As we known when samsung phone is rooted then Knox is tripping so multi user with a work profile isn't possible with the error message... can't create work profile.
This is howto guide to bypass Knox security so Shelter works on it, after many tries and errors methode
My setup
- S20 magisk zygisk root android 13
- Magisk modules: lsposed, knoxpatch apk and enhancer (in lsposed), shamiko as blacklist mode, safetynet fix
- Shelter
Guide
- Root your samsung phone with zygisk magisk (25.2) and install those magisk modules. Reboot several times
- In Lsposed enable KnoxPatch module with suggested Recommended. Reboot
- In Magisk Settings change Multiuser Mode > Device Owner Managed (using in multi user profile)
- In Magisk Settings change Mount Namespace Mode > Inherit namespace. Reboot
- Install Shelter and create work profile following Setup Wizard
- Clone the needed apps to Work profile or install directly from Shelter Work Profile
- In Magisk configure DenyList with those apps in work profile
My rooted S20 works fine in Work Profile with my company apps Microsoft Authenticator, Company Portal, Outlook, Teams etc.
Hope it helps for you guys too.
Further process how to make company apps work on Work Profile created by Shelter/ Island needs follow steps
- Install Applist Detector to check root
- Install InitrcHider (zygisk version) in Magisk
- In Magisk configure DenyList with full denying for those company apps (ticks all processes)
- Uninstall Magisk from Settings/ Apps, not directly from Magisk! because if doing it from Magisk then you loose the root
- Check root again with AppList Detector
- Delete company apps data and cache from Settings/ Apps then setup those apps again as new
This is howto guide to bypass Knox security so Shelter works on it, after many tries and errors methode
My setup
- S20 magisk zygisk root android 13
- Magisk modules: lsposed, knoxpatch apk and enhancer (in lsposed), shamiko as blacklist mode, safetynet fix
- Shelter
Guide
- Root your samsung phone with zygisk magisk (25.2) and install those magisk modules. Reboot several times
- In Lsposed enable KnoxPatch module with suggested Recommended. Reboot
- In Magisk Settings change Multiuser Mode > Device Owner Managed (using in multi user profile)
- In Magisk Settings change Mount Namespace Mode > Inherit namespace. Reboot
- Install Shelter and create work profile following Setup Wizard
- Clone the needed apps to Work profile or install directly from Shelter Work Profile
- In Magisk configure DenyList with those apps in work profile
My rooted S20 works fine in Work Profile with my company apps Microsoft Authenticator, Company Portal, Outlook, Teams etc.
Hope it helps for you guys too.
Further process how to make company apps work on Work Profile created by Shelter/ Island needs follow steps
- Install Applist Detector to check root
- Install InitrcHider (zygisk version) in Magisk
- In Magisk configure DenyList with full denying for those company apps (ticks all processes)
- Uninstall Magisk from Settings/ Apps, not directly from Magisk! because if doing it from Magisk then you loose the root
- Check root again with AppList Detector
- Delete company apps data and cache from Settings/ Apps then setup those apps again as new
Last edited: