Remote Wipe and Device Security for Company Mobiles
Remote wipe is the ability to erase data from a company mobile phone or tablet over the internet — without physically having the device. When a company mobile is lost, stolen, or an employee leaves, remote wipe ensures that company data, emails, cont...
Remote Wipe: Why Timing Matters
Remote wipe only works on devices enrolled in MDM before they are lost. A company phone with access to email, Teams, and business files — without remote wipe capability — is a significant data breach risk. Microsoft Intune, included in Microsoft 365 Business Premium, provides remote wipe for both company-owned and BYOD devices, with selective wipe preserving personal content.
Explore business mobile securityRemote wipe is the ability to erase data from a company mobile phone or tablet over the internet — without physically having the device. When a company mobile is lost, stolen, or an employee leaves, remote wipe ensures that company data, emails, contacts, and documents cannot be accessed by unauthorised individuals.
What Is Remote Wipe?
Remote wipe is a feature of Mobile Device Management (MDM) platforms — including Microsoft Intune — that allows IT administrators to send a command to a managed device that erases its contents. The device does not need to be in range of a Wi-Fi or mobile network at the time the command is sent — it queues the wipe command and executes it the next time the device connects.
There are two types of remote wipe relevant to UK businesses:
Full Remote Wipe (Factory Reset)
A full remote wipe resets the device to its factory default state — removing all data, applications, settings, and accounts. After a full wipe, the device is as it was when it left the manufacturer. This is appropriate for company-owned devices that are lost, stolen, or being decommissioned.
Selective Remote Wipe
A selective wipe removes only company data — Microsoft 365 emails, Teams messages, SharePoint files, corporate apps — whilst leaving personal data (photos, personal messages, personal apps) untouched. This is appropriate for personal devices (BYOD) used for work, where a full factory reset would be invasive and disproportionate.
Selective wipe is the primary reason most UK businesses deploy Mobile Application Management (MAM) for staff personal devices — it provides the ability to protect company data without the risk of destroying an employee's personal content.
Why Remote Wipe Matters for UK Businesses
UK GDPR Compliance
Under UK GDPR, personal data must be processed securely using appropriate technical measures. A company mobile device containing customer contact details, email correspondence with personal data, or employee records is a personal data processor. If that device is lost or stolen and its contents are accessed by an unauthorised person, this constitutes a personal data breach that may need to be reported to the ICO within 72 hours.
Remote wipe is the technical control that can prevent a lost device from becoming a reportable breach. If a device is wiped before its data is accessed, the breach may not be reportable — or may be reportable but with significantly reduced severity, as the ICO considers the mitigating technical controls in place.
Protection Against Insider Threats
When an employee leaves — particularly in difficult circumstances — their company mobile may contain sensitive client data, financial information, or proprietary business intelligence. Remote wipe, triggered immediately upon their departure, ensures this data is removed from the device before they lose access.
Without remote wipe capability, businesses often have no way to recover data from a device retained by a former employee, nor any way to prevent continued access to data cached on the device.
Lost or Stolen Devices
AMVIA's experience with UK businesses shows that mobile phone loss is one of the most frequent device security incidents. A 2024 survey found that 23% of UK employees had lost a work mobile device at some point. In most cases, the device was never recovered.
Without remote wipe, a lost device containing work email remains a live risk indefinitely — the finder can access everything on it until the battery dies or the device is reset. With remote wipe and device encryption, a lost device is effectively inert: the encrypted data cannot be read without the device PIN, and IT can remotely erase the device when the loss is reported.
Device Security Controls That Work Alongside Remote Wipe
Remote wipe is most effective as part of a broader device security framework. AMVIA's business mobile security management includes:
Device Encryption
All modern smartphones encrypt their storage by default when a PIN or password is set. This encryption means that even if a device is found and not wiped in time, its data cannot be accessed without the correct PIN. iOS devices are encrypted by default. Android devices require encryption to be enabled — Intune compliance policies can enforce this.
PIN and Biometric Lock
Intune compliance policies enforce that all managed devices require a PIN, password, or biometric (Face ID, fingerprint) to unlock. Without this, device encryption is irrelevant — anyone can access the device without a PIN.
Screen Lock Timeout
Intune compliance policies set the maximum screen inactivity period before the device locks automatically. For business mobiles, AMVIA typically configures a one to two minute timeout — ensuring the screen locks quickly if a device is set down and forgotten.
Jailbreak and Root Detection
Jailbroken (iOS) or rooted (Android) devices have their manufacturer security controls disabled, significantly reducing their security posture. Intune compliance policies detect jailbroken and rooted devices and mark them non-compliant — which, via Conditional Access, blocks them from accessing Microsoft 365 until the issue is resolved.
Minimum OS Version Enforcement
Outdated operating systems contain known, unpatched vulnerabilities. Intune compliance policies require devices to be running a minimum OS version, ensuring that staff are not accessing company data from phones with known security flaws.
How to Trigger a Remote Wipe
When a company mobile is reported lost, stolen, or a staff member leaves, AMVIA initiates the remote wipe process:
- AMVIA is notified (by the business owner, IT manager, or HR) that a wipe is required
- The device is located in the Intune management console
- The appropriate wipe command is sent — full wipe for company devices, selective wipe for personal devices
- The device queues the wipe command and executes it upon next network connection (Wi-Fi or mobile data)
- AMVIA confirms completion and documents the wipe event for compliance records
For urgent situations — a senior employee's device reported stolen containing sensitive data — AMVIA escalates the wipe request as a priority incident with immediate action.
AMVIA's Mobile Device Security Management Service
AMVIA's business mobile management service includes remote wipe as a standard capability, alongside the full Intune MDM/MAM deployment:
- Intune enrolment for all company mobiles and tablets
- Compliance policy configuration (encryption, PIN, OS version, jailbreak detection)
- MAM configuration for BYOD personal devices
- Remote wipe on demand — full or selective — with documented response
- Regular compliance status reporting — AMVIA monitors which devices are compliant and alerts on compliance failures
- Device retirement and decommissioning process management
Remote Wipe: Key Capabilities
What a properly implemented remote wipe solution provides.
Full Device Wipe
Erases all data and resets to factory settings — used for company-owned devices that are lost or stolen.
Selective Wipe
Removes only company data from the managed work profile — personal content untouched, for BYOD devices.
Device Location
Locate a managed device before initiating wipe — useful to confirm it is actually lost rather than misplaced.
Access Revocation
Immediately block device access to company email and apps whilst wipe is being initiated or confirmed.
Remote Wipe Readiness Checklist
What to confirm to ensure remote wipe works when you need it.
All devices enrolled in MDM before use
Remote wipe only works on enrolled devices — enrolment must happen before the device is issued.
Full vs selective wipe policy defined
Company-owned devices: full wipe. BYOD devices: selective wipe of work profile only.
Wipe procedure tested on a spare device
Process verified to work before it is needed in a real lost device scenario.
Staff know who to call if device is lost
Clear reported lost device process — every minute of delay matters.
Access revocation configured in Entra ID
Block Microsoft 365 access immediately on report of loss, before wipe completes.
Incident process documented
Written steps for lost device response, including GDPR breach assessment timeline.
Frequently Asked Questions
Remote wipe is the ability to erase data from a mobile device over the internet, without physically having the device. IT administrators can send a wipe command that removes company data from a lost, stolen, or departing employee's device. Full wipe resets the device to factory settings; selective wipe removes only company data from managed apps.
AMVIA's standard approach for personal (BYOD) devices is selective wipe — removing only company data (Microsoft 365 emails, Teams, SharePoint files) whilst leaving personal photos, messages, and apps untouched. Full remote wipe (factory reset) is only performed on company-owned devices.
No. The remote wipe command is sent and queued in the management system. When the device next connects to any network — Wi-Fi or mobile data — it receives and executes the wipe command. For devices that are switched off, the wipe will execute when the device is turned on and connects.
Selective wipe removes all data within Microsoft 365 managed apps: emails in Outlook, Teams messages and channels, SharePoint and OneDrive files, and any other apps managed by Intune. Corporate Wi-Fi and VPN profiles may also be removed. Personal photos, personal messages, personal app data, and personal accounts are unaffected.
UK GDPR requires appropriate technical measures to protect personal data. Remote wipe is a key technical control for mobile devices that access or store personal data. Without remote wipe capability, a business cannot adequately respond to a lost or stolen device containing personal data — and the ICO may consider the absence of this control in any breach investigation.
UK GDPR requires appropriate technical measures to protect personal data. Remote wipe is a key technical control for mobile devices that access or store personal data. Without remote wipe capability, a business cannot adequately respond to a lost or stolen device containing personal data — and the ICO may consider the absence of this control in any breach investigation.
Set Up Remote Wipe Before You Need It
AMVIA can configure Microsoft Intune MDM across your company phones and BYOD devices, including tested remote wipe procedures and documented incident response steps.
Related Resources
Business Mobile Phone Contracts for UK Companies
Business Mobile Phone Contracts for UK Companies
Mobile Device Management for UK Businesses
Mobile Device Management for UK Businesses
Microsoft Intune for Business Mobile Devices
Microsoft Intune for Business Mobile Devices
MDM vs MAM: What's the Difference?
MDM vs MAM: What's the Difference?
Consolidate your mobile fleet → Get a Mobiles Quote