Business Mobiles

Remote Wipe and Device Security for Company Mobiles

Remote wipe is the ability to erase data from a company mobile phone or tablet over the internet — without physically having the device. When a company mobile is lost, stolen, or an employee leaves, remote wipe ensures that company data, emails, cont...

Remote Wipe: Why Timing Matters

Remote wipe only works on devices enrolled in MDM before they are lost. A company phone with access to email, Teams, and business files — without remote wipe capability — is a significant data breach risk. Microsoft Intune, included in Microsoft 365 Business Premium, provides remote wipe for both company-owned and BYOD devices, with selective wipe preserving personal content.

Explore business mobile security

This is a core control inside AMVIA's business mobile security management. A company phone with live access to email, Teams, and files — but no way to wipe it — is a data breach waiting to happen.

What is remote wipe and how does it work?

Remote wipe is a feature of Mobile Device Management (MDM) platforms such as Microsoft Intune that lets an administrator send an erase command to a managed device. The device does not need to be online when the command is sent — it queues and executes the wipe the next time it connects to any network.

There are two types UK businesses use:

  • Full wipe (factory reset) — removes all data, apps, settings, and accounts, returning the device to its out-of-box state. Used for company-owned devices that are lost, stolen, or decommissioned.
  • Selective wipe — removes only company data (Outlook email, Teams, SharePoint, OneDrive, corporate apps) while leaving personal photos, messages, and apps untouched. Used for personal BYOD devices.

Selective wipe is the main reason most businesses deploy Mobile Application Management (MAM) for staff-owned phones — you protect company data without destroying someone's personal content.

Full wipe vs selective wipe: which applies?

The right wipe type depends on who owns the device. Company-owned hardware can be fully reset; staff-owned BYOD phones should only have their work profile removed. Getting this wrong either leaves data exposed or wipes an employee's personal life by mistake.

FactorFull wipeSelective wipe
Device typeCompany-ownedBYOD / personal
What is erasedEverything (factory reset)Company data only
Personal contentRemovedPreserved
Typical triggerLost, stolen, decommissionedLeaver, MAM-managed device
Underlying toolIntune MDMIntune MAM / app protection

AMVIA defines the full-vs-selective policy per device group before any phone is issued, so the correct action fires automatically when an incident is reported.

Why do UK SMEs need remote wipe?

Mobile loss is one of the most common device security incidents UK businesses face. A 2024 UK survey found that 23% of employees had lost a work mobile device at some point, and most were never recovered. Without remote wipe, a lost phone with work email stays a live risk until its battery dies or someone resets it.

UK GDPR and breach reporting

Under UK GDPR, personal data must be protected with appropriate technical measures. A lost company phone holding customer contacts or email correspondence is a personal data breach risk — and serious breaches must be reported to the Information Commissioner's Office (ICO) within 72 hours. Remote wipe is the technical control that can stop a lost device from becoming a reportable breach. If the device is encrypted and wiped before its data is accessed, the ICO weighs those mitigations when assessing severity.

The NCSC's device security guidance names remote wipe and encryption as baseline controls for mobile devices that hold business data.

Leavers and insider risk

When someone leaves — especially in difficult circumstances — their phone may still hold client data, financials, or cached business intelligence. A wipe triggered the moment they depart removes that access before it can be misused. Without it, a business often has no way to recover or revoke data on a device a former employee keeps.

What device security controls work alongside remote wipe?

Remote wipe is most effective inside a broader baseline. AMVIA's mobile device management enforces these controls through Intune compliance policies, so a lost device is already hard to break into before any wipe completes.

  • Device encryption — iOS encrypts by default once a passcode is set; Intune policies enforce encryption on Android. Encrypted data cannot be read without the PIN even if the wipe is delayed.
  • PIN and biometric lock — every managed device must require a PIN, password, or biometric to enable. Without it, encryption is pointless.
  • Screen lock timeout — AMVIA typically configures a one to two minute timeout so the screen locks quickly if a phone is set down.
  • Jailbreak and root detection — compromised devices are marked non-compliant and blocked from Microsoft 365 via Conditional Access.
  • Minimum OS version — devices running outdated, unpatched operating systems are blocked until updated.

These controls are configured and monitored through Microsoft Intune for business mobiles, and tie into AMVIA's wider managed cybersecurity so mobile risk is governed the same way as the rest of your estate.

How does AMVIA trigger a remote wipe?

When a phone is reported lost, stolen, or a staff member leaves, AMVIA runs a documented process so the wipe is fast and auditable. Speed matters: access is revoked first, then the device is wiped, then the event is logged for compliance.

1. AMVIA is notified by the owner, IT manager, or HR that a wipe is required. 2. The device is located in the Intune console. 3. The correct command is sent — full wipe for company devices, selective wipe for BYOD. 4. The device queues the command and executes it on next connection. 5. AMVIA confirms completion and documents the wipe for compliance records.

For a senior employee's stolen device holding sensitive data, AMVIA escalates the wipe as a priority incident with immediate action.

What does AMVIA's mobile device security service include?

AMVIA's business mobile security management bundles remote wipe with the full Intune deployment. Microsoft Intune is included in Microsoft 365 Business Premium at £16.90 per user per month (ex VAT, annual), so most SMEs already hold the licence.

  • Intune enrolment for all company mobiles and tablets
  • Compliance policy configuration — encryption, PIN, OS version, jailbreak detection
  • MAM configuration for BYOD personal devices
  • Remote wipe on demand, full or selective, with documented response
  • Regular compliance reporting and alerting on policy failures
  • Device retirement and decommissioning management

Remote wipe readiness checklist

Confirm these before you need a wipe — the control only works if it was set up in advance.

  • All devices enrolled in MDM before issue — wipe only works on enrolled devices.
  • Full-vs-selective policy defined per device group.
  • Wipe procedure tested on a spare device before a real incident.
  • Staff know exactly who to call the moment a device is lost.
  • Access revocation configured in Microsoft Entra ID, ready to block Microsoft 365 instantly.
  • Lost-device incident process documented, including the GDPR breach assessment timeline.

Remote Wipe: Key Capabilities

What a properly implemented remote wipe solution provides.

Full Device Wipe

Erases all data and resets to factory settings — used for company-owned devices that are lost or stolen.

Selective Wipe

Removes only company data from the managed work profile — personal content untouched, for BYOD devices.

Device Location

Locate a managed device before initiating wipe — useful to confirm it is actually lost rather than misplaced.

Access Revocation

Immediately block device access to company email and apps whilst wipe is being initiated or confirmed.

Remote Wipe Readiness Checklist

What to confirm to ensure remote wipe works when you need it.

All devices enrolled in MDM before use

Remote wipe only works on enrolled devices — enrolment must happen before the device is issued.

Full vs selective wipe policy defined

Company-owned devices: full wipe. BYOD devices: selective wipe of work profile only.

Wipe procedure tested on a spare device

Process verified to work before it is needed in a real lost device scenario.

Staff know who to call if device is lost

Clear reported lost device process — every minute of delay matters.

Access revocation configured in Entra ID

Block Microsoft 365 access immediately on report of loss, before wipe completes.

Incident process documented

Written steps for lost device response, including GDPR breach assessment timeline.

Frequently Asked Questions

Set Up Remote Wipe Before You Need It

AMVIA can configure Microsoft Intune MDM across your company phones and BYOD devices, including tested remote wipe procedures and documented incident response steps.