Reset completely blocked Android device

Fred Eric S 21 Reputation points
2020-08-21T15:01:45.67+00:00

Hi everyone,

I have an interesting situation. I used a Sony Xperia XA1 with Andoird 8.0 as a test device. The device was sucessfully enrolled and an administrative profile created. All device configuration policies were applied. The policies were deliberately configured to restrict the device as much as possible to test if an admin could actually render the device unusable if not knowing what they did. Lo and behold, you can totally tank the device. Now this wouldn't be a problem, even without Wifi, the posibility to reset the device or enable USB debugging for PC reset - if the device has a SIM inserted, it can get changed policies from Intune and be "unstuck".
That is, if some idiot doesn't delete the the device from intune while it's powered off. In this specific case, when the device is powered back on, it realizes it isn't managed by Intune anymore, however, all restrictions are still in place, reenrolling isn't possible and resetting the device isn't either.
So here's my question - how the hell do I get the device reset to factory settings if it's completely blocked by Intune and can't be unblocked by intune?

Cheers,

Fred

Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,733 questions
Microsoft Intune Enrollment
Microsoft Intune Enrollment
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Enrollment: The process of requesting, receiving, and installing a certificate.
1,258 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,406 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. AndyLiu-MSFT 576 Reputation points
    2020-08-24T02:16:37.06+00:00

    Basically, if some one deletes the device in Intune accidentally when it's powered off. When the device is powered back on, it still will check in with Intune, and then remove the policies and company data. Please just click Delete devices from the Intune portal for more details.

    19782-image.png

    In addition, the end user also can unenroll the Intune managed device. It can be performed from the Company Portal. Please refer to the following guide for more details.

    Unenroll your Android device from management


    If the response is helpful, please click "Accept Answer" and upvote it.

    0 comments No comments

  2. Fred Eric S 21 Reputation points
    2020-08-24T07:42:32.13+00:00

    Hi Andy,

    thanks for the reply and the suggested solution, however it's not quite correct.

    The device does check back with Intune, yes. And it also realizes it's not managed by Intune anymore. But, what it tries to do then does not match the Docs. It does not delete company data and it does not remove the policies. It offers to reinstall the management profile, which it can't because there's already one there. The existing policies prohibit the user from removing any profiles or accounts from the device. Hence, unenrolling the device by the user in Company Portal is not possible.

    Cheers,

    Fred