Policy to Render Intune Devices Unusable Upon Wipe

Aran Billen 596 Reputation points
2024-03-14T11:09:00.69+00:00

Is there a policy available in Intune that can render specific devices unusable if they are wiped? Our objective is to prevent the unauthorised wiping of these devices and ensure that even if wiped, they cannot be reused by the user. Is this functionality feasible within Intune?

Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,729 questions
Microsoft Intune Enrollment
Microsoft Intune Enrollment
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Enrollment: The process of requesting, receiving, and installing a certificate.
1,254 questions
Microsoft Intune Compliance
Microsoft Intune Compliance
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Compliance: Adhering to rules, standards, policies, and laws.
137 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,371 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. glebgreenspan 1,290 Reputation points
    2024-03-14T12:16:28.54+00:00

    Hello Aran

    Yes, you can achieve this functionality using Intune by utilizing the Endpoint security settings.

    One way to prevent unauthorized wiping of devices and make them unusable is by enabling the "Device Lock" feature in Intune. Device Lock can prevent anyone from performing a factory reset on the device or wiping the device remotely. This can help ensure that even if a device is wiped, it cannot be reused by the user without the necessary credentials or actions from the IT administrator.

    To enable Device Lock in Intune:

    1.     Sign in to the Microsoft Endpoint Manager admin center.

    2.     Go to Devices > Configuration profiles > Create profile.

    3.     Select the platform for the devices you want to configure (e.g., Windows, iOS, Android).

    4.     In the profile settings, look for options related to device security or security policies.

    5.     Enable the setting for Device Lock or Factory Reset Protection, depending on the platform.

    6.     Configure the policy settings to enforce Device Lock on the devices.

    7.     Assign the policy to the devices or groups of devices that you want to secure.