Samsung S23 work Play Store permission error with Okta Device Trust inactiveSolved

Participant
Discussion
5 months ago Mar 06, 2026

Hi everyone. I am running into a confusing issue with a few Samsung S23 devices enrolled via Hexnode for Work (Profile Owner mode). While hundreds of our other devices are working perfectly, one affected user cannot download work apps from the managed Google Play Store. It throws a permission error saying, “your administrator has not given access to this item.” The strange part is that we do not have any Android restrictions configured in our policies.

Additionally, this same user is stuck with Okta Device Trust showing as inactive. We have set up Okta Verify inside the work profile multiple times, but the user still cannot access work apps like Outlook and Teams. The Hexnode for Work app doesn’t show a “Setup Work Account” option either; it just opens to the normal home screen.

We’ve already tried opening the work Play Store to refresh it, manually syncing the work account in device settings, checking the Samsung battery optimization settings, and setting up Okta Verify again—but nothing is working, and the user is completely blocked. I’m really not sure what’s causing this underlying issue. At this point, would disenrolling and re-enrolling the device be the best way to clear this up?

Replies (1)

Marked SolutionPending Review
Hexnode Expert
5 months ago Mar 06, 2026
Marked SolutionPending Review

Hello,

Thanks for reaching out to Hexnode Connect.

You have done an excellent job troubleshooting this so far. Given that you have no restrictive policies applied and the issue is isolated to a few devices, this behavior strongly points to a corrupted or stale Android Enterprise work profile token on the device, rather than a configuration error.

Since you have already attempted the standard remediation steps—such as forcing a token refresh by opening the managed Play Store, verifying account sync, and checking background data settings—and the user is actively blocked from their workflow, a clean disenrollment and re-enrollment is indeed the fastest and most practical fix.

Because the device is enrolled in Profile Owner mode (Hexnode for Work), disenrolling will only remove the corporate work container. The user’s personal apps, photos, and personal data will remain completely untouched.

Here is the recommended workflow to cleanly reset the work profile binding:

  1. In the Hexnode portal, locate the affected device and navigate to Actions > Disenroll Device.
  2. Wait for the work profile to be automatically removed from the Samsung device.
  3. On the device, have the user confirm that the “Work” tab and the managed Google account are no longer present under their device’s account settings.
  4. Send a fresh Android Enterprise enrollment request from the Hexnode console.
  5. Have the user complete the Hexnode for Work enrollment to generate a brand-new work profile.
  6. Once the new work profile is active, install and open Okta Verify inside the work profile and complete the authentication.
  7. Finally, in the Hexnode portal, refresh the Okta Device Info status for that device.

This process forces a completely fresh token exchange between Android Enterprise, the managed Google Play Store, and Okta Verify, which will clear out the corrupted state and restore access to their work apps.

I hope this helps get your remote user back online swiftly! Feel free to reach out if you have any more doubts or need further assistance.

Best regards,
George,
Hexnode UEM

Save