Mobile Device Management (MDM) Removal and Device Offboarding Guide
Mobile Device Management platforms allow organisations to configure, secure, monitor and control business-owned computers, mobile phones and tablets. These systems are essential while equipment remains in service, but they can prevent devices from being reused, refurbished or reassigned if they are not removed correctly at the end of the device lifecycle.
Deleting local files or completing a factory reset does not always remove organisational management. A device may remain registered with Microsoft Intune, Windows Autopilot, Apple Business Manager, Samsung Knox, Android zero-touch enrolment, Jamf, Workspace ONE or another management platform.
When the device is switched on again, it may automatically reconnect to the organisation, display company branding, request corporate credentials or reinstall management policies.
This guide explains how businesses should offboard managed devices before they are released for reuse, resale, recycling or professional IT asset disposal.
Why Correct MDM Removal Matters
A managed device can appear to have been successfully erased while still remaining connected to its former organisation.
For example, a Windows laptop may have been removed from Intune but remain registered in Windows Autopilot. An Apple device may have been wiped through Jamf while still being assigned to an MDM server in Apple Business Manager. An Android device may have been factory reset but remain linked to Android zero-touch enrolment or protected by Google Factory Reset Protection.
Incomplete offboarding can result in:
-
The device automatically re-enrolling after a reset
-
Company applications and policies being reinstalled
-
Corporate branding appearing during setup
-
The setup process requesting company credentials
-
Activation locks or account-protection screens
-
Devices being unsuitable for refurbishment or resale
-
Delays during inspection and processing
-
Additional administration costs
-
Reduced rebates or recovery value
-
Reusable equipment being unnecessarily recycled
Correctly removing management and enrolment records allows the device to begin its next lifecycle without remaining connected to its previous owner.
For the complete process covering accounts, accessories, encryption and collection preparation, see our guide to preparing IT equipment for collection.


Completing the Correct Device-Offboarding Process Can Help To:
Protect organisational security
-
Removing management records prevents retired equipment from reconnecting to company systems, receiving policies or remaining visible in active device inventories.
Improve reuse and refurbishment
-
A device that reaches a standard setup screen without requesting company credentials is much more likely to be suitable for refurbishment and reuse.
Prevent automatic re-enrolment
-
Removing both the MDM record and the automated-enrolment assignment prevents company management from returning after a factory reset.
Maintain accurate asset records
-
Updating MDM, asset-management and ownership records ensures that retired devices are no longer shown as active or assigned.
Reduce processing delays
-
Devices that arrive correctly offboarded can be inspected, data processed and prepared for reuse much more efficiently.
Preserve equipment value
-
Unlocked and correctly released equipment normally has greater reuse and resale potential than devices that remain restricted by company management.
Step 1: Identify How the Device Is Managed
Before removing a device, identify every system that may control, enrol or protect it.
The MDM application installed on the device may be only one part of the management process. The device may also be registered in a separate automated-enrolment system, identity platform or manufacturer ownership portal.
Check whether the equipment is connected to:
-
Microsoft Intune
-
Windows Autopilot
-
Microsoft Entra ID
-
Apple Business Manager
-
Apple School Manager
-
Apple Automated Device Enrolment
-
Jamf
-
Samsung Knox Manage
-
Samsung Knox Mobile Enrolment
-
Android Enterprise
-
Android zero-touch enrolment
-
Google Admin
-
VMware Workspace ONE
-
MobileIron or Ivanti
-
Another endpoint-management platform
Record the device serial number, asset number, IMEI number and management platform before making any changes.
Where several systems are used together, the device may need to be removed separately from each one.
Important
Do not assume that removing the visible management profile from the device has removed the organisation’s ownership or automated-enrolment record.


Step 2: Confirm Ownership and Disposal Authority
Confirm that the organisation owns the equipment and that an authorised person has approved its retirement.
The device should no longer be required by the assigned employee, department, customer, school, contractor or project. Any legal hold, investigation, insurance requirement, finance agreement or internal retention requirement should also be checked before removal.
The authorisation record should identify:
-
The device or group of devices
-
The serial numbers or asset numbers
-
The current user or department
-
The reason for retirement
-
The person approving disposal
-
The intended route, such as reuse, resale, donation or recycling
-
Any special data-destruction or reporting requirements
Removing a device from central management can affect the organisation’s ability to locate, secure or remotely erase it. The removal should therefore be completed only after disposal has been properly approved.
Step 3: Remove the Device from the MDM Platform
Use the organisation’s management console to remove the device from the active MDM environment.
The available commands vary between platforms. Common options include:
Retire
A retire command normally removes company applications, settings and organisational data while leaving personal information intact. This is often used for employee-owned devices.
Wipe
A wipe command normally erases the device and returns it to its factory settings. However, wiping does not necessarily remove automated enrolment or organisational ownership.
Delete
Deleting the device record removes it from the MDM console. Depending on the platform, deleting the record may not remove a separate enrolment or manufacturer registration.
Release
Releasing a device normally removes it from an organisation’s ownership within a manufacturer or automated-enrolment portal. This is different from simply deleting it from the MDM platform.
For business-owned equipment leaving the organisation, confirm that the device has been fully removed rather than merely marked as inactive, retired or wiped.
Important
Do not select a removal option purely because it contains the word delete or wipe. Confirm what the command actually removes before proceeding.


Step 4: Remove Automated Enrolment
Automated-enrolment systems can return a device to company management even after the MDM record has been deleted and the device has been factory reset.
Check for registration in:
-
Windows Autopilot
-
Apple Automated Device Enrolment
-
Samsung Knox Mobile Enrolment
-
Android zero-touch enrolment
-
Manufacturer or reseller deployment portals
The device should be unassigned, deregistered or released from the relevant enrolment service before it leaves the organisation.
A factory-reset device that remains registered may display messages such as:
-
Welcome to your organisation
-
Set up for work or school
-
Remote Management
-
This device belongs to an organisation
-
Sign in with your company account
-
This device will be automatically configured
Where possible, record confirmation that the automated-enrolment record has been removed.
Key point
Removing a Windows device from Intune does not automatically guarantee that it has been removed from Autopilot. Similarly, removing an Apple device from Jamf does not necessarily release it from Apple Business Manager.
Step 5: Remove Associated User and Company Accounts
Remove organisational accounts and user associations that are no longer required.
These may include:
-
Microsoft work or school accounts
-
Microsoft Entra ID registration
-
Managed Apple Accounts
-
Apple IDs
-
Google Workspace accounts
-
Samsung accounts
-
Company email accounts
-
VPN credentials
-
Authentication certificates
-
Single sign-on profiles
-
Managed application accounts
The user should sign out of personal or company cloud services before the device is reset. Where the user is no longer available, an authorised administrator may need to remove the account centrally.
Also check for account-protection features such as:
-
Apple Find My
-
Apple Activation Lock
-
Google Factory Reset Protection
-
Samsung Reactivation Lock
-
Microsoft account device protection
Removing the MDM profile alone may not remove these account-level protections.
See our guide to preparing IT equipment for collection for the wider process covering user accounts and activation locks.


Step 6: Offboard Apple Devices Correctly
Apple devices may be controlled through several connected systems. Removing the device from only one system may leave other restrictions in place.
Check the device in:
-
Apple Business Manager
-
Apple School Manager
-
The assigned MDM server
-
Jamf or another Apple management platform
-
Apple Find My
-
Activation Lock records
-
The normal offboarding process may include:
-
Confirming the device serial number
-
Removing or unmanaging it in the MDM platform
-
Unassigning it from the MDM server in Apple Business Manager
-
Releasing it from organisational ownership where appropriate
-
Signing out of the Apple account
-
Disabling Find My
-
Confirming that Activation Lock has been removed
-
Erasing and testing the device
Releasing an Apple device from Apple Business Manager is generally intended for equipment permanently leaving the organisation. Ensure the correct device has been selected before completing the release.
After reset, the device should reach the standard Apple setup process without displaying a Remote Management screen or requesting the previous Apple account.
Future supporting guides
-
How to release a device from Apple Business Manager
-
How to remove Jamf management before disposal
-
How to disable Apple Activation Lock
-
How to confirm Apple Remote Management has been removed
Step 7: Offboard Windows Devices Correctly
Windows computers may be connected to Microsoft Intune, Microsoft Entra ID and Windows Autopilot at the same time.
A complete offboarding process may require the device to be removed from all three systems.
Check:
-
The Intune device record
-
The Microsoft Entra device record
-
The Windows Autopilot device list
-
The assigned primary user
-
Work or school account connections
-
BitLocker recovery-key records
-
Other endpoint-security or remote-management software
Removing the computer from Intune may stop active management, but an Autopilot registration can still cause the computer to reconnect to the organisation during Windows setup.
After the relevant records have been removed, reset or reinstall Windows and confirm that the computer reaches the normal setup screen without requesting organisational credentials.
Where BitLocker is enabled, retain any required recovery information until data processing and verification have been completed.
Future supporting guides
-
How to remove a device from Microsoft Intune
-
How to remove a computer from Windows Autopilot
-
How to remove a device from Microsoft Entra ID
-
How to check BitLocker recovery keys before disposal


Step 8: Offboard Android and Samsung Devices Correctly
Android devices can remain connected to several different management and protection systems.
Check whether the device is enrolled through:
-
Android Enterprise
-
Google Admin
-
Android zero-touch enrolment
-
Samsung Knox Manage
-
Samsung Knox Mobile Enrolment
-
A manufacturer-specific management portal
-
Another third-party MDM platform
Before completing a factory reset:
-
Remove the device from the active MDM platform
-
Remove it from zero-touch or Knox enrolment
-
Remove managed Google or Samsung accounts
-
Disable any device-protection or tracking features
-
Confirm that Factory Reset Protection will not be triggered
-
Record the removal in the asset register
-
Reset and test the device
Google Factory Reset Protection may require the credentials of an account previously used on the device if accounts are not removed correctly before the reset.
After resetting, the device should reach the standard Android setup screen without automatically downloading company policies or requesting an organisation account.
Future supporting guides
-
How to remove Samsung Knox Mobile Enrolment
-
How to remove Android zero-touch enrolment
-
How to avoid Google Factory Reset Protection
-
How to remove Android Enterprise management
Step 9: Remove Devices from Other MDM Platforms
Organisations may use platforms such as Workspace ONE, Ivanti, MobileIron, Cisco Meraki Systems Manager or another specialist endpoint-management system.
Although the terminology differs, the same principles apply:
-
Remove active management
-
Remove the assigned user
-
Delete or retire the device record
-
Remove automated-enrolment assignments
-
Remove company certificates and profiles
-
Remove manufacturer ownership records
-
Check account and activation protection
-
Reset and test the device
Some platforms connect to Apple Business Manager, Android Enterprise, Samsung Knox or Microsoft services. Removing the record from the main dashboard may not remove those connected registrations.
Where the correct process is unclear, consult the organisation’s IT administrator or the platform documentation before wiping the equipment.


Step 10: Factory Reset the Device
The factory reset should normally be completed after management, automated enrolment and account protection have been removed.
Resetting too early can make the offboarding process more difficult. It may remove local access to the device while leaving the central management records active.
Before resetting, confirm that:
-
Required business data has been backed up
-
The disposal has been authorised
-
The device has been removed from the MDM platform
-
Automated enrolment has been removed
-
User and company accounts have been disconnected
-
Activation and account locks have been disabled
-
Recovery information has been retained where required
-
Removable storage has been taken out
Use the manufacturer-approved reset method and allow the process to complete fully.
A factory reset is not always equivalent to certified data destruction. Equipment containing sensitive data may require additional erasure, degaussing or physical destruction according to the organisation’s security requirements.
Step 11: Test the Device After Reset
A successful reset does not by itself confirm that the device has been completely offboarded.
Switch the equipment on and proceed far enough through the initial setup process to check its status.
Confirm that:
-
The standard manufacturer setup screen appears
-
No company login is requested
-
No Remote Management screen appears
-
No previous user credentials are required
-
No organisation name or branding appears
-
No company applications are automatically installed
-
No management profile returns
-
The device does not automatically re-enrol
-
Activation Lock or Factory Reset Protection is not present
The device does not normally need to be fully configured with a new account. It only needs to be tested far enough to confirm that no previous organisational control remains.
Where a restriction is found, record the exact message shown and the device serial number. This will make further investigation easier.


Step 12: Record the Removal
Update the organisation’s asset and management records after the offboarding process has been completed.
Record:
-
Asset number
-
Serial number
-
IMEI number where applicable
-
Device type
-
Assigned user or department
-
MDM platform
-
Automated-enrolment platform
-
Date of removal
-
Administrator completing the work
-
Commands or actions completed
-
Reset status
-
Test result
-
Any remaining restrictions
-
Final disposal route
The device should no longer appear as active, compliant, assigned or available for deployment within the organisation’s systems.
Retaining a clear audit record provides evidence that the equipment was correctly removed from management before it left the organisation.

Common MDM Offboarding Mistakes
Factory resetting before removing management
The device may still be registered centrally and automatically return to company management during setup.
Removing Intune but leaving Autopilot active
The Windows computer may appear unmanaged but reconnect to the organisation when Windows is reinstalled.
Removing Jamf but not Apple Business Manager
The Apple device may still display Remote Management after it has been erased.
Deleting the device record without releasing ownership
A deleted record does not always remove the device from a manufacturer’s organisational portal.
Removing the MDM profile but leaving the user account
Activation Lock, Factory Reset Protection or another account restriction may remain.
Assuming an offline device is unmanaged
A device that has not contacted the server recently can still remain registered and may reconnect later.
Sending equipment without testing it
The problem may not become visible until the device is processed or prepared for reuse.
Removing the wrong device
Always verify serial numbers, asset numbers and IMEI numbers before deleting, releasing or wiping records.
Locked Devices and Additional Administration
Devices that remain connected to MDM, automated enrolment, user accounts or activation protection require additional investigation and administrative work.
Bioteknik may attempt to identify the restriction, record the device details and provide the relevant information to the customer. However, only the former organisation or authorised account holder may be able to remove some types of management or account protection.
Where additional work is required because equipment has not been correctly offboarded, an administration charge of £10 per affected device may apply.
This charge helps cover the time required to:
-
Inspect the device
-
Identify the type of restriction
-
Record serial numbers and asset details
-
Attempt available reset or removal procedures
-
Communicate findings to the customer
-
Retest the device after changes
-
Separate restricted devices from normal processing
Removing MDM, automated enrolment and account protection before collection helps avoid these charges and improves the likelihood that equipment can be reused.

Final MDM Offboarding Checklist
Before releasing managed devices for collection, confirm that:
-
Disposal has been properly authorised
-
Device serial numbers and asset numbers have been recorded
-
The assigned user or department has been removed
-
Required business data has been backed up
-
The device has been removed from the MDM platform
-
Automated enrolment has been removed
-
Microsoft, Apple, Google or Samsung accounts have been disconnected
-
Activation Lock and Factory Reset Protection have been checked
-
Manufacturer ownership records have been released where appropriate
-
Recovery information has been retained where required
-
The device has been factory reset
-
The device has been tested after reset
-
No organisation login or Remote Management screen appears
-
The removal date and administrator have been recorded
-
Any unresolved restrictions have been reported before collection
Preparing Managed Devices for Collection
Correct MDM offboarding protects organisational security, improves the value of retired equipment and gives devices the best possible opportunity for reuse.
Bioteknik provides secure business IT collections, IT asset disposal, data destruction, refurbishment and responsible recycling services throughout London, Kent and the wider South East.
Before arranging a collection, organisations should remove devices from all management, enrolment and account-protection systems and inform us of any restrictions that remain.
More IT Lifecycle Guides
Preparing IT Equipment for Collection
Follow the essential steps for recording, securing and preparing business IT equipment before it is collected for reuse, recycling or data destruction.
Removing Devices from Microsoft Intune
Learn how to retire and delete devices from Microsoft Intune so they are no longer managed or automatically re-enrolled.
Removing Windows Devices from Autopilot
Remove Windows devices from Autopilot and associated Microsoft records before resetting them for reuse, resale or secure disposal.
Releasing Devices from Apple Business Manager
Release Macs, iPhones and iPads from Apple Business Manager and remove any associated management or activation restrictions.
Removing Samsung Knox Enrolment
Remove Samsung devices from Knox management and automated enrolment before carrying out a factory reset or transferring ownership.
Preventing MDM Re-enrolment After Reset
Understand why devices can return to company management after a reset and how to clear the remaining enrolment records correctly.
