top of page

Mobile Device Management (MDM) Removal and Device Offboarding Guide

Mobile Device Management platforms allow organisations to configure, secure, monitor and control business-owned computers, mobile phones and tablets. These systems are essential while equipment remains in service, but they can prevent devices from being reused, refurbished or reassigned if they are not removed correctly at the end of the device lifecycle.

Deleting local files or completing a factory reset does not always remove organisational management. A device may remain registered with Microsoft Intune, Windows Autopilot, Apple Business Manager, Samsung Knox, Android zero-touch enrolment, Jamf, Workspace ONE or another management platform.

When the device is switched on again, it may automatically reconnect to the organisation, display company branding, request corporate credentials or reinstall management policies.

This guide explains how businesses should offboard managed devices before they are released for reuse, resale, recycling or professional IT asset disposal.

Why Correct MDM Removal Matters

A managed device can appear to have been successfully erased while still remaining connected to its former organisation.

For example, a Windows laptop may have been removed from Intune but remain registered in Windows Autopilot. An Apple device may have been wiped through Jamf while still being assigned to an MDM server in Apple Business Manager. An Android device may have been factory reset but remain linked to Android zero-touch enrolment or protected by Google Factory Reset Protection.

Incomplete offboarding can result in:

  • The device automatically re-enrolling after a reset

  • Company applications and policies being reinstalled

  • Corporate branding appearing during setup

  • The setup process requesting company credentials

  • Activation locks or account-protection screens

  • Devices being unsuitable for refurbishment or resale

  • Delays during inspection and processing

  • Additional administration costs

  • Reduced rebates or recovery value

  • Reusable equipment being unnecessarily recycled

Correctly removing management and enrolment records allows the device to begin its next lifecycle without remaining connected to its previous owner.

For the complete process covering accounts, accessories, encryption and collection preparation, see our guide to preparing IT equipment for collection.

why-correct-mdm-removal-matters
correct-device-offboarding-process-benefits

Completing the Correct Device-Offboarding Process Can Help To:

Protect organisational security

  • Removing management records prevents retired equipment from reconnecting to company systems, receiving policies or remaining visible in active device inventories.

Improve reuse and refurbishment

  • A device that reaches a standard setup screen without requesting company credentials is much more likely to be suitable for refurbishment and reuse.

Prevent automatic re-enrolment

  • Removing both the MDM record and the automated-enrolment assignment prevents company management from returning after a factory reset.

Maintain accurate asset records

  • Updating MDM, asset-management and ownership records ensures that retired devices are no longer shown as active or assigned.

Reduce processing delays

  • Devices that arrive correctly offboarded can be inspected, data processed and prepared for reuse much more efficiently.

Preserve equipment value

  • Unlocked and correctly released equipment normally has greater reuse and resale potential than devices that remain restricted by company management.

Step 1: Identify How the Device Is Managed

Before removing a device, identify every system that may control, enrol or protect it.

The MDM application installed on the device may be only one part of the management process. The device may also be registered in a separate automated-enrolment system, identity platform or manufacturer ownership portal.

Check whether the equipment is connected to:

  • Microsoft Intune

  • Windows Autopilot

  • Microsoft Entra ID

  • Apple Business Manager

  • Apple School Manager

  • Apple Automated Device Enrolment

  • Jamf

  • Samsung Knox Manage

  • Samsung Knox Mobile Enrolment

  • Android Enterprise

  • Android zero-touch enrolment

  • Google Admin

  • VMware Workspace ONE

  • MobileIron or Ivanti

  • Another endpoint-management platform

Record the device serial number, asset number, IMEI number and management platform before making any changes.

Where several systems are used together, the device may need to be removed separately from each one.

Important

Do not assume that removing the visible management profile from the device has removed the organisation’s ownership or automated-enrolment record.

identify-how-device-is-managed-mdm
confirm-device-ownership-and-disposal-authority

Step 2: Confirm Ownership and Disposal Authority

Confirm that the organisation owns the equipment and that an authorised person has approved its retirement.

The device should no longer be required by the assigned employee, department, customer, school, contractor or project. Any legal hold, investigation, insurance requirement, finance agreement or internal retention requirement should also be checked before removal.

The authorisation record should identify:

  • The device or group of devices

  • The serial numbers or asset numbers

  • The current user or department

  • The reason for retirement

  • The person approving disposal

  • The intended route, such as reuse, resale, donation or recycling

  • Any special data-destruction or reporting requirements

Removing a device from central management can affect the organisation’s ability to locate, secure or remotely erase it. The removal should therefore be completed only after disposal has been properly approved.

Step 3: Remove the Device from the MDM Platform

Use the organisation’s management console to remove the device from the active MDM environment.

The available commands vary between platforms. Common options include:

Retire

A retire command normally removes company applications, settings and organisational data while leaving personal information intact. This is often used for employee-owned devices.

Wipe

A wipe command normally erases the device and returns it to its factory settings. However, wiping does not necessarily remove automated enrolment or organisational ownership.

Delete

Deleting the device record removes it from the MDM console. Depending on the platform, deleting the record may not remove a separate enrolment or manufacturer registration.

Release

Releasing a device normally removes it from an organisation’s ownership within a manufacturer or automated-enrolment portal. This is different from simply deleting it from the MDM platform.

For business-owned equipment leaving the organisation, confirm that the device has been fully removed rather than merely marked as inactive, retired or wiped.

Important

Do not select a removal option purely because it contains the word delete or wipe. Confirm what the command actually removes before proceeding.

remove-device-from-all-management-platforms
remove-automated-enrolment-from-device

Step 4: Remove Automated Enrolment

Automated-enrolment systems can return a device to company management even after the MDM record has been deleted and the device has been factory reset.

Check for registration in:

  • Windows Autopilot

  • Apple Automated Device Enrolment

  • Samsung Knox Mobile Enrolment

  • Android zero-touch enrolment

  • Manufacturer or reseller deployment portals

The device should be unassigned, deregistered or released from the relevant enrolment service before it leaves the organisation.

A factory-reset device that remains registered may display messages such as:

  • Welcome to your organisation

  • Set up for work or school

  • Remote Management

  • This device belongs to an organisation

  • Sign in with your company account

  • This device will be automatically configured

Where possible, record confirmation that the automated-enrolment record has been removed.

Key point

Removing a Windows device from Intune does not automatically guarantee that it has been removed from Autopilot. Similarly, removing an Apple device from Jamf does not necessarily release it from Apple Business Manager.

Step 5: Remove Associated User and Company Accounts

​Remove organisational accounts and user associations that are no longer required.

These may include:

  • Microsoft work or school accounts

  • Microsoft Entra ID registration

  • Managed Apple Accounts

  • Apple IDs

  • Google Workspace accounts

  • Samsung accounts

  • Company email accounts

  • VPN credentials

  • Authentication certificates

  • Single sign-on profiles

  • Managed application accounts

The user should sign out of personal or company cloud services before the device is reset. Where the user is no longer available, an authorised administrator may need to remove the account centrally.

Also check for account-protection features such as:

  • Apple Find My

  • Apple Activation Lock

  • Google Factory Reset Protection

  • Samsung Reactivation Lock

  • Microsoft account device protection

Removing the MDM profile alone may not remove these account-level protections.

See our guide to preparing IT equipment for collection for the wider process covering user accounts and activation locks.

remove-associated-user-and-company-accounts
offboard-apple-devices-correctly

Step 6: Offboard Apple Devices Correctly

Apple devices may be controlled through several connected systems. Removing the device from only one system may leave other restrictions in place.

Check the device in:

  • Apple Business Manager

  • Apple School Manager

  • The assigned MDM server

  • Jamf or another Apple management platform

  • Apple Find My

  • Activation Lock records

The normal offboarding process may include:

  1. Confirming the device serial number

  2. Removing or unmanaging it in the MDM platform

  3. Unassigning it from the MDM server in Apple Business Manager

  4. Releasing it from organisational ownership where appropriate

  5. Signing out of the Apple account

  6. Disabling Find My

  7. Confirming that Activation Lock has been removed

  8. Erasing and testing the device

Releasing an Apple device from Apple Business Manager is generally intended for equipment permanently leaving the organisation. Ensure the correct device has been selected before completing the release.

After reset, the device should reach the standard Apple setup process without displaying a Remote Management screen or requesting the previous Apple account.

Future supporting guides

  • How to release a device from Apple Business Manager

  • How to remove Jamf management before disposal

  • How to disable Apple Activation Lock

  • How to confirm Apple Remote Management has been removed

Step 7: Offboard Windows Devices Correctly

Windows computers may be connected to Microsoft Intune, Microsoft Entra ID and Windows Autopilot at the same time.

A complete offboarding process may require the device to be removed from all three systems.

Check:

  • The Intune device record

  • The Microsoft Entra device record

  • The Windows Autopilot device list

  • The assigned primary user

  • Work or school account connections

  • BitLocker recovery-key records

  • Other endpoint-security or remote-management software

Removing the computer from Intune may stop active management, but an Autopilot registration can still cause the computer to reconnect to the organisation during Windows setup.

After the relevant records have been removed, reset or reinstall Windows and confirm that the computer reaches the normal setup screen without requesting organisational credentials.

Where BitLocker is enabled, retain any required recovery information until data processing and verification have been completed.

Secure data processing

Future supporting guides

  • How to remove a device from Microsoft Intune

  • How to remove a computer from Windows Autopilot

  • How to remove a device from Microsoft Entra ID

  • How to check BitLocker recovery keys before disposal

offboard-windows-devices-correctly
offboard-android-and-samsung-devices-correctly

Step 8: Offboard Android and Samsung Devices Correctly

Android devices can remain connected to several different management and protection systems.

Check whether the device is enrolled through:

  • Android Enterprise

  • Google Admin

  • Android zero-touch enrolment

  • Samsung Knox Manage

  • Samsung Knox Mobile Enrolment

  • A manufacturer-specific management portal

  • Another third-party MDM platform

Before completing a factory reset:

  1. Remove the device from the active MDM platform

  2. Remove it from zero-touch or Knox enrolment

  3. Remove managed Google or Samsung accounts

  4. Disable any device-protection or tracking features

  5. Confirm that Factory Reset Protection will not be triggered

  6. Record the removal in the asset register

  7. Reset and test the device

Google Factory Reset Protection may require the credentials of an account previously used on the device if accounts are not removed correctly before the reset.

After resetting, the device should reach the standard Android setup screen without automatically downloading company policies or requesting an organisation account.

Future supporting guides

  • How to remove Samsung Knox Mobile Enrolment

  • How to remove Android zero-touch enrolment

  • How to avoid Google Factory Reset Protection

  • How to remove Android Enterprise management

Step 9: Remove Devices from Other MDM Platforms

Organisations may use platforms such as Workspace ONE, Ivanti, MobileIron, Cisco Meraki Systems Manager or another specialist endpoint-management system.

Although the terminology differs, the same principles apply:

  • Remove active management

  • Remove the assigned user

  • Delete or retire the device record

  • Remove automated-enrolment assignments

  • Remove company certificates and profiles

  • Remove manufacturer ownership records

  • Check account and activation protection

  • Reset and test the device

Some platforms connect to Apple Business Manager, Android Enterprise, Samsung Knox or Microsoft services. Removing the record from the main dashboard may not remove those connected registrations.

Where the correct process is unclear, consult the organisation’s IT administrator or the platform documentation before wiping the equipment.

remove-devices-from-other-mdm-platformsge Aug 4, 2026, 12_50_10 PM.png
Step 10: Factory Reset the Device

Step 10: Factory Reset the Device

The factory reset should normally be completed after management, automated enrolment and account protection have been removed.

Resetting too early can make the offboarding process more difficult. It may remove local access to the device while leaving the central management records active.

Before resetting, confirm that:

  • Required business data has been backed up

  • The disposal has been authorised

  • The device has been removed from the MDM platform

  • Automated enrolment has been removed

  • User and company accounts have been disconnected

  • Activation and account locks have been disabled

  • Recovery information has been retained where required

  • Removable storage has been taken out

 

Use the manufacturer-approved reset method and allow the process to complete fully.

A factory reset is not always equivalent to certified data destruction. Equipment containing sensitive data may require additional erasure, degaussing or physical destruction according to the organisation’s security requirements.

Certified data destruction

Step 11: Test the Device After Reset

A successful reset does not by itself confirm that the device has been completely offboarded.

Switch the equipment on and proceed far enough through the initial setup process to check its status.

Confirm that:

  • The standard manufacturer setup screen appears

  • No company login is requested

  • No Remote Management screen appears

  • No previous user credentials are required

  • No organisation name or branding appears

  • No company applications are automatically installed

  • No management profile returns

  • The device does not automatically re-enrol

  • Activation Lock or Factory Reset Protection is not present

The device does not normally need to be fully configured with a new account. It only needs to be tested far enough to confirm that no previous organisational control remains.

Where a restriction is found, record the exact message shown and the device serial number. This will make further investigation easier.

test-device-after-factory-reset
record-mdm-removal-and-device-offboarding

Step 12: Record the Removal

Update the organisation’s asset and management records after the offboarding process has been completed.

Record:

  • Asset number

  • Serial number

  • IMEI number where applicable

  • Device type

  • Assigned user or department

  • MDM platform

  • Automated-enrolment platform

  • Date of removal

  • Administrator completing the work

  • Commands or actions completed

  • Reset status

  • Test result

  • Any remaining restrictions

  • Final disposal route

The device should no longer appear as active, compliant, assigned or available for deployment within the organisation’s systems.

Retaining a clear audit record provides evidence that the equipment was correctly removed from management before it left the organisation.

ChatGPT Image Aug 4, 2026, 02_10_30 PM.png

Common MDM Offboarding Mistakes

Factory resetting before removing management

The device may still be registered centrally and automatically return to company management during setup.

Removing Intune but leaving Autopilot active

The Windows computer may appear unmanaged but reconnect to the organisation when Windows is reinstalled.

Removing Jamf but not Apple Business Manager

The Apple device may still display Remote Management after it has been erased.

Deleting the device record without releasing ownership

A deleted record does not always remove the device from a manufacturer’s organisational portal.

Removing the MDM profile but leaving the user account

Activation Lock, Factory Reset Protection or another account restriction may remain.

Assuming an offline device is unmanaged

A device that has not contacted the server recently can still remain registered and may reconnect later.

Sending equipment without testing it

The problem may not become visible until the device is processed or prepared for reuse.

Removing the wrong device

Always verify serial numbers, asset numbers and IMEI numbers before deleting, releasing or wiping records.

Locked Devices and Additional Administration

Devices that remain connected to MDM, automated enrolment, user accounts or activation protection require additional investigation and administrative work.

Bioteknik may attempt to identify the restriction, record the device details and provide the relevant information to the customer. However, only the former organisation or authorised account holder may be able to remove some types of management or account protection.

Where additional work is required because equipment has not been correctly offboarded, an administration charge of £10 per affected device may apply.

This charge helps cover the time required to:

  • Inspect the device

  • Identify the type of restriction

  • Record serial numbers and asset details

  • Attempt available reset or removal procedures

  • Communicate findings to the customer

  • Retest the device after changes

  • Separate restricted devices from normal processing

Removing MDM, automated enrolment and account protection before collection helps avoid these charges and improves the likelihood that equipment can be reused.

ChatGPT Image Aug 4, 2026, 02_17_13 PM.png

Final MDM Offboarding Checklist

Before releasing managed devices for collection, confirm that:

  • Disposal has been properly authorised

  • Device serial numbers and asset numbers have been recorded

  • The assigned user or department has been removed

  • Required business data has been backed up

  • The device has been removed from the MDM platform

  • Automated enrolment has been removed

  • Microsoft, Apple, Google or Samsung accounts have been disconnected

  • Activation Lock and Factory Reset Protection have been checked

  • Manufacturer ownership records have been released where appropriate

  • Recovery information has been retained where required

  • The device has been factory reset

  • The device has been tested after reset

  • No organisation login or Remote Management screen appears

  • The removal date and administrator have been recorded

  • Any unresolved restrictions have been reported before collection

Download the Preparation Guide

Preparing Managed Devices for Collection

Correct MDM offboarding protects organisational security, improves the value of retired equipment and gives devices the best possible opportunity for reuse.

Bioteknik provides secure business IT collections, IT asset disposal, data destruction, refurbishment and responsible recycling services throughout London, Kent and the wider South East.

Before arranging a collection, organisations should remove devices from all management, enrolment and account-protection systems and inform us of any restrictions that remain.

More IT Lifecycle Guides

Preparing IT Equipment for Collection

Follow the essential steps for recording, securing and preparing business IT equipment before it is collected for reuse, recycling or data destruction.

Removing Devices from Microsoft Intune

Learn how to retire and delete devices from Microsoft Intune so they are no longer managed or automatically re-enrolled.

Removing Windows Devices from Autopilot

Remove Windows devices from Autopilot and associated Microsoft records before resetting them for reuse, resale or secure disposal.


 

Releasing Devices from Apple Business Manager

Release Macs, iPhones and iPads from Apple Business Manager and remove any associated management or activation restrictions.

Removing Samsung Knox Enrolment

Remove Samsung devices from Knox management and automated enrolment before carrying out a factory reset or transferring ownership.

Preventing MDM Re-enrolment After Reset

Understand why devices can return to company management after a reset and how to clear the remaining enrolment records correctly.

Read the Intune Guide
bottom of page