reset it. It's not as simple as just going into security and removing encryption.
Sent from my Nexus 7 using xda premium
squshy 7 said:
I'm guessing the security is messed up (somehow, don't know how) from removing the corporate account.
But, just for future reference, the only way to remove encryption from an Android device is to factory reset it. It's not as simple as just going into security and removing encryption.
Sent from my Nexus 7 using xda premium
Click to expand...
Click to collapse
I heard and seen otherwise. I was shown, by someone who has a Nexus 10, that you can remove the encryption as long as you remove the account and removed the device from the OWA site.
Unfortunately, that person is no longer available to me to help.
So basically I'm screwed and all of my information on the device is gone. No one else has any thoughts?
Well, your data is probably lost, but you can easily factory reset it from recovery.
Skullpuck said:
I heard and seen otherwise. I was shown, by someone who has a Nexus 10, that you can remove the encryption as long as you remove the account and removed the device from the OWA site.
Unfortunately, that person is no longer available to me to help.
So basically I'm screwed and all of my information on the device is gone. No one else has any thoughts?
Click to expand...
Click to collapse
I think you can skip the password via adb. http://forum.xda-developers.com/showthread.php?t=1800799
lKBZl said:
I think you can skip the password via adb. http://forum.xda-developers.com/showthread.php?t=1800799
Click to expand...
Click to collapse
Unless I misread, or misunderstood it looks like that'll only work for *pattern* unlock not pin.
Edit: Nevermind, it looks like this post in that thread might have your answer:
http://forum.xda-developers.com/showpost.php?p=30285850&postcount=12
To the OP, if it's a simple pin, a brute force script or program could make short work of it in minutes (or hours at most; depending on length of password).
Skullpuck said:
I heard and seen otherwise. I was shown, by someone who has a Nexus 10, that you can remove the encryption as long as you remove the account and removed the device from the OWA site.
Unfortunately, that person is no longer available to me to help.
So basically I'm screwed and all of my information on the device is gone. No one else has any thoughts?
Click to expand...
Click to collapse
You saw a way to remove certificates for your corporate email account, not remove encryption from your device.
There is only one way to remove device encryption, and that is by factory reset, by design. It wouldn't be very secure otherwise.
Skullpuck said:
I heard and seen otherwise. I was shown, by someone who has a Nexus 10, that you can remove the encryption as long as you remove the account and removed the device from the OWA site.
Unfortunately, that person is no longer available to me to help.
So basically I'm screwed and all of my information on the device is gone. No one else has any thoughts?
Click to expand...
Click to collapse
Sorry, you heard wrong, or you were listening to a fruitcake. By definition you cannot "remove" encryption. It changes the whole file.
Think of it like this. I just scrambled an egg. Then I'm like "oh no! I don't like scrambled eggs! Can someone help me remove the scramble?"
It's not that easy. Sure, there is brute force, if your apps were THAT important it might be worth it to try.
But the short solution: factory reset your data, or give it the pin it wants.
Swiped from my Nexus 10 using xda-developers app
In the future, NEVER use the corporate account system built into iphone / android, this let's your company apply security policies that can wipe your device remotely, and your encryption junk. Use something like Touchdown app which still syncs your contacts, emails, and calendar into your device for any other app to use, but the security policies only get applied to Touchdown. I know this from experience when my former company's IT department "accidentally" wiped everybody's devices messing around in Exchange. "Whoops."

[Q] Knox Email Account - How do I get it setup?

Loving my Note 3 so far. I want to get my corporate email (activesync) setup using Knox. I've installed Knox and it seems to be working fine switching between the two 'environments' but when I go to add a Knox Email account or a Knox Active Sync account I can't type anything into the email and password boxes.
It will let me add a normal exchange account but it won't let me add a Knox exchange account. The whole point of Knox is to keep my corporate and personal accounts separate so I'm really confused as to why it won't work.
Has anyone overcome this yet? I've searched and googled for hours but there is literally no documentation that I can find from Samsung and a search on these forums didn't bring anything back either.
Any help would be really appreciated. Cheers.
Might be a really silly suggestion...
But which keyboard are you using? It is possible that a 3rd party one isn't authorized to be run in the Knox environment. (That's how these things work on a pc, anyway. My Note 3 is still on order.. *grumble*)
ShadowLea said:
Might be a really silly suggestion...
But which keyboard are you using? It is possible that a 3rd party one isn't authorized to be run in the Knox environment. (That's how these things work on a pc, anyway. My Note 3 is still on order.. *grumble*)
Click to expand...
Click to collapse
You beauty! You were absolutely right, definitely not a silly question! Knox does not like 3rd party keyboards and to fix my issue I have to use the Samsung keyboard. A little annoying because I can't even revert to the Google keyboard on the non-knox side of my phone once the account has been added. I can't just use the Samsung keyboard for just the Knox side of the phone.
Hopefully there'll be a workaround in the future. Thanks for your help mate!

Email encryption issue

My company has decided to implement some new policies. In order to access the Exchange Server from a cell phone, they want to set up to be an Admin of the phone, force a PIN and auto screen timeout and have access to remote wipe the device.
They also want to force the phone to be encrypted. That last part, I am not cool with. This is my device and I have had issues in the past with an encrypted phone, where it slows things down, and it makes it inconvenient when you want to copy files to and from the device, like pictures, videos, downloads and music... copying from the encrypted device to the PC, the files were unusable.
MY files, not theirs.
So on my Moto RazR HD, I remember rooting the phone and installing a modified .APK for the Exchange client, that let me set up my account, and when I got to the part that it demanded the device to be encrypted, it simply ignored it and tricked the server into thinking that it had already been done.
So my question is, can I root this phone, install a similar .apk, and then unroot the phone(they claim they will check to see if phones are rooted or jailbroken), and then set up my email account?
Anyone think of a way to accomplish this?
I don't need arguments on how I should obey policy and all that, so let's not go there. If it is get my phone encrypted and possible cause problems on a personal device that I paid $600 for, or not having email on it and inconveniencing others when they can't get ahold of me, I will not have email on the device.
But if I can keep it from encrypting, but keep all the other security in place(PIN, timeout and remote wipe), I am fine with that.
Can this be done today? Is there still a modified exchange.apk or whatever, or maybe another email client that is simple, close to the stock on in look and feel, but won't force the encryption policy?

Locked out of Phone, No Google Password

Hello!,
Just recently purchased an unlocked S7 SM-G935F phone several weeks back, and got locked of the google account. I can't get password from google because I think the password was compromised. Google refuses to provide the password or reset it. So, my question is how can I modify this phone without having the developers tab tap 7 times get back to it's original firmware? Any advice would be appreciated. Thanks in advance!
Sorry but you didn't give enough information.
First of all, if the phone is not yours, give it back to the owner or don't try to access data without passwords: it is illegal, though impossible too.
If it's your legitimate property you can reset your google password with the methods you configured. If you find no way suggested to recover your password you will have to contact directly google customer service and hope they will try to verify your identity and give you someway access to your data, and device too.
The thing of developer option it's not correlate to your problem, maybe you want to install a custom aoftware (rom, kernel etc) but you didn't say that. And anyway there are tons of guides which you maybe already read. If your device is locked there's no way to recover it without your google password. Don't try flash strange things you will brick it.
Suspect
Sprov said:
Sorry but you didn't give enough information.
First of all, if the phone is not yours, give it back to the owner or don't try to access data without passwords: it is illegal, though impossible too.
If it's your legitimate property you can reset your google password with the methods you configured. If you find no way suggested to recover your password you will have to contact directly google customer service and hope they will try to verify your identity and give you someway access to your data, and device too.
The thing of developer option it's not correlate to your problem, maybe you want to install a custom aoftware (rom, kernel etc) but you didn't say that. And anyway there are tons of guides which you maybe already read. If your device is locked there's no way to recover it without your google password. Don't try flash strange things you will brick it.
Click to expand...
Click to collapse
Nope, it's my phone. I purchased it several weeks ago as mentioned before. I have a receipt from Amazon as proof. I honestly got locked out of the phone and can't recall the exact password because I probably tossed it away. I've called google 4 times still no avail. I would like to install a custom rom if possible. Any other suggestions? Id be willing to donate a few bucs.
JoeJingle92 said:
Nope, it's my phone. I purchased it several weeks ago as mentioned before. I have a receipt from Amazon as proof. I honestly got locked out of the phone and can't recall the exact password because I probably tossed it away. I've called google 4 times still no avail. I would like to install a custom rom if possible. Any other suggestions? Id be willing to donate a few bucs.
Click to expand...
Click to collapse
Then go back to the Amazon seller and ask him/her.
I'm sorry but if you write here on xda you will likely find people who know what is going on. And anyone would be suspicious if you're asking to bypass a security lock. There are 2 cases, one is that that ain't not your device, the other is that you're so dumb to lock a 700$ device with a password you don't remember saying bull****s like " the password was compromised " or, which is fantastic, " I called Google 4 times" like if they have a number to call to get Samsung assistance. I'm really happy theres no way to acces phone without correct psw, but if you want you can keep waisting your time.Mods please throw away this tief
You forgot or "lost" your Google password? This doesn't sound right.
Why not recover your Google password using their online system?
"I cant recall the password because I probably tossed it away"
Love the "probably". Can be hard to keep track of bulls***.
Make your mind up - find a lie and stick to it. Did you probably toss it away or is the password "compromised"?
Good luck trying to fool anyone in here to help you out with your "problem".
If it was legitimately yours, then you would've set up a fingerprint and not only a password, don't you think that would've been smart? That way you would've not been "locked out of phone". Emphasis on "If it was legitimately yours".
Smell test is clear...
Password was compromised, password was tossed away... sounds legit!
I've actually done what this guy has but I did it on a freshy right outta the box with me swing the first owner. However this does seem suspect I would help if I knew you were the first and only owner but seeing you're not I cant.
I'm in the same boat. My father-in-law somehow got his S7 edge locked and forgot his google password at the same time. He went to a Verizon store, but they only told him to recover via google. He shipped the phone to me to try and help him unlock it. Google password recovery is by 3 methods:
1) send a text to the phone. Of course this doesn't help because I can't unlock the phone. I hear the tone when the text comes in, but can't retrieve it
2) Sends a code to another email associated with the google account. He swears its his daughter's email address, but when we put that code in, google says it doesn't recognize her email as authorized
3) tell google what month & year the account was created. He can't remember that either
At this point, I'm willing to pay someone to fix it. I believe it has the newest Nougat firmware. I tried many suggestions from YouTube, but I can't even get to the menu where you connect to a wifi signal.
Anyone willing to help or just think I stole the phone like the previous guy?
Dave
deptrai1 said:
1) send a text to the phone. Of course this doesn't help because I can't unlock the phone. I hear the tone when the text comes in, but can't retrieve it
Click to expand...
Click to collapse
Put the SIM into another phone and receive the SMS. Simple.
the_scotsman said:
Put the SIM into another phone and receive the SMS. Simple.
Click to expand...
Click to collapse
THANK YOU!. At least I made some progress. Now I find myself in an endless loop...the phone keeps saying "This device was reset. To continue, sign in with a Google Account that was previously synced on this device".
My father-in-law has 2 Google accounts. Having put his sim in my phone, I was able to reset passwords for both of these Google accounts, but the phone doesn't like either of them.
Any more suggestions?
Oh. Without the sim, I was finally prompted to connect to a wifi.
Is it possible that no Google account was synced with this device?
guys... try to fix ur google accounts in a pc .. after u finish and u have the email and the password. just enter it to the phone.. u dont need to doo all the work from the phone
thebiggboss180 said:
guys... try to fix ur google accounts in a pc .. after u finish and u have the email and the password. just enter it to the phone.. u dont need to doo all the work from the phone
Click to expand...
Click to collapse
I've fixed (can now log in) two of my father-in-law's google accounts. Its just that the phone isn't recognizing either of them now. I don't know if he has a 3rd account of if it was possible to set up the phone without one. I'm on Verizon with an iPhone so I don't know anything about android or google.
Read that you have to wait 24 hours after changing Google password, so I'll try it again tonight.
the scotsman - You are my F*CKING hero! 24 hours after resetting the google password, the S7 edge recognizes it and is now unlocked. My father-in-law (& mother-in-law) thank you.
Dave

Categories

Resources