Can Hexnode prevent users from erasing or formatting devices?Solved

Participant
Discussion
5 months ago Mar 13, 2026

Hi everyone. I’m trying to figure out if Hexnode can prevent users from formatting or resetting our managed devices. We currently have iPhones and a few laptops (macOS and Windows) enrolled, and I want to know if our Enterprise plan includes a restriction to stop users from completely wiping them. Ideally, I am looking for a single setting that blocks things like “Erase All Content and Settings” across all of these different device types. Does such a universal option exist?

Replies (1)

Marked SolutionPending Review
Hexnode Expert
5 months ago Mar 13, 2026
Marked SolutionPending Review

Hello, and thanks for reaching out to Hexnode Connect.

To answer your question directly: there is no single, universal toggle that blocks device formatting across all operating systems. The ability to restrict erase or reset actions is highly platform-specific due to how different operating systems handle core system recovery.

For your iOS devices, you can easily prevent users from wiping their phones. Hexnode provides a direct configuration profile restriction that effectively grays out the reset option in the device’s settings. You can enforce this by following these steps:

  1. Navigate to Policies and open your target iOS policy.
  2. Go to Manage > Modify.
  3. Navigate to iOS > Advanced Restrcitions > Allow Security and Privacy Settings.
  4. Disable the Erase content and settings option and save the policy.

For macOS and Windows laptops, preventing a full device wipe is fundamentally different. Because formatting a drive or reinstalling a desktop operating system can often be initiated completely outside of the managed user session (such as via macOS Recovery mode or a Windows bootable USB), it cannot be locked down through a simple MDM restriction toggle.

To effectively prevent unauthorized formatting on your laptops, you must combine your Hexnode MDM policies with local hardware and OS security measures. This typically involves removing local administrator rights, enforcing disk encryption, and implementing strict firmware or BIOS passwords so users cannot boot to external media or recovery partitions.

I hope this clarifies the architectural differences in platform capabilities. Please feel free to reach out if you need further assistance strategizing your desktop security protocols!

Best regards,
George,
Hexnode UEM

Save