MDM Removal Before IT Disposal: Business Device Offboarding Guide
Correct offboarding removes active device management, automated enrolment and account or activation controls before business IT equipment is reset, collected or processed.
MDM and device-management platforms to check
- Intune · Windows Autopilot: Remove the device from active management and any automated enrolment or deployment records that could reapply control after reset.
- Apple Business Manager / School Manager: Release organisational assignment and check Activation Lock / Find My status before the device leaves your control.
- Knox Mobile Enrollment: Remove the device from Knox enrolment where applicable so management is not automatically restored during setup.
- Jamf: Remove management records and any deployment or activation controls used by the organisation.
- Workspace ONE: Retire or unenrol the device and clear automated enrolment relationships where configured.
- Android zero-touch enrolment: Deregister devices transferring ownership; removing a configuration is not the same as removing the zero-touch registration.
- Google FRP / Apple Activation Lock: Check user-account and activation protections as a separate step; a factory reset alone may not release them.
Phase 01: Identify
Know what is managed before you start.
Step 01: Confirm the device and owner
Record serial number, asset tag, assigned user and the organisation or tenant that currently controls the device.
Step 02: Identify the management platform
Confirm whether the device is controlled by Intune, Autopilot, ABM/ASM, Knox, Jamf, Workspace ONE or another MDM platform.
Step 03: Check account and activation protection
Identify Apple Find My / Activation Lock, Google FRP and other user-account controls that can remain after reset.
Phase 02: Release
Remove organisational control before reset.
Step 04: Confirm the platform-specific order
Keep administrative access and recovery information available. Resolve Apple Activation Lock before releasing the device from the organisational inventory.
Step 05: Complete the authorised management action
Choose the appropriate retire, unenrol or wipe action for this platform and verify completion on the device before removing the management route.
Step 06: Release automated enrolment and ownership
After the platform prerequisites are met, deregister or release the relevant Autopilot, Apple, Knox or zero-touch record. Verify the required released status, not merely a deleted profile.
Phase 03: Unlock
Remove barriers that can survive the wipe.
Step 07: Recheck account and activation protections
Confirm Find My / Activation Lock and Google account protection are resolved through the authorised route. Do not mark an unresolved device as reusable.
Step 08: Remove firmware restrictions
Clear BIOS, UEFI, firmware or management passwords that would prevent testing, secure processing or reuse.
Step 09: Retain recovery information until verified
Keep relevant recovery keys or administrative access available until the device has been confirmed released and ready for processing.
Phase 04: Verify
Prove the device is really free of management.
Step 10: Allow platform changes to synchronise
Some removals are not instantaneous. Confirm the management service has accepted the change before treating the device as released.
Step 11: Recheck the device record
Confirm the required deregistered or released status for the exact device. A retained historical record is not necessarily an active enrolment.
Step 12: Record exceptions before collection
Flag devices that could not be released so they can be identified, stored and handled separately during processing.
Retire, Wipe, Delete and Release are not the same action.
Choose the action for the device's platform and ownership. Keep authorised administrative access, backups and recovery information available until the required changes are complete. A console record disappearing is not, by itself, proof of erasure or successful offboarding.
Retire / unenrol
Intune Retire removes managed company apps, settings and data while leaving personal content. It is not a full-device wipe. Other platforms use their own unenrolment commands: check the effect for that device and confirm the action has reached it.
Wipe / reset
A wipe normally resets the device, but behaviour and options vary. It does not necessarily release cloud registration. Windows Autopilot Reset intentionally retains Intune management and Microsoft Entra identity for internal reuse; it is not the same as removing a device for sale or recycling.
Delete
Deleting an Intune record can trigger Retire or Wipe depending on platform and enrolment. A server-side Completed status does not establish that a disconnected device completed its action. Do not delete the only management route before an intended remote action has been confirmed.
Release / deregister
This addresses the organisation's separate automated-enrolment or ownership record. It is not a data-destruction certificate. Check the exact serial or IMEI, authorisation and consequences before release; some platforms require reseller involvement to add the device again.
Use the platform-specific order, not a universal reset checklist. In particular, resolve Apple Activation Lock while the organisation still has the authority to do so, before releasing the device from its organisational inventory.
Microsoft Intune, Windows Autopilot and Entra ID
Record the serial and management identity, preserve required recovery information securely, and choose the appropriate Intune retirement or wipe action for the intended outcome. Allow the device to check in and verify the result. Separately follow Microsoft's deregistration process for the Windows Autopilot registration: removing a profile assignment is not the same as deregistration.
Review any remaining Microsoft Entra identity and other management relationships using the current platform guidance. Where Windows Autopilot device association is used, follow its distinct removal process as well; removing a list entry alone may not clear an association already stored on the device.
After the approved reset and synchronisation, verify setup does not restore your organisation's enrolment. Keep unresolved devices on the exception list rather than marking them released.
Microsoft guidance: Retire · Wipe · Delete · Autopilot Reset · Autopilot registration · Device association removal.
Apple Business Manager / School Manager, Find My and Activation Lock
Apple organisation assignment, the active MDM profile and Activation Lock are separate checks. Use the authorised account or management route to turn off Activation Lock before releasing ownership. A wipe from Jamf or another MDM does not, on its own, prove that the organisational assignment has been released.
Follow the release workflow for the Apple portal your organisation uses. Apple describes released devices as remaining in the inventory with a Released status; do not mistake that retained history for an active assignment. After release, erase and restore as required, then verify that setup no longer requires the previous organisation or user's credentials.
Apple's current device-release guidance explains the Activation Lock restriction and the required erase/restore step. Interface names may differ between Apple Business, Business Manager and School Manager.
Android zero-touch, Google account protection and Samsung Knox
Check active Android Enterprise management, zero-touch registration, Knox Mobile Enrollment where used, and Google Factory Reset Protection separately. A reset can reinstall management when automated enrolment remains configured.
For an ownership transfer, Google's guidance calls for deregistration from zero-touch. Selecting No config temporarily excludes a device from automatic enrolment but is not the same as deregistering it. Verify the serial or IMEI before deregistering; re-registration requires the reseller.
For Samsung devices, complete the authorised unenrolment and Knox Mobile Enrollment removal steps for your setup. Check other relevant Knox services and account protection too. Do not assume clearing an enrolment profile also removes every lock. Record what was actually removed and what remains pending.
Vendor guidance: Google zero-touch device administration · Knox Manage unenrolment · Knox Mobile Enrollment device removal.
Jamf, Workspace ONE, firmware locks and handover evidence
For Jamf, Workspace ONE, Ivanti and other systems, have the responsible IT administrator document the platform-specific removal action and the separate deployment services it uses. Removing one agent or management record is not a substitute for checking every applicable enrolment and activation relationship.
Before collection, check BIOS/UEFI administration and boot restrictions as well as MDM. Retain the authorised support route for controls such as HP Sure Admin or Dell BIOS administration; record unresolved restrictions against the device serial. Do not put passwords, recovery keys or temporary unlock codes in the client collection spreadsheet.
Record the device serial/asset tag, platform, original lock finding, removal result, check date and a contact able to resolve exceptions. Keep requested, pending, failed and verified results distinct. A client declaration remains separate from Bioteknik's subsequent inspection and data-treatment records.
Platform references reviewed 17 September 2026. Follow your organisation's authorised process and the current vendor guidance before destructive or irreversible actions. Pair this guide with equipment preparation and secure data destruction.
Common MDM offboarding mistakes
- Factory reset only: Resetting the device does not necessarily remove cloud management, automated enrolment or activation locks.
- Removing only the MDM profile: A device can be unenrolled yet remain in Autopilot, ABM/ASM, Knox or another automated deployment service.
- Deleting the user too early: Removing access before confirming the device is released can make activation-lock or recovery steps harder.
- Assuming wipe means reusable: A securely erased device may still be unusable for refurbishment if organisational or activation controls remain.
- No exception list: Unresolved locked devices are much easier to manage when serial numbers and the suspected control are recorded before collection.
- Waiting until collection day: Large estates should be checked in advance; management-platform changes may need time to synchronise.
Locked devices and additional administration
Unresolved management or activation controls can reduce reuse potential. A £10 administration charge per locked device may apply where extra identification, client contact, remote-removal assistance, storage, rechecking or reprocessing is required.
Preparing equipment for collection · Secure data destruction · Knowledge Centre