Microsoft Intune
General

Wipe devices with Microsoft Intune

In brief

The documentation now explains that eSIMs are preserved by default on specified Android Enterprise corporate-owned devices and can be removed during a single-device wipe using the new device view.

What Intune admins need to know

Review wipe procedures and use the new device view when eSIM removal is required.

This summary was assembled from the tracked documentation change. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Device action: wipeWipe devices with Microsoft Intune

Use the Wipe action in Intune to factory reset a device, restoring it to its default settings. This action removes all personal and organizational data, apps, and configurations. It's commonly used when a device needs to be retired, repurposed, reset for troubleshooting, or securely erased if lost or stolen.

How to wipe a device from the Intune admin center

  1. In the [Microsoft Intune admin center], select [Devices] > [All devices].
  2. From the devices list, select a device.
  3. At the top of the device overview pane, find the row of action icons. Select Wipe.

::: zone pivot="macosandroid" 4. Enter a 6-digit Recovery PIN. This PIN is required to reinstall the operating system on devices that don't have the T2 security chip—typically models from 2018 or earlier, or devices running macOS 10.14 or earlier. Make sure to record the PIN and share it with the device owner. The PIN won't be visible after the wipe completes. 5. Select an option from Obliteration Behavior, which is used to define the fallback for devices when Erase All Contents and Settings (EACS) fails. The following options can be configured:

::: zone-end

  1. In the [Microsoft Intune admin center], select [Devices] > [All devices].
  2. From the devices list, select a device.
  3. At the top of the device overview pane, find the row of action icons. Select Wipe.

::: zone pivot="android" 4. For Android Enterprise corporate-owned fully managed (COBO), corporate-owned dedicated (COSU), and corporate-owned work profile (COPE) devices, eSIMs are preserved by default. To remove the eSIMs during the wipe, select the option to remove eSIMs. 5. Select Wipe.

::: zone-end

::: zone pivot="macos" 4. Enter a 6-digit Recovery PIN. This PIN is required to reinstall the operating system on devices that don't have the T2 security chip—typically models from 2018 or earlier, or devices running macOS 10.14 or earlier. Make sure to record the PIN and share it with the device owner. The PIN won't be visible after the wipe completes. 5. Select an option from Obliteration Behavior, which is used to define the fallback for devices when Erase All Contents and Settings (EACS) fails. The following options can be configured:

Daily Intune.Admin.News

Get daily email updates

Get a concise summary of the latest Microsoft Intune updates delivered straight to your inbox.

Loading the secure signup form…