Research / compatibility data last verified

Primary sourceBuild-specific
POLICY / 41

SAFETY / MANAGEMENT AUTHORITY

A managed iPhone is a policy stop—not a compatibility test.

Do not use MisakaX or misaka26 on an organization-owned, supervised or actively enrolled device. On personal BYOD, Company Portal, a management profile or protected work apps still create a policy boundary. Identify the state; do not remove it to make Apply possible.

THE DIRECT ANSWER

Stop before Apply. Leave enrollment exactly as you found it.

A compatible build is not permission to modify a managed device. MDM can carry ownership, security, compliance, app, account, network and recovery requirements that MisakaX does not evaluate.

DORecord the management state.

Ownership, supervision message, profile owner, Company Portal status and work-app signal.

DO NOTDelete policy to pass.

No profile removal, Company Portal uninstall, unenrollment, date trick, reset or factory erase.

HANDOFFAsk the organization.

Use the approved helpdesk channel before any write or recovery decision.

FIVE OBSERVABLE SIGNALS

Check evidence—not the presence of one app icon.

Company Portal alone cannot identify the exact management type. A supervision message, organization profile or device compliance record is stronger evidence.

  1. 01 / SETTINGS

    Supervision message

    Look near the top of the main Settings page. If the device is supervised, stop.

    STRONG DEVICE SIGNAL
  2. 02 / PROFILE

    VPN & Device Management

    Open the profile and identify its organization and purpose. Do not remove it.

    INSPECT, DO NOT CHANGE
  3. 03 / PORTAL

    Devices + compliance

    A listed phone with Check status or compliance connects the phone to an organization policy.

    STRONG POLICY SIGNAL
  4. 04 / APP

    Protected work data

    A protection message proves app policy; it does not by itself prove full-device enrollment.

    APP-LEVEL SIGNAL
  5. 05 / OWNER

    Work or school property

    Ownership is a stop even if profiles appear absent or the administrator has not contacted you.

    AUTHORITY OVERRIDES

MANAGEMENT IS NOT ONE STATE

Personal ownership and device control are different questions.

Use the label only after the visible evidence supports it. Every level below still requires the organization’s policy decision.

LevelWhat you may observeWhat it provesMisakaX decision
01PROTECTED APP / MAM

A work app says it is protected by your organization, but the device may not be enrolled.

App-level policy is proven. Full-device MDM is not.

Pause and ask IT before an optional system change.
02USER ENROLLMENT / BYOD

A personal device uses a Managed Apple Account and separated work data.

Personal ownership does not make the enrolled work context unmanaged.

Do not use MisakaX while enrolled.
03DEVICE ENROLLMENT

An organization can apply a broader set of device settings and restrictions.

The enrollment profile and managed apps belong to one policy chain.

Do not remove or modify that chain yourself.
04SUPERVISED / AUTOMATED

Settings identifies supervision; the organization can apply additional controls.

This is designed for organization-owned deployment and profile removal may be restricted.

Stop and hand the decision to the owner/admin.

EIGHT-FACT MANAGEMENT CHECK

Route the decision without inspecting the device.

This local form reads only your selections. It cannot see USB, Settings, Company Portal, profiles, accounts or work data.

Do not enter organization names, usernames, tenant URLs, identifiers, passwords, tokens or profile data.

STATE-SPECIFIC RESPONSE

Preserve policy evidence before you try to restore access.

The least invasive next step depends on what already happened. None of these states authorizes an MDM bypass.

BEFORE APPLY

Close the workflow.

Do not change the profile, enrollment or Company Portal state. Ask IT whether the device may be used at all.

Prepare the helpdesk record →
APPLY / NO SYMPTOM

Freeze the first state.

No more flags or compliance experiments. Record the exact change and ask IT before Reset/Revert.

Preserve outcome evidence →
WORK ACCESS BLOCKED

Capture the exact policy signal.

Record Company Portal status and the first Outlook/Teams/enrollment message. Use the organization’s support channel.

Microsoft status boundary →
MBERRORDOMAIN / 22

Stop at the managed setting.

Do not treat an MDM backup-encryption policy as the local Finder/iTunes checkbox. Preserve the full response.

Read owner issue #33 →
BOOT / RECOVERY / SETUP

Owner-coordinated recovery.

Stop MisakaX. Confirm backup, ownership, enrollment and erase authority before the Apple recovery ladder.

Open device recovery →

TWO INCIDENTS / TWO EVIDENCE CLASSES

A user outcome and an exact error are not universal causes.

Both justify a hard stop. Neither proves a failure rate, encryption change or one repair for every organization.

R23 / COMMUNITY REPORTCompany Portal + Outlook/Teams

Reported sequence

  1. Personal phone with Microsoft management profile.
  2. Apple Intelligence enabled with misaka26.
  3. Outlook and Teams stopped working.
  4. Reset and profile reinstallation did not resolve it.
  5. Reporter used backup, full restore and backup restore.

Not established

Exact build/release/logs, management configuration, controlled cause, rate or a required universal repair. The encryption explanation is the reporter’s inference.

Read the original R23 report
ISSUE #33 / OWNER TRACKERRestore policy response

Exact reported boundary

Cannot remove iTunes Backup Encryption — Encrypted Backup MDM setting present on device (MBErrorDomain/22)

What it changes

The restore stage reported an explicit managed setting. The user’s belief that ordinary backup encryption was off does not clear that policy state.

What remains unknown

No maintainer response, fix, rate or cross-environment diagnosis is published in the issue.

Read misaka26 issue #33

NEVER TURN POLICY INTO A TWEAK

Six shortcuts create a second incident.

Changing the evidence can remove work access, data or the organization’s supported recovery path.

01

Delete the profile

Associated settings, apps and data may also be removed.

02

Unenroll to Apply

Company resources and the approved device record can disappear.

03

Fake date or compliance

Do not evade expiration, attestation, detection or policy checks.

04

Retry Apply / Reset

Repeated writes destroy the first attributable state.

05

Factory reset alone

Erase is destructive and does not decide ownership or enrollment.

06

Hide the tool from IT

The helpdesk needs the true change sequence to make a safe decision.

ADMINISTRATOR HANDOFF

Report the sequence—not company secrets.

Use the organization’s private helpdesk channel. State plainly that a restore-based customization tool was used, what was selected, whether Apply/Reset ran and the first observed policy or device change.

Keep public posts redacted.

No company/tenant name, work email, server URL, token, certificate, profile payload, serial, UDID, IMEI, Apple Account, passcode, backup password or work content.

REDACTED INCIDENT / TEMPLATEOwnership: personal BYOD / organization-owned
iOS/iPadOS: version + BuildVersion
Management: supervision/profile category
Work state: compliant / blocked / unknown
Tool: MisakaX or misaka26 + release
Change: feature category only
Stage: selected / Apply / Reset / restore
First signal: exact redacted wording
Device health: usable / degraded / recovery
Backup: date + access verified
Request: policy-safe next action
DO NOT REQUEST / “HOW DO I BYPASS MDM?”

MDM + WORK DEVICE FAQ

Company Portal, supervision, compliance, error and recovery answers.

Each answer separates visible evidence, organization authority and unknown product behavior.

Can I use MisakaX or misaka26 on a work iPhone?

No. Do not run an optional restore-based system modification on an organization-owned, supervised or actively managed phone. Build compatibility does not override device ownership, security policy, compliance or support obligations.

Can I use misaka26 on my personal iPhone with Company Portal?

Personal ownership does not remove the management context. If Company Portal lists the phone as enrolled, checks compliance or controls access to work resources, stop and ask your IT team. One published user report describes Outlook and Teams failing after misaka26 on a personal phone with a management profile.

Does having the Company Portal app mean my iPhone is MDM-managed?

Not by itself. The app can be installed without proving the exact enrollment type. Check whether Company Portal lists this device and a compliance state, whether Settings shows an organization profile, and whether work apps say they are protected. Until the state is clear, do not Apply.

How do I check if an iPhone or iPad is supervised?

Open the main Settings page and look near the top for Apple’s supervision message. Then open Settings → General → VPN & Device Management and inspect any profile. Do not delete a profile while identifying it.

How do I check whether my iPhone has an MDM profile?

Open Settings → General → VPN & Device Management. An organization-named enrollment or management profile is a strong management signal. Also check Company Portal → Devices for this phone and its compliance state. Record only the organization category—not private tenant or account details.

VPN & Device Management is empty. Does that prove the phone is unmanaged?

No. It means that screen showed no profile at that moment; it is not a security attestation. App-protection policy can still govern work data without full-device enrollment, and an unknown ownership or Company Portal state still needs clarification.

What is the difference between MAM and MDM on iPhone?

Managed-app policy can control work data inside selected apps, while device enrollment can apply settings and restrictions to the device. A protected-app message proves app policy, not necessarily full-device MDM. Both create a work-policy boundary for this page.

What is Apple User Enrollment?

User Enrollment is Apple’s BYOD-oriented management type for a personally owned device. It separates managed work data and uses a Managed Apple Account. It gives the user more autonomy than device-wide enrollment, but the work context is still managed.

What is the difference between Device Enrollment and a supervised iPhone?

Device Enrollment lets an organization manage a broader set of device settings. Automated Device Enrollment is designed for organization-owned devices and produces supervised devices, where additional controls and restricted profile removal may apply. Neither is a MisakaX test environment.

The compatibility checker says my build is supported. Is MDM use now safe?

No. Compatibility answers a product/build question only. Management authority, compliance, work-data availability, backup policy and recovery ownership remain separate gates and can stop the workflow even on a supported build.

Can written IT approval make an actively managed phone compatible?

Approval can resolve authority, but it does not create an owner-documented MDM-safe mode or remove technical/policy conflict. An administrator who wants to evaluate the tool should use an organization-controlled test plan and disposable test hardware—not a production user device.

Should I delete the management profile before using MisakaX?

No. Apple says removing a profile can also remove associated settings, apps and data. On supervised or organization-enrolled devices, removal may be restricted. Profile deletion is an administrative lifecycle action, not a compatibility switch.

What if there is no Remove Management button?

Do not try to force one to appear. Apple documents enrollment methods where the organization can prevent user removal, especially on supervised devices. Record the profile owner and ask that organization to remove or release the device through its management system.

Should I remove the device from Company Portal and enroll it again later?

Not as a workaround. Microsoft documents that removal can take away work apps, email profiles, internal sites, Wi-Fi/VPN access and organizational settings. Follow the organization’s approved offboarding or re-enrollment process only when IT instructs you.

Can I uninstall Company Portal before Apply?

Uninstalling an app does not prove the device is unenrolled or policy-free, and it can disrupt access or support evidence. Do not alter the management state to make an optional customization pass.

Can MisakaX remove or bypass MDM?

This site does not provide, validate or support MDM removal or bypass. MisakaX/misaka26 feature modification is not authorization to evade organization ownership, enrollment, compliance, Activation Lock or Setup controls.

Can my employer or school see that I used MisakaX?

This project has no audit proving exactly what every management system can observe. Apple and Microsoft document compliance, restrictions and managed-device communication, but visibility depends on enrollment and organization configuration. Never assume the change is invisible.

Company Portal says “Reconnect compromised device.” What should I do?

Stop MisakaX and preserve the exact Company Portal wording and device status. Microsoft uses this compliance state when it classifies a device as jailbroken and may revoke work access; that label does not settle whether MisakaX is technically a jailbreak. Do not factory reset until IT confirms the required recovery and data plan.

What does “noncompliant” mean in Company Portal?

It means the organization’s check says the device does not currently meet one or more workplace requirements. Access to work resources can be restricted. Preserve the exact status and required-action screen, then contact the helpdesk instead of guessing which system setting to change.

Outlook or Teams stopped working after misaka26. What should I do?

Stop all Apply and Reset attempts. Record whether the apps show a policy, sign-in, protection or compliance message and whether Company Portal lists the device as compliant. Keep the phone usable, preserve the original MobileGestalt and contact IT with a redacted timeline.

Company Portal cannot install the management profile after MisakaX. What next?

Do not repeatedly install/delete profiles or add more tweaks. Preserve the first enrollment error, current profile list, device health and the MisakaX stage. The R23 author reported this state, but the post does not establish a universal cause or repair; involve IT.

Should I tap Check status in Company Portal after work access fails?

If the phone is stable and your organization normally uses that action, one check can capture the current compliance result. Do not cycle settings or repeat checks as an experiment. Microsoft directs unresolved access problems to the organization’s IT support.

Will Reset MobileGestalt fix Company Portal?

There is no published guarantee. In R23, the reporter says Reset did not restore management-profile installation before a later full restore, but that is one outcome. Do not alternate Apply and Reset on a managed device; ask IT before any product-level revert.

What is MBErrorDomain/22 “Encrypted Backup MDM setting present”?

misaka26 issue #33 records a restore response saying it could not remove iTunes backup encryption because an encrypted-backup MDM setting was present. Treat that exact message as a managed-policy stop. It is not a prompt to disable or remove the policy.

Backup encryption is off, so why does misaka26 still report an MDM setting?

Ordinary local backup encryption and the managed policy named in the error are not the same claim. Issue #33 reports the message despite the user believing local backup encryption was off. Preserve the full response and contact the administrator; toggling the local checkbox does not disprove MDM policy.

Does issue #33 prove MDM always blocks misaka26?

No. It proves one exact restore-stage response was reported on one stated build. The issue has no maintainer-confirmed universal diagnosis, frequency or fix. The explicit policy error is enough to stop that incident without generalizing it to every deployment.

What happened in the Company Portal report R23?

The author says a personal iPhone had a Microsoft Company Portal management profile for Outlook and Teams, then those apps stopped working after enabling Apple Intelligence with misaka26. Reset and profile reinstallation did not resolve it; the author reports using a Mac backup, full restore and backup restore.

Does R23 prove misaka26 changed device encryption?

No. Encryption was the author’s proposed explanation, not a maintainer, Apple or Microsoft diagnosis. The report does not publish exact build, product release, logs, management configuration or a controlled reproduction.

Should I factory reset a work iPhone after a MisakaX problem?

Not without the organization’s approval and a verified data/re-enrollment plan. Factory reset erases personal data and may be available as an organization action. A supervised device can enroll again through organizational deployment after setup.

Does a factory restore permanently remove company MDM?

Do not assume so. An organization-owned device assigned to Apple Business Manager or Apple School Manager can enroll again through Automated Device Enrollment after erase or restore. Permanent release is an owner-side administrative action, not a restore trick.

Will restoring my iPhone backup also restore or remove MDM?

Do not use a backup as an MDM lifecycle tool. The result depends on OS version, enrollment method, ownership and organization configuration; Automated Device Enrollment can reapply management independently. Ask IT what must be backed up, erased, restored and re-enrolled.

Does iOS 27 restore MDM from an iPhone backup?

Apple says iOS 27 no longer restores the enrollment profile, management configuration or supervision status from backup. That does not release an organization-owned device: a device assigned for Automated Device Enrollment can enroll again after restore and receive current management.

Can I re-enroll in Company Portal after restoring the iPhone?

Possibly, but it is not a self-service recovery guarantee. Enrollment eligibility, device ownership, compliance, OS support, app data and organization assignments are controlled by IT. Confirm the approved backup, erase, setup and re-enrollment sequence before restoring.

I already clicked Apply but everything still works. What should I do?

Stop while the first state is still attributable. Do not add another flag or test compliance by breaking it. Preserve the exact release/build, selected changes, Apply result, original file, current work-app state and backup date, then ask IT before Reset or any new write.

The phone bootloops or shows the Restore screen. Does MDM change recovery?

Device instability moves to Apple recovery, but organization ownership and enrollment still apply. Do not use MisakaX again. Contact the owner/admin, preserve the current screen and backup state, and use the recovery guide; Restore can erase data.

I bought a used iPhone that still says it is supervised. Can MisakaX remove it?

No. A supervision or Remote Management state must be resolved by the organization or seller with legitimate authority. Return to the seller or ask the listed organization to release the device; do not use an MDM bypass.

Can I test MisakaX on a spare company or school phone?

A spare device is still organization property and can still be enrolled, logged or needed for service. Only the owner’s administrator can define an authorized test environment. This page does not convert spare hardware into permission.

What should I send my IT helpdesk after a MisakaX incident?

Send device ownership category, iOS/iPadOS version and build, supervision/profile category, Company Portal compliance wording, affected work apps, time of the first change, MisakaX track/release, selected feature, Apply/Reset stage, current device health and backup date. State that a restore-based customization tool was used.

What must I redact from an MDM incident report?

Remove organization and tenant names from public posts, plus work email, usernames, server URLs, enrollment tokens, profile payloads, certificates, serial, UDID, IMEI, Apple Account, passcodes, backup passwords and work content. Give private details only to the authorized helpdesk channel.

Can this page detect MDM on my connected iPhone?

No. The checker reads only the options you select in this browser tab. It has no USB, Company Portal, profile, account or management-system access and cannot certify a device as unmanaged.

01

Return to the complete risk model.

Safety hub →
02

Build recovery proof before any change.

Preparation →
03

Classify an exact desktop error.

Error library →
04

Preserve Apply and outcome evidence.

Apply + verify →
05

Use Reset only after authorization.

Routine revert →
06

Route boot, Restore or Setup states.

Device recovery →