Edit

Share via


Wipe all data from a macOS device

Intune gives you the ability to use the Wipe remote device action to wipe data from macOS devices, including the operating system.

Important

When you use Wipe, the device is also removed from Intune management and no warning is given to the end user once a wipe is initiated.

Note

The behavior for Wipe on iOS devices is that it restores the device to factory defaults and removes the management profile, including any configuration profiles that were installed.

Before you start

  • For devices running macOS 12.0.1 and later, review the requirements for erasing devices available on the Apple Support site.

  • For devices running a version of macOS earlier to 12.0.1, macOS must be reinstalled. Steps covering how to reinstall macOS are available on the Apple Support site.

How to use Wipe

  1. In the Microsoft Intune admin center, choose Devices > All devices > and select the device you want to wipe. Select Wipe.

    Screen shot that shows where in the Intune admin center you select Wipe.

  2. Provide a 6-digit number for the Recovery PIN. The six-digit PIN is required to reinstall the operating system on the device, if the device isn't equipped with T2 security chip enabled (that is, the model year of the device is 2018 and earlier, or the device is running macOS 10.14 or earlier). Be sure to make a note of this PIN and give it to the device owner as it won't be visible after the wipe action completes.

    Screen shot that shows where to provide a pin and select an option for obliteration behavior.

  3. Select an option from Obliteration Behavior, which is used to define the fallback for devices when Erase All Contents and Settings (EACS) fails. The following options can be configured:

    • Default: If Erase All Content and Settings (EACS) preflight fails, the device responds to Intune with an Error status and then attempts to erase itself. If EACS preflight succeeds but EACS fails, then the device attempts to erase itself.

    • Do not obliterate: If Erase All Content and Settings (EACS) preflight fails, the device responds to Intune with an Error status and doesn't attempt to erase itself. If EACS preflight succeeds but EACS fails, then the device doesn't attempt to erase itself.

    • Obliterate with warning: If Erase All Content and Settings (EACS) preflight fails, the device responds with a Success status and then attempts to erase itself. If EACS preflight succeeds but EACS fails, then the device attempts to erase itself.

    • Always obliterate: The system doesn't attempt Erase All Content and Settings (EACS). T2 and later devices always obliterate.

  4. Select Wipe to erase the device.