Remote Wipe and Device Security for Company Mobiles
Remote wipe is the ability to erase data from a company mobile phone or tablet over the internet — without physically having the device. When a company mobile is lost, stolen, or an employee leaves, remote wipe ensures that company data, emails, cont...
Remote Wipe: Why Timing Matters
Remote wipe only works on devices enrolled in MDM before they are lost. A company phone with access to email, Teams, and business files — without remote wipe capability — is a significant data breach risk. Microsoft Intune, included in Microsoft 365 Business Premium, provides remote wipe for both company-owned and BYOD devices, with selective wipe preserving personal content.
Explore business mobile securityThis is a core control inside AMVIA's business mobile security management. A company phone with live access to email, Teams, and files — but no way to wipe it — is a data breach waiting to happen.
What is remote wipe and how does it work?
Remote wipe is a feature of Mobile Device Management (MDM) platforms such as Microsoft Intune that lets an administrator send an erase command to a managed device. The device does not need to be online when the command is sent — it queues and executes the wipe the next time it connects to any network.
There are two types UK businesses use:
- Full wipe (factory reset) — removes all data, apps, settings, and accounts, returning the device to its out-of-box state. Used for company-owned devices that are lost, stolen, or decommissioned.
- Selective wipe — removes only company data (Outlook email, Teams, SharePoint, OneDrive, corporate apps) while leaving personal photos, messages, and apps untouched. Used for personal BYOD devices.
Selective wipe is the main reason most businesses deploy Mobile Application Management (MAM) for staff-owned phones — you protect company data without destroying someone's personal content.
Full wipe vs selective wipe: which applies?
The right wipe type depends on who owns the device. Company-owned hardware can be fully reset; staff-owned BYOD phones should only have their work profile removed. Getting this wrong either leaves data exposed or wipes an employee's personal life by mistake.
| Factor | Full wipe | Selective wipe |
|---|---|---|
| Device type | Company-owned | BYOD / personal |
| What is erased | Everything (factory reset) | Company data only |
| Personal content | Removed | Preserved |
| Typical trigger | Lost, stolen, decommissioned | Leaver, MAM-managed device |
| Underlying tool | Intune MDM | Intune MAM / app protection |
AMVIA defines the full-vs-selective policy per device group before any phone is issued, so the correct action fires automatically when an incident is reported.
Why do UK SMEs need remote wipe?
Mobile loss is one of the most common device security incidents UK businesses face. A 2024 UK survey found that 23% of employees had lost a work mobile device at some point, and most were never recovered. Without remote wipe, a lost phone with work email stays a live risk until its battery dies or someone resets it.
UK GDPR and breach reporting
Under UK GDPR, personal data must be protected with appropriate technical measures. A lost company phone holding customer contacts or email correspondence is a personal data breach risk — and serious breaches must be reported to the Information Commissioner's Office (ICO) within 72 hours. Remote wipe is the technical control that can stop a lost device from becoming a reportable breach. If the device is encrypted and wiped before its data is accessed, the ICO weighs those mitigations when assessing severity.
The NCSC's device security guidance names remote wipe and encryption as baseline controls for mobile devices that hold business data.
Leavers and insider risk
When someone leaves — especially in difficult circumstances — their phone may still hold client data, financials, or cached business intelligence. A wipe triggered the moment they depart removes that access before it can be misused. Without it, a business often has no way to recover or revoke data on a device a former employee keeps.
What device security controls work alongside remote wipe?
Remote wipe is most effective inside a broader baseline. AMVIA's mobile device management enforces these controls through Intune compliance policies, so a lost device is already hard to break into before any wipe completes.
- Device encryption — iOS encrypts by default once a passcode is set; Intune policies enforce encryption on Android. Encrypted data cannot be read without the PIN even if the wipe is delayed.
- PIN and biometric lock — every managed device must require a PIN, password, or biometric to enable. Without it, encryption is pointless.
- Screen lock timeout — AMVIA typically configures a one to two minute timeout so the screen locks quickly if a phone is set down.
- Jailbreak and root detection — compromised devices are marked non-compliant and blocked from Microsoft 365 via Conditional Access.
- Minimum OS version — devices running outdated, unpatched operating systems are blocked until updated.
These controls are configured and monitored through Microsoft Intune for business mobiles, and tie into AMVIA's wider managed cybersecurity so mobile risk is governed the same way as the rest of your estate.
How does AMVIA trigger a remote wipe?
When a phone is reported lost, stolen, or a staff member leaves, AMVIA runs a documented process so the wipe is fast and auditable. Speed matters: access is revoked first, then the device is wiped, then the event is logged for compliance.
1. AMVIA is notified by the owner, IT manager, or HR that a wipe is required. 2. The device is located in the Intune console. 3. The correct command is sent — full wipe for company devices, selective wipe for BYOD. 4. The device queues the command and executes it on next connection. 5. AMVIA confirms completion and documents the wipe for compliance records.
For a senior employee's stolen device holding sensitive data, AMVIA escalates the wipe as a priority incident with immediate action.
What does AMVIA's mobile device security service include?
AMVIA's business mobile security management bundles remote wipe with the full Intune deployment. Microsoft Intune is included in Microsoft 365 Business Premium at £16.90 per user per month (ex VAT, annual), so most SMEs already hold the licence.
- Intune enrolment for all company mobiles and tablets
- Compliance policy configuration — encryption, PIN, OS version, jailbreak detection
- MAM configuration for BYOD personal devices
- Remote wipe on demand, full or selective, with documented response
- Regular compliance reporting and alerting on policy failures
- Device retirement and decommissioning management
Remote wipe readiness checklist
Confirm these before you need a wipe — the control only works if it was set up in advance.
- All devices enrolled in MDM before issue — wipe only works on enrolled devices.
- Full-vs-selective policy defined per device group.
- Wipe procedure tested on a spare device before a real incident.
- Staff know exactly who to call the moment a device is lost.
- Access revocation configured in Microsoft Entra ID, ready to block Microsoft 365 instantly.
- Lost-device incident process documented, including the GDPR breach assessment timeline.
Remote Wipe: Key Capabilities
What a properly implemented remote wipe solution provides.
Full Device Wipe
Erases all data and resets to factory settings — used for company-owned devices that are lost or stolen.
Selective Wipe
Removes only company data from the managed work profile — personal content untouched, for BYOD devices.
Device Location
Locate a managed device before initiating wipe — useful to confirm it is actually lost rather than misplaced.
Access Revocation
Immediately block device access to company email and apps whilst wipe is being initiated or confirmed.
Remote Wipe Readiness Checklist
What to confirm to ensure remote wipe works when you need it.
All devices enrolled in MDM before use
Remote wipe only works on enrolled devices — enrolment must happen before the device is issued.
Full vs selective wipe policy defined
Company-owned devices: full wipe. BYOD devices: selective wipe of work profile only.
Wipe procedure tested on a spare device
Process verified to work before it is needed in a real lost device scenario.
Staff know who to call if device is lost
Clear reported lost device process — every minute of delay matters.
Access revocation configured in Entra ID
Block Microsoft 365 access immediately on report of loss, before wipe completes.
Incident process documented
Written steps for lost device response, including GDPR breach assessment timeline.
Frequently Asked Questions
Remote wipe is the ability to erase data from a mobile device over the internet, without holding it. An administrator sends a command that removes company data from a lost, stolen, or departing employee's device. A full wipe resets the phone to factory settings; a selective wipe removes only company data from managed apps.
For personal BYOD devices, AMVIA's standard approach is selective wipe — removing only company data such as Microsoft 365 email, Teams, and SharePoint files, while personal photos, messages, and apps stay untouched. A full factory-reset wipe is only performed on company-owned devices, where erasing everything is appropriate and proportionate.
No. The wipe command is sent and queued in the management system. When the device next connects to any network — Wi-Fi or mobile data — it receives and executes the command. If the phone is switched off, the wipe runs the moment it is turned back on and reconnects.
UK GDPR requires appropriate technical measures to protect personal data, and remote wipe is a key control for mobiles that store or access it. Without remote wipe, a business cannot properly respond to a lost device, and the ICO may consider the absence of that control when assessing a breach.
Selective wipe removes data inside Microsoft 365 managed apps: Outlook email, Teams messages, SharePoint and OneDrive files, and other Intune-managed apps. Corporate Wi-Fi and VPN profiles may also be removed. Personal photos, personal messages, personal app data, and personal accounts are unaffected.
Set Up Remote Wipe Before You Need It
AMVIA can configure Microsoft Intune MDM across your company phones and BYOD devices, including tested remote wipe procedures and documented incident response steps.
Related Resources
Business Mobile Phone Contracts for UK Companies
Business Mobile Phone Contracts for UK Companies
Mobile Device Management for UK Businesses
Mobile Device Management for UK Businesses
Microsoft Intune for Business Mobile Devices
Microsoft Intune for Business Mobile Devices
MDM vs MAM: What's the Difference?
MDM vs MAM: What's the Difference?
Consolidate your mobile fleet → Get a Mobiles Quote