# Security Management Mobile Device Manager Plus can be used to remotely secure data in mobile devices even in the event of the device being lost or missing. The following operations can be done using the security commands in MDM. To perform actions like sending commands (e.g., Remote Lock) or wiping a device, go to Inventory, select the device, open the Actions menu, choose the desired command (e.g., Remote Lock, Deprovision (Wipe), or Corporate/Complete Wipe), confirm the action, and monitor the status in the Inventory tab. ![Device management actions menu in MDM showing options like Remote Lock and Wipe.](https://www.manageengine.com/mobile-device-management/help/images/remotecommand.png) ## Remote Lock You can remotely lock the managed mobile device. After a remote lock is performed, the user is prompted to enter the passcode of the mobile device only if you have [set a passcode](https://www.manageengine.com/mobile-device-management/help/profile_management/android/mdm_android_passcode.html) for the device. This feature is supported for **Android, iOS, macOS.** In devices running **iOS 7 or later versions**, you can also specify a **message and a contact number** while locking the device. The device can be unlocked using the existing passcode. For macOS devices, you can only specify a message to be displayed while locking the device. The existing passcode will be rendered invalid, and the device can be unlocked only using the PIN set by the admin. **This feature is not supported on Windows devices.** Follow the steps mentioned below to specify a contact number and message on devices running iOS 7 or later: 1. On the web console, navigate to **Devices**. 2. Select the device to be locked. 3. Under **Actions**, click on **Remote Lock**. Enter the contact number and message to be displayed on the locked screen. ## Scan Now You can scan the enrolled mobile device to view details about installed apps, blacklisted apps, restrictions imposed on the device, and other device details. Scanning can be performed only when the device is connected to the internet. **This feature is supported for Android, iOS, Windows, and ChromeOS.** If [Periodic communication mode](https://www.manageengine.com/mobile-device-management/help/enrollment/customize_me_mdm_app.html#Configure_Mode_of_Communication) is chosen, the scanning operation has a 60-minute communication interval with the server. Scanning takes place the next time the device interacts with the server. ## Remote Alarm You can trigger an alarm on the mobile device if it is lost or stolen. It sounds an alarm even if the device is in silent mode. The alarm stops only when the device is unlocked. This feature is applicable for **Android, iOS (Supervised), and Windows phones**, with iOS requiring [Lost Mode](https://www.manageengine.com/mobile-device-management/help/security_management/location_tracking.html#Lost_Mode_iOS) to be enabled for Remote Alarm to work. **Note:** After enabling Lost Mode, the option to trigger a **Remote Alarm** will be available under **Inventory Actions**. ## Complete Wipe All data on the device can be completely wiped using this command. The device becomes as good as new. You can also wipe all data from the device's SD card for Knox devices. Supported for **Android, iOS, macOS, ChromeOS, and Windows.** ## Corporate or Selective Wipe All profiles and apps previously installed using MDM are wiped in **iOS, macOS, and Android devices.** In Windows devices, only profiles are removed and not the apps. Personal data on the device is not affected. The device is no longer managed by MDM. **Note:** In EC Inventory, Corporate Wipe and Complete Wipe are shown only for Modern Management Devices (macOS and Windows). In standalone and integrated (EC MDM) MDM Inventory, [Deprovision](https://www.manageengine.com/mobile-device-management/help/enrollment/mdm_device_deprovision.html) is shown instead of Wipe actions. ## Logout User This command lets the admin log out the current users on **Shared iPads**, even when users are currently logged in or when iCloud data sync is in progress. ## Delete User This command lets the admin select users on Shared iPads or Mac and delete the session for all device users. With force deletion, users can be deleted even when logged in or when iCloud data sync is in progress. Applicable for **Shared iPads and Mac machines running macOS 10.13 and above.** **Note:** For Mac machines, the administrator user with a secure token cannot be deleted. ## Clearing the Passcode This command clears the passcode completely. If a passcode policy was previously associated, the user is prompted to enter a new passcode. Clearing the passcode also clears biometric-based passcodes in all **iOS and Android devices (provisioned as Device Owner)** except Samsung devices running Android 5.0. **Not supported for Windows devices.** ## Reset Passcode You can reset the passcode on managed devices. If the new passcode does not meet complexity criteria or if no passcode was set, the user is prompted to set one as per policy. Applicable only for **Android devices.** Admins can specify the new passcode and send a notification mail to the user. **Note:** - Passcodes set by users cannot be removed or reset from Samsung devices running Android 9.0 or above enrolled via invite. OS-specific details are provided in the table below. - For Android 14.0 and above, the minimum passcode length should be 6. ## Clear Screentime Passcode Admins can remotely clear the Screen Time passcode on **Supervised iOS devices.** - In iOS 11.0 and earlier, this removes Screen Time passcode restrictions and constraints. - From iOS 12.0 and above: - If **Share Across Devices** is enabled, the command clears the Screen Time passcode and its restrictions. It fails if the user is a child in an iCloud family. - If Share Across Devices is disabled, it clears only the Screen Time passcode, not other restrictions. You can enable/disable users from configuring [screen time restrictions](https://www.manageengine.com/mobile-device-management/help/profile_management/ios/mdm_restrictions.html) on the device. ## Device Access Recovery Key If a managed device is locked due to incorrect passwords, you can perform **Clear Passcode** or generate a **Device Access Recovery Key** to unlock it. Supported for Android devices enrolled as **Device Owner**. Once half the maximum number of failed attempts (defined in the [passcode policy](https://www.manageengine.com/mobile-device-management/help/profile_management/android/mdm_android_passcode.html)) is exhausted, users are redirected to the recovery key page. Example: If the maximum failed attempts value is 6: - After 3 failed attempts, the device locks and can be unlocked using the recovery key. - After 6 failed attempts, the device data is wiped. To learn how to generate a Device Access Recovery Key, [click here](https://www.manageengine.com/mobile-device-management/how-to/device-access-recovery-key.html). ## Pause Kiosk The Pause command lets you pause Kiosk mode on devices previously provisioned with Kiosk. Used for troubleshooting. You can automatically resume Kiosk after a specified time using the [Resume Kiosk](#resume_kiosk) command. You can also pause Kiosk using other methods as [listed here](https://www.manageengine.com/mobile-device-management/help/profile_management/android/android_kiosk.html#Temporarily_Disabling_Kiosk). **Supported only for Android devices.** ## Resume Kiosk If a device provisioned as Kiosk is paused, the Resume command restores it to Kiosk mode. Other resume methods are [listed here](https://www.manageengine.com/mobile-device-management/help/profile_management/android/android_kiosk.html#Temporarily_Disabling_Kiosk). **Supported only for Android devices.** MDM supports pausing and resuming Kiosk using different methods, including remote chat commands and security commands. ## Enable Lost Mode This command marks devices as lost and initiates [Lost Mode](https://www.manageengine.com/mobile-device-management/help/security_management/location_tracking.html#Lost_Mode). Before enabling Lost Mode, be aware of potential failures when disabling it, as outlined in [Apple's protocol document](https://developer.apple.com/documentation/devicemanagement/disable_lost_mode#discussion). Failed attempts may cause the device to remain stuck in Lost Mode. **Note:** For devices without SIM cards (e.g., iPads), restarting while in Lost Mode may disconnect Wi-Fi and lock the device. Clear the passcode after enabling Lost Mode but before restarting. ### Lost Mode Behaviour - The Lost Mode screen is displayed only when the device is locked. - If a user unlocks the device while Lost Mode is active, it will immediately lock again. - If no passcode is configured, the device powers on unlocked. MDM immediately locks it, and the Lost Mode screen will not be displayed. To ensure proper functionality, the device must be secured with a passcode. If not configured, the administrator must set one through Lost Mode configuration. ## Restart Remote Restart is applicable for: - Supervised iOS devices running iOS 10.3 or above - Samsung or non-Samsung devices running 7.0 or later provisioned as Device Owner - macOS devices - Windows devices - Chrome OS devices provisioned in Kiosk Mode **Note:** - Remote Restart and Remote Shutdown can be scheduled. Watch [this video](https://www.youtube.com/watch?v=k-gf9bsEE0Y) to learn more. - On Windows devices, the command executes 5 minutes after acknowledgment. - On Chrome devices, the command expires if the device does not contact the MDM server within 10 minutes. - On Apple devices, password-protected devices must be unlocked after restart to connect to Wi-Fi. - macOS devices provide an option to notify users to restart. - For scheduling steps, refer to [this document](https://www.manageengine.com/mobile-device-management/help/asset_management/mdm-bulk-actions.html#Scheduling_Remote_Restart_and_Shutdown_for_Groups_and_Devices). ## Wipe Users Wipes all users and user profiles from the device. **Applicable only for Chrome devices.** ## Take Screenshot Executes a screenshot on Chrome devices provisioned in Kiosk mode. The command expires if the device does not contact the MDM server within 10 minutes. Screenshots are recorded under Device Files (Inventory > Devices > System Activity). To view them, sign in to the Google Admin Console. ## Set Volume Sets the volume level on kiosk devices remotely. The command expires if the device does not contact the MDM server within 10 minutes. **Applicable only for Chrome devices.** ## Recover User Account When a device is locked after exceeding the maximum number of failed attempts in [Passcode](https://www.manageengine.com/mobile-device-management/help/profile_management/mac/mdm_mac_passcode.html#overview), the account can be remotely unlocked using **Recover User Account**. Supported for **macOS 10.13 and above.** Only devices running Android 5.0 or above can be provisioned as [Profile Owner](https://www.manageengine.com/mobile-device-management/help/android_for_work/mdm_android_for_work_introduction.html#Profile_Owner) or [Device Owner](https://www.manageengine.com/mobile-device-management/help/android_for_work/mdm_android_for_work_introduction.html#Device_Owner). ## Android OS Support Matrix | ANDROID OS VERSION | DESCRIPTION | SAMSUNG (Invites) | PROFILE OWNER (Invites) | CORE ANDROID (Invites) | DEVICE OWNER (Admin Enrollment) | |---|---|---|---|---|---| | **Clear Passcode** | | | | | | | Below Android 5.0 | Passcode applied to the work profile in a Profile Owner provisioned device and the device passcode in a Device Owner provisioned device cannot be cleared. | ![success](https://www.manageengine.com/mobile-device-management/help/images/success.png) | ![success](https://www.manageengine.com/mobile-device-management/help/images/failured.gif) | ![failured](https://www.manageengine.com/mobile-device-management/help/images/success.png) | ![failured](https://www.manageengine.com/mobile-device-management/help/images/failured.gif) | | Android 5.0 and 6.0 | Passcode applied to the work profile in a Profile Owner provisioned device cannot be cleared. | ![success](https://www.manageengine.com/mobile-device-management/help/images/success.png) | ![success](https://www.manageengine.com/mobile-device-management/help/images/failured.gif) | ![failured](https://www.manageengine.com/mobile-device-management/help/images/success.png) | ![success](https://www.manageengine.com/mobile-device-management/help/images/success.png) | | Android 7.0 | Passcode applied to a device provisioned as Device Owner and the work profile passcode in a Profile Owner provisioned device can be cleared. | ![success](https://www.manageengine.com/mobile-device-management/help/images/success.png) | ![failured](https://www.manageengine.com/mobile-device-management/help/images/success.png) | ![failured](https://www.manageengine.com/mobile-device-management/help/images/failured.gif) | ![success](https://www.manageengine.com/mobile-device-management/help/images/success.png) | | Android 8.0 and above | Passcode can be cleared in Samsung devices provisioned as Device Owner and the work profile in Profile Owner provisioned devices. | ![failured](https://www.manageengine.com/mobile-device-management/help/images/success.png) | ![failured](https://www.manageengine.com/mobile-device-management/help/images/success.png) | ![failured](https://www.manageengine.com/mobile-device-management/help/images/failured.gif) | ![success](https://www.manageengine.com/mobile-device-management/help/images/success.png) | | **Reset Passcode** | | | | | | | Below Android 5.0 | Passcode applied to the work profile in a Profile Owner provisioned device and the device passcode in a Device Owner provisioned device cannot be reset. | ![success](https://www.manageengine.com/mobile-device-management/help/images/success.png) | ![success](https://www.manageengine.com/mobile-device-management/help/images/failured.gif) | ![failured](https://www.manageengine.com/mobile-device-management/help/images/success.png) | ![failured](https://www.manageengine.com/mobile-device-management/help/images/failured.gif) | | Android 5.0 and 6.0 | Passcode applied to the work profile in a Profile Owner provisioned device cannot be reset. | ![success](https://www.manageengine.com/mobile-device-management/help/images/success.png) | ![success](https://www.manageengine.com/mobile-device-management/help/images/failured.gif) | ![failured](https://www.manageengine.com/mobile-device-management/help/images/success.png) | ![success](https://www.manageengine.com/mobile-device-management/help/images/success.png) | | Android 7.0 | Passcode applied to a device provisioned as Device Owner and the work profile passcode in a Profile Owner provisioned device can be reset. | ![failured](https://www.manageengine.com/mobile-device-management/help/images/success.png) | ![failured](https://www.manageengine.com/mobile-device-management/help/images/success.png) | ![failured](https://www.manageengine.com/mobile-device-management/help/images/failured.gif) | ![success](https://www.manageengine.com/mobile-device-management/help/images/success.png) | | Android 8.0 and above | Passcode can be reset in Samsung devices provisioned as Device Owner and the work profile in Profile Owner provisioned devices. | ![failured](https://www.manageengine.com/mobile-device-management/help/images/success.png) | ![failured](https://www.manageengine.com/mobile-device-management/help/images/success.png) | ![failured](https://www.manageengine.com/mobile-device-management/help/images/failured.gif) | ![success](https://www.manageengine.com/mobile-device-management/help/images/success.png) | ## Knox Remote Actions For Knox, security commands can be executed separately for the device and the container. - **Create Container:** Distribute Knox License and create a Knox Container within a supported device. - **Remove Container:** Remove the Knox Container and revoke the Knox license. - **Lock Container:** Lock the Knox Container and restrict user access. - **Unlock Container:** Unlock the container to permit access. - **Clear Passcode:** Clear the Knox Container passcode. The user must set a new passcode adhering to complexity criteria. Follow the steps below to use security commands: 1. Navigate to **Devices** under the **Inventory** tab. 2. Click the specific device under **Device Name**. 3. Click the **Action Button** and select the action. Enter your password to authenticate. 4. The specified security command is executed and status is reported under **Device Details**. ## Troubleshooting Tips **Issue:** This Mac is Locked. Try again in 24,284,826 minutes. ![ ](https://www.manageengine.com/mobile-device-management/help/images/epochmactime.png) **Cause:** The Mac was MDM-locked and left powered on. Its battery drained completely. After restart, the system clock reset to Epoch time (00:00:00 UTC, January 1, 1970). **Solution:** - Connect the device directly to the corporate network via Ethernet. - Allow 30 minutes of uninterrupted uptime. - Perform a full restart and verify the device unlocks. ## FAQ **Why does the Clear Passcode / Reset Passcode inventory action fail on devices enrolled using ADB enrollment?** If a passcode was set **before ADB enrollment**, the **Clear Passcode** and **Reset Passcode** actions will fail. In this case, wipe the device and enroll again. If the passcode is configured **after ADB enrollment**, these actions will work as expected.