Skip to main content

2026년 9월 4일

Application Removal Protection (Modernized)

Application Removal Protection (ARP) is a safety feature that prevents the accidental removal of important internal applications from managed devices. When applications are removed from devices surpassing the permitted device limit within a specified timeframe, the ARP automatically blocks further removals, allowing administrators to review and approve the changes before they proceed.

This feature helps organizations avoid disruption to business operations by ensuring that critical enterprise applications are not accidentally removed from devices due to assignment changes, smart group modifications, or other configuration updates.

How to Configure Application Removal Protection

To configure ARP threshold settings at a Customer type organization group in the Workspace ONE UEM console, follow the listed procedure.

  1. Navigate to Groups & Settings > All Settings > Apps > Workspace ONE > App Removal Protection.

    App Removal Protection

  2. Enter the following threshold settings:

    SettingDescription
    Devices AffectedThe default value is 100.
    Enter the maximum number of devices from which the app can be removed within the configured time window before ARP is triggered. The app is silently removed from the first (n‑1) devices as they check in. When the nth device checks in, ARP is triggered, and app removal is paused.
    Within (minutes)Default value is 10 minutes.
    Specify the time duration within which reaching the Devices Affected threshold will trigger ARP.
    Allow Removals without Protection (hrs)The default duration is 24 hours, but you can modify this value based on your requirement.
    Specify the number of hours for which app removals can continue without any protection once ARP is unpaused.
    Email TemplateSelect an email notification template and make customizations. The system includes the App Remove Limit Reached Notification template, which is specific to the app removal protection.
    Send Email toEnter email addresses to receive notifications about paused removals so that you are notified and can take timely actions.
  3. Click Save.

How Application Removal Protection Works

In modernized SaaS‑based UEM, ARP is evaluated during each device check‑in, whereas with legacy UEM, ARP evaluation occurred only when assignment updates were published.

When a device checks in, the system evaluates whether the 'Devices Affected' threshold for the app has been reached within the configured time window.

For any given app, the ARP time window begins when the first device checks in and qualifies for app removal. If, at the time of check‑in, the count of affected devices has not reached the configured threshold within the active time window, the app is silently removed from the device. This silent removal continues with each device check-in until the threshold is met within the current time window. The system tracks the number of affected devices from which the app has been removed. ARP is triggered immediately when the affected device count meets the threshold within the active time window. At this point, app removal is paused on the device that reaches the threshold, and no further removals occur on subsequent device check-ins until an admin manually unpauses them.

If the threshold is not met by the end of the active time window, ARP is not triggered. In such a scenario, the affected device count is reset to zero, and a new time window begins for the ARP evaluation when the next device checks in.

Devices that lose an app due to assignment deletions, app deletions, or Smart Group changes are counted toward the Devices Affected threshold. Devices losing the app as a result of forced removals are not counted towards reaching this threshold.

Review App Removal Logs

You can review apps that have been removed from devices or for which removals are paused from the App Removal Logs page in the UEM console. To view the page, navigate to Monitor > Events and Logs > App Removal Logs.

For an app, you can view the removal log entry having details such as app name, bundle ID, impacted device count, and status.

When the ARP is triggered, app removals are blocked unless you take action to unpause or dismiss them. In this state, the App Removal Logs page displays two types of log entries:

  • Unpaused (grayed out): Shows the number of devices where the app was already removed before the threshold was reached. This entry does not require any action.
  • Paused (actionable): Shows the count and list of devices where app removal is blocked. You can select these entries to Unpause or Dismiss the removals.

The log entries can be filtered on status or bundle ID. They can be sorted based on Last Modified, App Name, and Bundle ID.

App Removal Protection

To unpause removals, select the app with a Paused status and click Unpause. After unpausing, the app is removed from any device that checks in and loses the app. Once unpaused, removals continue uninterrupted for the duration configured for the ‘Allow Removals without Protection (hrs)’ setting, regardless of the number of impacted devices.

If you do not want the app to be removed from devices, you can choose to dismiss the paused removal by clicking Dismiss. Before dismissing, restore any assignments, resources, or smart groups that were mistakenly removed.

Restoring unintended updates ensures that when devices check in next, UEM detects a valid assignment for them and does not attempt to remove the app. If mistakenly removed configurations are not restored, the app will keep being removed from devices as they check in, until the Devices affected threshold is met again within the subsequent time window.

Important Considerations

  • You are advised to review and update the ‘Devices Affected' and ‘Within (minutes)’ settings to avoid silent removal of the app from a large number of devices before ARP gets triggered. Consider reducing the ‘Devices Affected' and increasing the ‘Within’ time duration.
  • A new setting, 'Allow removals without protection (hours)' has been introduced in modern SaaS UEM environments, which allows removals without protection for the defined duration after removal is unpaused. You may want to review and reduce this threshold to avoid unrestricted removals for an extended duration.

이 페이지가 도움이 되었나요?

이 항목에 대한 피드백 보내기

이 항목이 도움이 되었나요?

개인정보나 기밀정보는 입력하지 마세요.

링크를 생성하는 중…