Remote Wipe and Device Security for Company Mobiles
Remote wipe allows a business to erase company data from a lost or stolen phone within minutes. Without it, a misplaced device is an open door to your email, files, and business applications. This guide explains how remote wipe works and what UK businesses need to implement it properly.
Remote Wipe: Why Timing Matters
Remote wipe only works on devices enrolled in MDM before they are lost. A company phone with access to email, Teams, and business files — without remote wipe capability — is a significant data breach risk. Microsoft Intune, included in Microsoft 365 Business Premium, provides remote wipe for both company-owned and BYOD devices, with selective wipe preserving personal content.
Explore business mobile securityWhat Is Remote Wipe?
Remote wipe is the ability to erase data from a smartphone or tablet without physical possession of the device. It is delivered through Mobile Device Management (MDM) software — typically Microsoft Intune for UK businesses using Microsoft 365. When a device is enrolled in MDM, an administrator can initiate a wipe command from a management console that takes effect as soon as the device connects to the internet.
There are two types of remote wipe. A full device wipe erases everything and returns the phone to its factory state — appropriate for company-owned devices. A selective wipe (sometimes called a targeted wipe) removes only the managed work profile and its contents — company email, apps, and files — while leaving personal photos, contacts, and apps intact. Selective wipe is the appropriate action for BYOD (personal) devices.
How Remote Wipe Works
Remote wipe requires MDM enrolment to be in place before the device is lost. Once enrolled, the device regularly checks in with the MDM platform. When a wipe command is issued, it is queued and delivered the next time the device connects — whether over Wi-Fi or mobile data. Most modern smartphones receive and execute the wipe command within minutes of it being sent, provided the device has any network connectivity.
The process in Microsoft Intune is straightforward: the administrator selects the device from the Intune portal, chooses the wipe type, and confirms. Intune sends the command and provides status confirmation once the device reports back. AMVIA manages this process for clients as part of its mobile device management service.
Why UK Businesses Need Remote Wipe Before a Device Is Lost
A smartphone with access to company email, Microsoft Teams, SharePoint, and cloud file storage contains significant amounts of sensitive business and potentially personal data about clients and staff. Under UK GDPR, the business is the data controller for that information and is responsible for its security.
A lost device without remote wipe capability means that data is accessible to whoever finds the phone — particularly if the device lacks a strong PIN or the lock screen can be bypassed. The ICO expects businesses to have implemented appropriate technical measures, including the ability to remotely wipe devices, as part of their data protection obligations. Failure to do so can constitute a reportable breach if personal data is compromised.
Key Considerations for UK SMEs
- MDM must be set up before the device is lost: Remote wipe only works on enrolled devices. Every business mobile should be enrolled in MDM before staff begin using it for work.
- Have a clear incident process: Staff should know who to call immediately when a device is lost. Delayed reporting delays the wipe — time matters if sensitive data is on the device.
- Use selective wipe for BYOD: Full wipe of a personal device would destroy an employee's personal content — selective wipe removes company data only, which is both legally appropriate and more likely to encourage cooperation.
- Test the wipe process in advance: Before relying on remote wipe in an emergency, test the procedure using a spare device so your team knows exactly what to do.
- Revoke access immediately: Whilst wipe is being initiated, block access to company email and Microsoft 365 through Entra ID — this stops data being accessed even before the wipe completes.
How AMVIA Can Help
AMVIA configures Microsoft Intune MDM for company-owned and BYOD devices, including remote wipe procedures and documented incident response steps. When a device is reported lost, AMVIA initiates the wipe and access revocation process immediately — no delay waiting for internal IT. As part of a managed mobile service, AMVIA also handles device provisioning, policy management, and secure device disposal at end of life. Call 0333 733 8050 to discuss your requirements.
Remote Wipe: Key Capabilities
What a properly implemented remote wipe solution provides.
Full Device Wipe
Erases all data and resets to factory settings — used for company-owned devices that are lost or stolen.
Selective Wipe
Removes only company data from the managed work profile — personal content untouched, for BYOD devices.
Device Location
Locate a managed device before initiating wipe — useful to confirm it is actually lost rather than misplaced.
Access Revocation
Immediately block device access to company email and apps whilst wipe is being initiated or confirmed.
Remote Wipe Readiness Checklist
What to confirm to ensure remote wipe works when you need it.
All devices enrolled in MDM before use
Remote wipe only works on enrolled devices — enrolment must happen before the device is issued.
Full vs selective wipe policy defined
Company-owned devices: full wipe. BYOD devices: selective wipe of work profile only.
Wipe procedure tested on a spare device
Process verified to work before it is needed in a real lost device scenario.
Staff know who to call if device is lost
Clear reported lost device process — every minute of delay matters.
Access revocation configured in Entra ID
Block Microsoft 365 access immediately on report of loss, before wipe completes.
Incident process documented
Written steps for lost device response, including GDPR breach assessment timeline.
Remote Wipe FAQs
Apple and Google both provide basic remote wipe through their consumer cloud services (Find My iPhone and Find My Device respectively), but these require the employee to be logged into their personal Apple or Google account and provide limited management capability. For business use, MDM is the appropriate solution — it provides consistent policy enforcement, selective wipe for BYOD devices, and management independent of the employee's personal accounts.
If the device is switched off or has no connectivity, the wipe command is queued by the MDM platform. As soon as the device connects to any network — Wi-Fi or mobile data — the command is delivered and executed. The device does not need to be online at the moment you initiate the wipe. In the meantime, access to company resources can be blocked through Microsoft Entra ID conditional access.
With selective wipe configured properly in Microsoft Intune, only the managed work profile is wiped — company email, apps, and files in the work container. Personal photos, contacts, messages, and apps are not affected. This separation is a core reason why MDM with work profiles is the appropriate BYOD approach, both technically and from a GDPR perspective.
Remote wipe is an important technical measure in meeting your GDPR obligations around data security, but it is one element of a broader approach. The ICO expects businesses to have implemented appropriate technical and organisational measures — this includes encryption, access controls, a BYOD policy, and incident response procedures, as well as remote wipe capability. AMVIA can help you assess your overall mobile data security posture against GDPR requirements.
Set Up Remote Wipe Before You Need It
AMVIA can configure Microsoft Intune MDM across your company phones and BYOD devices, including tested remote wipe procedures and documented incident response steps.
Related Resources
Business Mobile Security
The full set of security controls every business should have on company phones.
BYOD Security Policy
How to manage personal devices accessing company data, including selective wipe.
Business Mobiles for UK SMEs
Company phones with MDM, support, and full lifecycle management from AMVIA.
The Complete Cybersecurity Guide
How device security fits into a layered security strategy for UK businesses.