How-Tos

How to Remove a Work Profile from Android

Work profile removal on Android differs by who initiates it, employees use Settings, IT admins work through an MDM console. Here's both paths, step by step.

Mountain landscape representing leadership perspective and vision
Written by
Trio Content Team
Published on
06 Apr 2026
Modified on
06 Apr 2026

An employee is leaving, and their personal Android phone still has a work profile on it. Knowing how to remove work profile from Android sounds simple, but it means two different things depending on who is doing it. The employee taps through device Settings. The IT admin initiates removal from an MDM console. Both paths end at the same result, but the steps and consequences are different.

The most urgent question is usually about data. Removing a work profile deletes only the corporate container, the apps, email, files, and configurations that live inside it. Personal photos, personal apps, personal accounts, and contacts are completely untouched. This separation is enforced at the Android OS kernel level across processes, memory, and storage. It is not a policy setting that can be toggled off.

The employee path to remove work profile Android is: Settings > Accounts > Work tab > Remove Work Profile. The IT admin path runs through the MDM console, initiate a selective removal, and it executes on the device's next check-in. The enrollment mode (BYOD work profile vs. fully managed device) determines which path applies and what gets deleted.

This guide covers both removal paths step by step, the difference between BYOD and company-owned device offboarding, the post-removal checklist IT admins need to close out an offboarding properly, version-specific behaviors in Android 14, 15, and 16, and what to communicate to employees before the process starts.

TL;DR
  • Removing a work profile deletes only corporate apps, email, and data, personal photos, apps, and accounts are never touched.

  • Employees: go to Settings > Accounts > Work tab > Remove Work Profile and confirm. No factory reset needed.

  • IT admins: initiate a selective removal (sometimes called Retire or Enterprise Wipe) from the MDM console, it runs on the device's next check-in, not instantly.

  • For company-owned fully managed (Device Owner) devices, a full factory reset is required, not a selective work profile removal.

  • After removing the work profile, also delete the device record from your identity provider (e.g., Microsoft Entra ID) to fully cut corporate access.

  • On Android 16+, any corporate-managed eSIM on a BYOD device is always wiped when the work profile is removed, new behavior to be aware of.

What an Android Work Profile Actually Is

If you already know how Android work profile separates corporate and personal data at the OS level, skip ahead to the next section. If not, the definition matters for understanding why removal works the way it does.

A work profile is a distinct, OS-enforced container within the device, not a folder, not an app, not a toggled setting. It runs as a separate user profile at the Android kernel level, with its own process space, memory allocation, and storage. Apps installed inside the work profile appear with a briefcase badge to distinguish them from personal apps. The two sides of the device cannot access each other's data by default.

This architecture is why personal data is genuinely safe during work profile removal. The corporate container is deleted as a unit. The personal side is structurally separate and unaffected.

Profile Owner vs. Device Owner: Why the Difference Matters

The enrollment mode set at device provisioning determines what IT can control, and what removal method applies at offboarding.

  • BYOD / Profile Owner (PO): The device is employee-owned. IT manages only the work profile container. Removal is a selective action, only the work profile goes.
  • Fully Managed / Device Owner (DO): The organization owns the device. IT manages the entire device. Offboarding requires a full factory reset, not a selective removal.
  • COPE (Corporate-Owned Personally Enabled, Android 11+): Organization owns the device but the work profile is a separate container for the personal side, selective work profile deletion applies, personal data is preserved, and the device reverts to unmanaged.

Getting the enrollment mode wrong at offboarding is where problems start. Applying a factory reset to a personal BYOD device wipes everything on it, not just the work profile.

How to Remove a Work Profile from Android, Both Paths

There are two distinct removal paths for android byod devices, and which one you take depends on who initiates it. The employee self-service path works through device Settings and is appropriate for unenrolled devices or admin-confirmed self-removal. The IT admin path runs through the MDM console and is the correct method for formal employee offboarding, it creates an audit trail and integrates with identity provider cleanup.

Path 1- The Employee Steps (Personal BYOD Device)

Questions like "how to remove my work profile from Android" or how to delete work profile Android come up most often from employees who have already left, or who are going through a self-service offboarding process. The standard steps on most Android devices are:

  • Open Settings
  • Tap Accounts (labeled "Passwords, Passkeys & Accounts" on newer Android versions)
  • Tap the Work tab
  • Tap Remove Work Profile
  • Confirm deletion when prompted

No factory reset is required. No personal data is deleted. The process takes under a minute.

If the Remove Work Profile option is greyed out or missing, the MDM policy has restricted user-initiated removal, the IT admin needs to initiate it from the console instead.

Samsung-Specific Removal Steps

For employees asking how to take work profile off Android on a Samsung device, the menu path differs from stock Android due to Samsung Knox.

  • Android 9 and above: Settings > Accounts and Backup > Manage Accounts > Switch to Work tab > Uninstall Work Profile
  • Older Samsung devices (Android 8 / Knox): Settings > Workspace > Uninstall Workspace

The outcome is identical, only the work container is removed, personal data is untouched.

Path 2- The IT Admin Steps (MDM Console)

For formal employee offboarding, the MDM console is the correct path. It provides documentation, ensures proper data removal, and connects to identity provider cleanup. The general process across platforms:

  • Open your MDM admin console and navigate to the device inventory
  • Locate the departing employee's device
  • Select the selective removal action, the label varies by platform (common labels include "Retire" or "Enterprise Wipe")
  • Confirm the action, removal executes on the device's next check-in
  • Delete the device record from your identity provider separately

Platform note: For Android personally-owned work profile devices, only the selective removal action is valid. Full wipe is not supported on personally-owned Android work profile devices in this enrollment mode.

If the work profile is still showing on the device an hour after you initiated removal, check whether the device has been online and connected, the retire action only runs on the next MDM check-in.

The removal runs on the device's next check-in. For immediate security needs, revoke the employee's credentials and cloud access first, then let the MDM removal follow. Credential revocation is the fast-acting control; MDM removal is the device-layer cleanup. If the employee is still cooperating, ask them to open the Company Portal app to force a check-in, otherwise wait for the standard sync window.

After the MDM console shows the device as retired, the device record remains in your identity provider until you manually delete it. Skipping this step leaves the former employee's device identity active in your directory.

Android Work Profile Removal: Enrollment Mode Comparison

Enrollment ModeDevice OwnershipIT Admin ControlsRemoval MethodPersonal Data Affected?
BYOD / Work Profile (Profile Owner)Employee's personal deviceWork profile onlySelective removal via MDM console (Retire) or Settings > Remove Work ProfileNo, personal data untouched
Fully Managed (Device Owner)Company-ownedEntire deviceFactory reset requiredN/A, company-owned device
COPE (Android 11+)Company-ownedFull device + separate personal work profileWork profile deleted; personal data preserved; device reverts to unmanagedNo, personal data preserved
Basic RMM / Device Admin (Legacy)BYOD or company-ownedLimited (legacy)Manual removal; policy enforcement limitedVaries, depends on enrollment
No MDM EnrollmentEmployee's personal deviceNoneNo remote removal possible; employee must actNo admin control at all

If your fleet includes unmanaged devices, enrollment through an MDM platform is the only way to gain remote removal capability at offboarding.

What Actually Gets Deleted When You Remove a Work Profile

When removing work profile Android devices from your MDM environment, be precise about what that action covers. Removing a work profile is not the same as a remote wipe android, a full remote wipe resets the entire device and is only appropriate for company-owned fully managed devices. Work profile removal is scoped strictly to the corporate container.

What IS deleted:

  • All apps installed within the work profile
  • Corporate email accounts and all cached email data
  • Documents and files saved within work apps
  • Corporate Wi-Fi profiles, VPN configurations, and certificates scoped to the work profile
  • MDM policies and managed app configurations

What is NOT deleted:

  • Personal photos, videos, and files
  • Personal apps
  • Personal accounts (Google, banking, and others)
  • Personal contacts, unless cross-profile contact sharing was enabled by policy, in which case the merged contact list may be affected
  • Text messages and call logs
  • The device operating system

One version-specific behavior to flag: on Android 16 and later, any corporate-managed eSIM profile on a BYOD device is always deleted when the work profile is removed. This did not happen automatically on earlier Android versions. If your organization provisions corporate eSIM profiles to employee personal devices, plan for this at offboarding and communicate it to the employee in advance.

Terminology note from IT community forums: "enterprise wipe," "selective wipe," and "retire" all refer to the same scoped action for BYOD devices. They remove only the work container. The personal side is untouched in all three cases. The different labels come from different platforms, not different actions.

The personal/corporate data boundary is enforced at the OS kernel level. Neither the employee nor the MDM platform can override this separation by design.

BYOD Offboarding vs. Company-Owned Device Offboarding

The rule is simple but the consequences of getting it wrong are significant. For android device offboarding: BYOD (Profile Owner) devices get a selective work profile removal, no factory reset, personal data untouched. Company-owned fully managed (Device Owner) devices require a factory reset. That is the entire device.

Applying a factory reset to a personal device during offboarding deletes the employee's personal photos, contacts, and data. In EU contexts, this is a GDPR violation. In any context, it is a significant liability. Confirming the enrollment mode before initiating any removal action is a non-negotiable step.

If full remote control at offboarding is a priority, fully managed (Device Owner) enrollment gives you the most options. COPE is better suited for devices where employee personal use is a core requirement, but it does not give you the same level of remote control as fully managed at offboarding.

The Factory Reset Protection (FRP) Problem for Company-Owned Devices

Factory Reset Protection is an Android security feature that locks a device after a factory reset, requiring the last-signed-in Google account credentials to reactivate. For company-owned devices, this creates a well-documented offboarding complication: if an employee's personal Google account was tied to the device and FRP was not pre-configured with a corporate account, the device cannot be reactivated after reset without the former employee's credentials.

This is the most common operational failure in company-owned device offboarding, and Google's official offboarding checklist identifies FRP configuration as a required step that must be addressed before the device is issued, not when the employee is leaving.

If a factory-reset company-owned Android device is stuck on the FRP verification screen, you will need the former employee's Google credentials to proceed, or a zero-touch enrollment bypass if it was pre-configured at provisioning.

The FRP problem is almost always an onboarding oversight. Configure FRP at device issuance using a corporate Google account, or use zero-touch enrollment, which bypasses FRP entirely. By the time you are offboarding, it is too late to fix this configuration.

What IT Admins Should Do After Removing the Work Profile

After you remove a work profile from Android, the offboarding is not finished. Employees sometimes use the phrase "how to uninstall work profile android", the device-side action is one step, but the admin-side cleanup is what actually closes the offboarding loop. Here is the full checklist.

Use your android device management console to work through each of these in order:

  • 1. Confirm the work profile is actually gone. Check the device's compliance status and last check-in time in your MDM console. Do not assume the retire action completed, verify it. If the device has not checked in since you initiated removal, the work profile is still present.
  • 2. Delete the device record from your identity provider. Remove the device record from your organization's identity provider directory. Leaving it in place keeps the device's identity active in your directory even after the work profile is gone.
  • 3. Revoke all associated credentials. Email account, VPN access, SSO tokens, and corporate Wi-Fi passwords. This step should happen before or simultaneously with MDM removal, not after. Credential revocation is the immediate security action. If the MDM retire action is delayed by check-in timing, revoking credentials is what actually stops data access now.
  • 4. Document the removal for compliance. Record the date, the action taken, and confirmation that personal data was preserved. For GDPR-regulated organizations, this documentation supports the lawful basis for data removal at offboarding.
  • 5. Monitor for unexpected re-enrollment or access attempts. After offboarding, confirm the former employee cannot re-enroll or access corporate resources through any remaining credentials or device records.

Android Version Changes That Affect Work Profile Removal

How admins and employees remove a work profile from Android has changed with recent OS updates. If you manage a fleet with mixed Android versions, the behavior is not uniform across devices.

Android 14 - The Work Profile "Pause" Change

In Android 13 and below, selecting "turn off work profile" stopped all background activity in the work container. In Android 14, this became a pause, the work profile continues to sync in the background even when toggled off. This is a significant behavioral change for employees expecting that turning off the work profile stops corporate app activity during off-hours.

Android 15 - Enrollment Failures on New Devices

Multiple IT admins reported "unable to create work profile" errors on Android 15 devices during enrollment in early 2025. If you encounter this on an Android 15 device, the known workaround is using ADB commands to remove any existing work profile fragment before re-enrolling. The enterprise changes in Android 15 also brought enrollment modernization updates that affect how work profiles initialize on first setup.

Android 16 - eSIM Is Always Wiped with the Work Profile

New in Android 16: on BYOD devices, any corporate-managed eSIM profile is always deleted when the work profile is removed. On Android 15 and earlier, eSIM profiles could persist after work profile removal. If your organization provisions corporate eSIM profiles to employee personal devices, this change affects both your offboarding communication and your eSIM provisioning process going forward.

Staying current on these changes is one practical reason to select a best android mdm platform that actively tracks Android Enterprise version updates, behavioral changes like the Android 14 pause shift affect real devices in your fleet without any action on your part.

What to Tell Employees About Work Profile Removal

The single biggest obstacle to smooth BYOD offboarding is usually not the technical process, it is that nobody told the employee what to expect, and fear of losing personal data leads to self-removal or non-cooperation before the MDM process has a chance to run. Proactive communication is the fix.

Cover these points before offboarding begins. First, the company has never had access to personal apps, photos, messages, or contacts. The work profile is a separate container, and personal data has always been structurally inaccessible to the organization. Second, when the work profile is removed, only corporate apps and data are deleted, nothing personal is affected, and no factory reset occurs on a personal device.

Clarify the difference between "turn off" and "remove." Employees searching for how to turn off work profile on android are often looking for a way to pause work notifications, not permanently remove the profile. In Android 14 and later, turning it off pauses it, removal is a separate, permanent action. If they want to disable work notifications temporarily, turning off is the right option. Full removal is for offboarding only.

Finally, let them know that they may be asked to open the MDM app during offboarding to trigger a check-in. Frame this as a process step, not a surveillance action. Employees who understand what is happening are far more likely to cooperate, and cooperation matters when you need a device to check in before the standard sync window closes.

How Trio MDM Helps with Android Work Profile Management

When you need to remove a work profile from Android across a managed fleet, the MDM platform you use determines how much control and visibility you actually have at offboarding. Trio MDM is built around the features that matter most for this specific workflow.

Android work profile enrollment for BYOD: Trio MDM supports Android work profile enrollment for BYOD devices, with policies scoped strictly to the work profile container. Personal and corporate data are isolated by design, Trio MDM only accesses data within the work account and does not collect personal data. Policies apply to the work account only, not to the employee's personal side of the device.

Real-time visibility and on-demand sync: The check-in dependency is the most frustrating part of MDM offboarding workflows. Trio MDM addresses this directly with on-demand manual sync, online/offline indicators, and live last check-in tracking. When you initiate a removal, you can see the device's current status and trigger a sync rather than waiting for a default refresh cycle.

Reliable device lifecycle management: Unenrollment reliability matters specifically when hardware needs to be repurposed, a botched removal that leaves a device in a permanently locked state is a real cost. Trio MDM is built to avoid that outcome.

Compliance monitoring and audit trail: Trio MDM provides continuous compliance monitoring, automated control testing, compliance reports, and device configuration auditing. The platform logs admin panel activities, device activities, incidents, and actions taken on devices, the documentation trail that GDPR and other compliance frameworks require at offboarding is built into the product, not bolted on.

Mixed fleet support: If your organization runs Android, iOS, Windows, and macOS devices, Trio MDM manages all platforms from a single console, no separate tools for different device types.

If you manage Android BYOD devices and want the offboarding workflow to be clean and documented, start your free trial to see how Trio MDM handles work profile enrollment and removal. Or book a demo if you want to walk through the console with your specific fleet in mind.

Ready-to-use Templates

Must-have Template Toolkit for IT Admins

Explore All
Template Toolkit

Start your free trial

No credit card required
Full access to all features

Get Ahead of the Curve

Every organization today needs a solution to automate time-consuming tasks and strengthen security. Without the right tools, manual processes drain resources and leave gaps in protection. Trio MDM is designed to solve this problem, automating key tasks, boosting security, and ensuring compliance with ease.

Don't let inefficiencies hold you back.

Every organization today needs a solution to automate time-consuming tasks and strengthen security. Without the right tools, manual processes drain resources and leave gaps in protection. Trio MDM is designed to solve this problem, automating key tasks, boosting security, and ensuring compliance with ease.

Smiling womanAbstract geometric patternAbstract geometric patternSmiling womanSmiling woman

Frequently Asked Questions (FAQ)

The removal executes on the device's next check-in. Check the device's last sync time in your MDM console, if the device has not checked in since you initiated removal, the work profile is still present. If your platform supports on-demand sync, use it. If the employee is still cooperating, ask them to open the Company Portal app to force a check-in. After the check-in, confirm the device's compliance status has updated in the console.

Yes. MDM platforms can restrict user-initiated work profile removal via device policy. When this restriction is active, the Remove Work Profile option in device Settings is greyed out or hidden entirely, the IT admin must initiate removal from the console. This is useful for ensuring offboarding follows a documented process rather than an employee self-removing before formal offboarding is complete.

A self-initiated factory reset removes the work profile along with everything else on the device. This bypasses MDM logging, there is no admin-side record that the work profile was removed through the proper offboarding flow. Corporate data is gone from the device, but the device record may still show as enrolled in your MDM console until you manually remove it. This is one reason clear employee communication matters: self-removal before formal offboarding creates gaps in your audit trail.

Yes. Starting with Android 16, any corporate-managed eSIM profile on a BYOD personally-owned device is always wiped when the work profile is removed. On Android 15 and earlier, eSIM profiles could persist after work profile removal. If your organization provisions corporate eSIM profiles to personal devices, account for this when communicating offboarding steps to employees, they need to know the eSIM will be removed.

"Retire" (and equivalent labels like "selective wipe" or "enterprise wipe") refers to the same scoped action for BYOD devices: removing only the work profile and corporate data, with no effect on personal data. "Wipe" performs a full factory reset and applies only to company-owned fully managed devices. "Delete" removes the device record from the MDM console but does not trigger any action on the device itself. For BYOD offboarding, the selective removal action, whatever your platform calls it, is always the correct choice.

Related

From the blog

The related industry news, interviews, technologies, and resources.