This article talks about locking down an IOS device such that end user cannot delete the installed profiles.
Environment: This article best suits to CPPM 6.2.x
Navigate to " Home » Onboard + WorkSpace » Deployment and Provisioning » Provisioning Settings" on CPG Login and select the below.
If we select "Never allow Removal" for "Profile Security", end user will not be able to delete the profile
However we cannot stop a user from wiping the device. The end user has ultimate control over the device and can wipe it. They can also do a factory restore to reset the firmware.