All managed apps suspended at once (greyed out, "app disabled") on dedicated Intune device | How to detect affected devices proactively?
Hi,
We run a retail fleet of Android Enterprise dedicated (COSU) devices managed by Intune, with Entra shared device mode and no Managed Home Screen. Devices are Samsung Galaxy XCover6 Pro (SM-G736B), Android 15, build G736BXXSAFYJ3, enrolled via KME, with KSP Premium, KAI and E-FOTA. All our apps are on the KSP battery optimization allowlist.
This is the same environment as these two earlier threads, but the symptoms this time are different, so I'm posting it separately:
- "Disabled apps" (Feb 2025): https://www.androidenterprise.community/android-enterprise-general-discussions-3/disabled-apps-1156
- "Intune app disabled" (May 2026): https://www.androidenterprise.community/android-enterprise-general-discussions-3/intune-app-disabled-2570
What happened this time (Aug 31, ~12:00 UTC+2, one device so far):
- Every Intune-managed app was disabled simultaneously: Intune app, Authenticator, Remote Help, Knox Remote Help, Knox Asset Intelligence, our POS app, our own settings app.
- Icons were greyed out on the launcher, and tapping one showed a toast "app disabled".
- No Enable button in Settings > Apps, and nothing in Play Store either. This is different from our earlier cases, where apps kept normal icons, were still launchable, and Play showed an Enable button that just did nothing.
- The device's last Intune check-in was 11:58 — about two minutes before the incident window.
- In Intune everything was green throughout: device compliant, all configuration profiles "Succeeded", all managed apps installed.
Because KAI, Knox Remote Help and Remote Help were suspended along with everything else, we had no way to pull logs remotely, and the store had to factory reset the device to resume operations. A bug report taken after the reset contains nothing from the incident itself.
The symptom set (greyed launcher icons + system toast + no enable path anywhere + everything at once) looks like device-owner package suspension - i.e. Android Device Policy's compliance enforcement block - rather than the Samsung MARs/auto_disabler behavior from our other thread (which shows enabled=4 and a dead Enable button in Play). But the device was fully compliant and green from the Intune side, so we can't see what ADP might have objected to.
My questions are less about this one device and more about the fleet:
- Is this a known issue? Is Google aware of dedicated/fully managed devices getting all apps suspended by Android Device Policy while the EMM (Intune) reports the device as fully compliant?
- Is there anything we can do proactively to identify devices that are heading toward this state before they break? With Intune as the EMM we have no visibility into ADP's compliance view, everything looks green right up until the device is unusable.
- Has anyone else running dedicated devices with Intune seen this full-suspension behavior?
This is the third variant of "managed apps get disabled" on this fleet, and each one has been worse than the last. In the first cases, only "unimportant" apps like Edge were affected, and we could recover by updating, or reinstalling the app - though when the Intune app itself got disabled, only a wipe fixed it. Crucially, in those cases most managed apps kept working, including Knox Asset Intelligence, so we could still pull dumpstate logs and investigate. This time everything was disabled at once, including KAI - so we had no way to collect any evidence at all. These devices are in stores in other countries: shipping them to us or having store staff run ADB isn't realistic. So any pointer toward early detection, or a log path that survives this state, would be hugely appreciated.
Thanks!
