What to do if…
an unfamiliar administrator, management profile, or certificate appears on your device
Short answer
Do not approve, trust, or enter information into anything you do not recognise. Record what appears, check whether the device is or was managed by an employer, school, seller, or family organiser, and verify it through a contact route you already trust before removing anything.
Do not do these things
- Do not approve a new administrator, management profile, certificate, work account, or trust request that you do not recognise.
- Do not enter passwords, payment details, recovery codes, or authentication codes into a related prompt.
- Do not contact an organisation using details shown only inside the unfamiliar profile, certificate, app, email, or pop-up.
- Do not install a third-party removal or security tool recommended by the same message or website.
- Do not remove management from an employer-owned or school-owned device without contacting its authorised support team.
- Do not factory-reset the device before checking that essential data and account recovery details are available.
- Do not assume that every unfamiliar certificate or management entry is malicious.
What to do now
-
Stop interacting with the prompt, profile, certificate, or related app. Do not approve any requested permissions or trust settings.
-
Take screenshots or photographs showing the administrator or organisation name, profile details, certificate name or issuer, related app, and any warning message. Keep passwords, recovery codes, and authentication codes out of the images.
-
Establish whether the device is personal, supplied by work or school, managed by a family organiser, or bought second-hand. Contact any likely organisation through a phone number, email address, or website you already know is genuine.
-
Check the relevant settings without approving or trusting anything:
- On iPhone or iPad, open Settings > General > VPN & Device Management. Manually installed certificate trust settings may appear under Settings > General > About > Certificate Trust Settings.
- On a Mac, open System Settings > General > Device Management if that option is present.
- On Android, search Settings for work profile, device admin apps, device policy, credentials, or certificates. Names vary by manufacturer and Android version.
- On Windows, open Settings > Accounts > Access work or school and check for an account or organisation you do not recognise.
-
Think back to any recent work or school sign-in, app installation, downloaded file, email attachment, website instruction, VPN setup, security software installation, device repair, or second-hand purchase that may explain the entry.
-
If the device is personal and a trusted organisation confirms that the entry is not theirs, use the device’s normal settings to remove or disconnect it. Removing a management or work profile may also remove associated apps, accounts, settings, certificates, and work data.
-
Remove any related app that you do not recognise. Install available operating-system and app updates. On a Windows PC or Mac with established security software, run its normal security scan and follow its recommendations.
-
If you entered a password, recovery code, authentication code, or financial information after following suspicious instructions, use a different trusted device to change the affected password. Start with your main email account and any other account using the same password. Contact your bank promptly through its official number if payment details or money were involved.
-
Contact the device manufacturer or seller through an official support route if the management cannot be removed, returns after removal, names an unknown organisation, or remains on a second-hand device. A previously managed device may need to be released by the organisation that enrolled it.
What can wait
You do not need to identify who created the entry, confront a seller or organisation, replace the device, report an incident, or perform a factory reset immediately. First record what appears, avoid entering sensitive information, verify whether the management is legitimate, and secure any account details you may have disclosed.
Important reassurance
An unfamiliar administrator, management profile, or certificate does not by itself prove that someone has accessed all your information. Workplaces, schools, VPNs, security products, networks, family controls, and previous device owners can create similar entries, so checking the device’s history may explain it.
Scope note
This guide covers immediate steps to prevent further access or accidental data loss. Device recovery, workplace disputes, second-hand purchase problems, technical investigation, refunds, and longer-term account security may require help from the manufacturer, an authorised IT team, your bank, the seller, or a cyber-security specialist.
Important note
This is general information, not technical, legal, financial, or professional advice. Menu names, management powers, and removal options vary by device, operating-system version, manufacturer, and management arrangement.
Additional Resources
- Apple Support — Review and delete configuration profiles
- Apple Support — Trust manually installed certificate profiles in iOS, iPadOS and visionOS
- Google — What policies is my organization enforcing on my device? - Android Enterprise Help
- Google — Add & remove certificates
- Microsoft — Add Your Work or School Account to a Windows Device
- National Cyber Security Centre — How to recover an infected device
- National Cyber Security Centre — Hacked accounts
About this guide
This guide was produced and is maintained by PanicStation.org using its published editorial process. Official and specialist sources are checked where relevant, and AI-assisted tools may be used for drafting, organisation, and consistency checks. The site operator remains responsible for publication, revision, and removal decisions.