Last updated: July 24, 2026
Generate time-bound, device-specific recovery keys in Mobile Device Manager Plus for emergency access when standard authentication fails or devices are offline; three key types support unlocking devices after passcode lockouts, pausing Kiosk mode, or revoking management profiles.
Mobile Device Manager Plus allows you to generate a recovery key to revoke device management in critical situations. This key serves as a backup access method when standard authentication fails or when the device is unreachable due to network issues.
You may need a recovery key in the following scenarios:
All these three keys can be used when the device is offline.



Follow the below-given steps based on the recovery key type
Unlocking Device:
To unlock your device after too many passcode attempts, enter the recovery key to reset your passcode.
Pause Kiosk:
1. If the Self Service app (previously ME MDM app) is not allowed in the kiosk allowed apps list:
2. If the Self Service app (previously ME MDM app) is allowed in the kiosk allowed apps list:
3. If the Self Service app (previously ME MDM app) is not allowed and the Home button is restricted:
Revoke Management:
To enter the 'Revoke Management Recovery Key' on the device, first open the Self Service app (previously ME MDM app) icon and click four times on the top pane where the app name is visible. A Password Prompt dialog box appears where the Recovery Key can be entered.
Use a recovery key when standard authentication fails or the device is unreachable - for unlocking a device after failed passcode attempts, temporarily pausing Kiosk mode, or revoking management (removing the MDM profile); all three key types work even when the device is offline.
Administrators can generate all three key types; unlock-device and pause-kiosk keys additionally require Inventory Full Access permission, while the Revoke Management key requires Deprovision-Write access, and each generated key is time-bound and expires after a set period.