# How to completely Wipe a Device?

 The **Wipe Device** remote action is a critical security measure that performs a factory reset on managed devices, permanently deleting all data to prevent corporate leaks if an asset is lost or stolen.

 **Why perform a Complete Device Wipe?**
 
------------------------------------------

 Wiping a device is the final line of defense for data protection. While locking a device prevents immediate access, a complete wipe ensures that even if encryption is bypassed, sensitive corporate and personal information remains inaccessible.

- **Data Protection**: Erases files, contacts, calendars, apps, and certificates.
- **Asset Disposal**: Prepares a corporate-owned device for retirement or reassignment.
- **Security Compliance**: Safeguards against unauthorized access on compromised endpoints.

 **Platform Support and Compatibility**
 
-----------------------------------------

 The **Wipe Device** action is supported across multiple operating systems, with specific behavior variations based on version and management state.

PlatformSupported Versions / Conditions**Android**Version 5.0 or later.**iOS / tvOS**iOS 4.0+, tvOS 10.2+.**macOS**10.7+. macOS 12.0.1+ uses Erase All Content and Settings (EACS).**Windows**All managed Windows devices.**ChromeOS**All managed ChromeOS devices.**Linux**Fedora 36+, Ubuntu 18.04+, Debian 10+. User credentials required for Linux Mint.**Other**Fire OS 6.0+, visionOS. **Critical Warnings**
 
------------------------

- **Irreversibility**: The wipe process cannot be stopped or paused once initiated.
- **Total Data Loss**: All data, corporate and personal, is permanently deleted.
- **Management Loss**: Standard Android, unsupervised iOS, Windows, and Mac devices are removed from Hexnode management and require manual re-enrollment.
- **Linux Impact**: The device is rendered unusable and requires a complete OS re-installation.

 **Step-by-Step Guide: Executing a Remote Wipe**
 
--------------------------------------------------

 Follow these steps to initiate a factory reset from the Hexnode UEM console:

1. Log in to the **Hexnode UEM portal**.
2. Navigate to the **Manage** tab.
3. Select the target device(s) you wish to wipe.
4. Click **Actions > Security > Wipe Device**.
5. Configure platform-specific options in the prompt: 
    - **macOS 10.8+**: Enter the **Find My Mac PIN**.
    - **Clear Factory Reset Protection/Activation Lock**: Enable **Clear Factory Reset Protection/Activation Lock** to remove lock screens on supervised iOS/macOS or Android Enterprise devices.
    - **macOS 12.0+ Fallback**: Choose between **Complete Wipe** for manual OS install or **Do not wipe** if EACS fails.
    - **ChromeOS Methods**: Select **Remove User Profiles** to retain policies or **Factory Reset** to erase everything.
    - **iOS and visionOS**: 
        - **Re-enroll device to MDM automatically**: Enable this option to automatically re-enroll devices into Hexnode UEM after wiping.  Pre-requisites:
            - This feature is supported only on iOS 17.0+ and visionOS 26.0+ devices.
            - For devices that are not enrolled through ADE, *Profile-driven enrollment* is required to support automatic re-enrollment.
            - The Activation Lock must be disabled on all devices before wiping to re-enroll devices back to MDM automatically.
            - The **Enable Return to Service** option in ADE enrollment profiles must be enabled for the profile-based configurations to be applied automatically on the device after wiping.
        - **Preserve managed applications**: Enable this option to retain managed applications assigned through the ADE enrollment profile when wiping the device.  Note: 
             This feature only works on iOS 17.0+ and visionOS 26.0+ devices enrolled using ADE.
            
             
            
            
            - **Deploy additional apps**: Use this dropdown to select additional apps to be deployed on the device after wiping it.  Note: 
                 You must [configure a valid VPP token](https://www.hexnode.com/mobile-device-management/help/how-to-deploy-apple-vpp-apps-with-hexnode-mdm/) to view, select, and deploy additional apps.
            - **Installation timeout**: Enable this option to limit how long Setup Assistant pauses in the foreground to install preserved or additional apps when a device restarts after a wipe. The installation phase times out if it exceeds the specified duration, and the Setup Assistant proceeds with the device setup.
            
             Disclaimer: 
             Enabling the **Preserve managed applications** option does not retain app configurations or app data.
        - Enable **Retain eSIM Configuration** to preserve mobile data plans.  Note: 
             This option is available only for iOS 11.0+ devices.
6. Click **Wipe**.
7. Enter your **Hexnode UEM portal password** and click **Confirm** to authorize the action.

 [ ![Screenshot of Hexnode UEM dashboard showing the configuration window for the Wipe Device remote action for iOS and visionOS devices.](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2018/08/Device-Wipe-Configuration.png)
 ](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2018/08/Device-Wipe-Configuration.png "Device Wipe Configuration")

 **Post-Wipe Re-enrollment Behavior**
 
---------------------------------------

Device Enrollment TypeAutomatic Re-enrollment?**Android (Knox, Zero-touch, ROM/OEM)**Yes. Requires internet connection.**visionOS (DEP / ADE)**Yes.**iOS (DEP / ADE)**Yes. Unless within the 30-day provisional period.**iOS (Profile-driven enrollment)**Yes, if the **Re-enroll device to MDM automatically** option is enabled.**iOS (Apple Configurator)**No. Manual enrollment required.**Standard Windows / Mac**No. Manual enrollment required.Automatic device wipe using Hexnode UEM
---------------------------------------

 A device can be set up to get completely wiped automatically if the user enters an incorrect password for a specific number of times. This feature is available only on iOS, Android, and Windows devices.

### Configure automatic wipe after failed password attempts

1. Go to **Policies** and create a new policy or continue with an existing one.
2. Go to **iOS > Passcode**, **Android > Device Password**, **Android > Work Profile Password**, or **Windows > Password**.
3. Set a value for **Failed Attempts** or **Failed attempts before wipe**.

### Associate the policy with targets before saving

1. Go to the **Policy Targets** tab from the policy setup screen.
2. Add devices, users, device groups, user groups, or domains.
3. Save the policy.

### Associate the policy with targets after saving

1. Go to **Policies** and select the required policy.
2. Click **Manage > Associate Targets**.
3. Click **Device/User/Device Group/User Group/Domain**.
4. Select the required targets and click **Associate**.

 [ ![Screenshot of Hexnode UEM policy configuration for automatic device wipe after failed password attempts.](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2020/12/Automate-wipe-action-using-Hexnode-MDM-.png)
 ](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2020/12/Automate-wipe-action-using-Hexnode-MDM-.png)

 **Troubleshooting Guide**
 
----------------------------

###  **OS cannot be reinstalled on erased macOS devices**
 

 **Problem**: OS cannot be installed back on macOS devices after a device wipe. You may have to install or reinstall the same OS version from scratch to resolve this issue.

 **Resolution**:

1. **Boot to the Recovery HD**: Restart the Mac, and after the chime, long-press the **command + R** keys until the menu screen appears. Else, long-press the **option** key until the boot manager screen appears. Then, choose Recovery HD and click on the corresponding arrow button.
2. **Erase the Hard Drive**: 
    1. Select **Disk Utility** in the **macOS Utilities** window and click **Continue**.
    2. Select the startup volume, generally **Macintosh HD**, from the Disk Utility left panel. Then click **Erase** in the main window.
    3. Input a partition name and set the partition format as **Mac OS Extended (Journaled)**.
    4. Click **Erase** in the pop-up window.
    5. Close the *Disk Utility* window and go back to the **macOS Utilities** menu.
3. **Reinstall macOS**: Close the Disk Utility window and go back to the macOS Utilities menu. Choose **Reinstall macOS** and proceed with the installation.

 Notes:- An active internet connection is mandatory for OS installation.
- The OS version you are installing now should be the same as the one before the wipe.

 

 
 ###  **Wipe action remains in “Pending” status**
 

 **Problem**: The Wipe Device action does not execute and remains pending in the portal.

 **Possible Causes**:

- The device is powered off.
- The device is not connected to the internet.
- The device is no longer actively communicating with the management server.

 **Resolution**:

- Ensure the device is powered on.
- Confirm it has an active internet connection, such as Wi-Fi or cellular.
- Verify the device is checking in with the server.
- Retry the action once connectivity is restored.

###  **Device did not re-enroll after wipe**
 

 **Problem**: The device does not automatically re-enroll in management after the wipe completes.

 **Possible Causes**:

- The device was not enrolled using an automated enrollment program, such as Knox, Zero-touch, ADE, or DEP.
- The ADE Enrollment Profile does not have **Enroll devices in MDM** enabled.
- The device was within the 30-day provisional period for Apple Configurator-added iOS devices.

 **Resolution**:

- Verify the enrollment method used before wipe.
- Ensure automated enrollment settings are correctly configured in the respective enrollment program.
- Manually re-enroll the device if automatic re-enrollment is not supported.