Skip to main content

 

Cisco Meraki Documentation

How to Remove Profiles and Apps from Managed Devices

Overview 

This article explains how to remove profiles and managed apps from Systems Manager endpoint devices remotely through the Cisco Meraki dashboard. It covers several methods, from removing content across all devices to targeting a single device, and describes what to expect on the endpoint after removal. 

Use the method that matches your goal: 

  • Remove a profile or app from all devices, either permanently or temporarily. 
  • Remove profiles or apps from a group of devices. 
  • Remove profiles or apps from a single device. 
  • Remove all profiles and apps from one or more devices using a selective wipe. 

Only managed apps can be removed. If a user installed an app manually or through another means, you cannot remove it remotely from Systems Manager. 

Step-by-step instructions 

Remove profiles and apps from all devices 

Choose one of two approaches, depending on whether you will need the profile or app again in the future. 

Permanent removal 

If you will not need the app or profile again, delete it from Systems Manager. After deletion, it is removed from all devices on which it was previously applied. 

To delete the app(s): 
  1. Go to Systems Manager > Manage > Apps

  1. Select the checkbox(es) next to the app(s) to delete. 

  1. Select Delete

  1. The app(s) about to be deleted are highlighted in a red hue. 

  1. Select Save to confirm deletion. 

Deleting an app on the Meraki Dashboard

To delete the profile(s): 
  1. Go to Systems Manager > Manage > Settings

  1. Select the profile to delete. 

  1. Scroll to the bottom of the page and select Delete this profile

  1. Select OK to confirm deletion. 

  1. Repeat steps 2, 3, and 4 for any additional profiles to delete. 

  1. Select Save to confirm the changes. 

Deleting a profile on the Meraki Dashboard

Temporary removal 

If you may need to reapply the profile or app later, modify its scope so it no longer includes any devices. 

To temporarily remove the app from all devices: 
  1. Go to Systems Manager > Manage > Apps

  1. Select the app to temporarily remove from all devices. 

  1. Go to the Targets section and change Scope to No devices (disabled)

  1. Devices with the pending app removal are highlighted in a red hue. 

  1. Select Save to confirm the changes. 

Temporarily removing an app from managed devices

To temporarily remove the profile from all devices: 
  1. Go to Systems Manager > Manage > Settings

  1. Select the profile to temporarily remove from all devices. 

  1. Go to the Targets section and change Scope to No devices (disabled)

  1. Devices with the pending profile removal are highlighted in a red hue. 

  1. Select Save to confirm the changes. 

Temporarily removing a profile from managed devices

Remove profiles and apps from a group of devices 

To remove one or more profiles or apps from multiple devices, use one of these methods: 

  • Force uninstallation of the app from selected devices (this does not apply to profiles). 

Once a device is out of scope, it no longer appears under the Devices in scope section of the profile or app page. 

To force uninstallation of an app from selected devices: 

  1. On the Systems Manager > Manage > Apps page, select the app to remove. 

  1. Under the Devices in scope section, select the checkbox next to any devices that should have the app removed. 

  1. Select Systems Manager > Manage > Uninstall

For app removal to be permanent, you may also need to remove the device from scope. Otherwise, the app may be reinstalled later. 

Remove profiles and apps from a single device 

To remove one or more profiles or apps from a single device, modify the tags associated with that device to remove it from the scope of the profile(s) or app(s). 

Alternatively, remove specific apps manually: 

  1. Go to Systems Manager > Monitor > Devices and select the device. 

  1. Under Apps, find the row for the app to remove. 

  1. Select Remove

For app removal to be permanent, you may also need to remove the device from scope. Otherwise, the app may be reinstalled later. 

Remove all profiles and apps from devices 

To remove all profiles and apps from one or more devices, perform a selective wipe and place the device(s) into quarantine. This removes all managed profiles and apps as soon as possible and prevents any additional profiles or apps from being deployed. Quarantine remains in effect, regardless of any tags applied, until you remove the device(s) from quarantine and authorize them again. Use this method when a device should have no managed content or settings but should still be tracked and controlled in Systems Manager. 

To perform a selective wipe: 

  1. Go to Systems Manager > Monitor > Devices

  1. Select the checkbox(es) next to the device(s) to have all profiles and apps removed. 

  1. Select Quarantine > Selective wipe

  1. When you browse to a specific device, a warning indicates that the device is in quarantine. 

Device details page will show the client is quarantined banner

For more details, refer to the  knowledge base article on selective wipe.

Disable the auto-install option 

You can configure apps not to auto-install or auto-remove. The disable auto-install option appears on the app details page beneath Scope. When you select this option, apps are NOT automatically removed when an endpoint device leaves scope. In that case, the user must uninstall the app manually, or you must use the Systems Manager > Manage > Uninstall option under the Devices in scope section.

Verification 

Confirm removal from the device details page. Go to Systems Manager > Monitor > Devices and select the endpoint to check. 

  • Profiles: After a profile is removed, it no longer appears under the Profiles section of the device details page. 

  • Apps: After an app is removed, it no longer appears under the Apps section of the device details page. An entry also appears in the Activity log showing that the app was removed, or that removal is pending. 

Device activity log shows command is pending

Troubleshooting 

Endpoint behavior on removal: 

  • After you queue a managed app or profile for uninstallation, the endpoint processes it once it receives the command. The time this takes varies by device and other factors. 
  • Ensure the endpoint is unlocked, powered on, and connected to a wireless network or mobile data so it can receive the command. 
  • If you remove Wi-Fi settings, and no other auto-join networks are configured and mobile data is not enabled, the device cannot communicate with Systems Manager or the internet after removal until someone manually reconnects it. 

Only managed apps can be removed. If a user installed an app manually or through another means, you cannot remove it remotely from Systems Manager. 

Platform-specific behavior: 

  • iOS devices: Apps, profiles, and associated settings are removed in the background once the device is unlocked. The user is not prompted. 
  • Android devices: Users are prompted to remove apps via notification. Once confirmed, the app is uninstalled. Profiles and associated settings are removed silently in the background.