# Deprovisioning Devices Keeping track of all the mobile devices in an organization is a crucial device management task to be performed by any mobile device management solution. IT admins need to have complete information about the devices that are in use and the ones that are not currently a part of the workforce. The admin should also be able to deprovision the devices that are not in use. Using Mobile Device Manager Plus, all that the IT admin has to do is mark the devices to be deprovisioned. ## Why deprovision devices? Deprovisioning devices completely removes them from management. In case of lost devices, devices requiring maintenance, and devices of employees who are leaving the organization, they have to be removed from management. Such devices have to be deprovisioned. For workspace-managed devices, the work profile can be revoked. In case of fully managed devices, they can be factory reset. ## How to deprovision a device? Deprovision can be done either for a single device or multiple devices. For deprovisioning individual devices, navigate to **Enrollment > Devices > Managed > Actions > Deprovision**. You can also choose multiple devices from this tab and then deprovision them. For Zebra device deprovisioning, refer to [this page](https://www.manageengine.com/mobile-device-management/help/enrollment/zebra_deprovision.html). ### Important note: To prevent accidental or unauthorized bulk deprovisioning, the following limits apply: 1. **Per action limit:** Up to 25 devices for Corporate Wipe and 10 devices for Complete Wipe. 2. **24-hour limit:** Up to 100 devices or 40% of managed devices (whichever is lower) for Corporate Wipe, and up to 50 devices or 20% of managed devices (whichever is lower) for Complete Wipe, within a rolling 24-hour period. These limits are calculated per day and reset at 00:00 UTC. ## Revoke MDM ![Revoke MDM](https://www.manageengine.com/mobile-device-management/help/images/deprovision2.png) **Revoke MDM** erases only corporate data (work apps, company documents, etc.) present on the device. The user's personal data (personal apps, personal files, etc.) remains safe and present on the device. **Note:** The data once deleted cannot be restored. ## Factory reset device ![Factory reset device](https://www.manageengine.com/mobile-device-management/help/images/deprovision1.png) Wipe options (**Retain MDM profile**, **Unlock PIN**, **Retain eSIM data**, **Retain SD card data**) are applicable only when **Factory reset device** is selected. **Retain MDM profile:** Applicable only for devices enrolled via Windows Autopilot. **Unlock PIN:** After factory reset, the device must be unlocked using this new PIN to initiate device bootup. Applicable only for macOS devices. **Retain eSIM data:** When enabled, eSIM configurations will be retained on the device even after factory reset. Applicable for iOS/iPadOS devices. **Retain SD card data:** Applicable for all Android devices. These options are shown based on the device platform selected for deprovision. If a complete wipe is performed, both corporate and personal data will be deleted. **Note:** - Complete wipe can be performed on both Supervised and Unsupervised Apple devices based on the permissions configured in the device privacy settings in MDM prior to enrollment. - Complete wipe can be performed only on fully managed and WPCO Android devices, but not workspace-managed devices. - You can deprovision corporate data for up to 25 devices at once. - You can perform complete wipe for up to 10 devices at once. ## Move devices to Personal devices can only be moved to retired. Corporate devices can be moved to stock, repair, or retire. - **In Stock** – When employees leave the organization, their mobile devices can be deprovisioned and moved to **"In Stock"**, allowing them to be re-enrolled and assigned to another user. - **Repair** – Mobile devices often require servicing, and while under repair, they cannot be part of the workforce. However, they may still contain corporate data. When a device is being repaired, it can be marked as **"In Repair"** in the MDM server. Once repaired, it can be re-enrolled. If the device cannot be repaired and needs to be permanently removed from MDM, it can be removed through the Actions option. - **Retire** – If a device is moved to Retired, it will be deprovisioned. Personal devices remain available on the server for 90 days, after which they are automatically removed. Corporate devices must be manually removed. **Note:** Specify the reason for deprovision as it is used for audit log purposes. Deprovisioned devices can be removed or reenrolled. If the device was enrolled using KNOX, ABM/ASM, Zero-touch, or Chrome enrollment, it will be automatically re-enrolled upon boot up. ## Deprovisioning Settings Admins can deprovision devices from MDM when a device is no longer in use or when an employee leaves the company. Deprovisioning devices completely erases all corporate data present on the device, helping protect corporate data associated with unmanaged devices. In MDM, admins can configure certain settings to predefine the device deprovisioning process. 1. **Revoke MDM from devices once users are deactivated in Okta** – Admins can configure automatic deprovisioning of devices associated with users who are disabled or removed from the Okta directory. **Note:** Deprovisioning is not possible when a user has more than three associated devices and when the device count exceeds 50. Desktops and laptops remain continuously provisioned. 2. **Upon deprovisioning, sign out the associated Google Workspace (G Suite) users across all apps** – This removes all data and accounts associated with G Suite users from the device. 3. **Notify via email when device unmanaged by user:** For personal devices, since users cannot be completely restricted from revoking management, admins can enable the option **Notify when the device becomes unmanaged**. Admins can specify multiple email addresses to receive notifications. 4. **Show unenrollment option in ME MDM app:** Device management can be revoked by the user if this option is enabled in the product console. Learn how to prevent device unenrollment in ME MDM App: [Learn How to prevent Device Unenrollment in ME MDM App](https://www.manageengine.com/mobile-device-management/how-to/revoke-enrollment.html) ## Remove admin enrolled deprovisioned devices If a device enrolled using admin enrollment is deprovisioned, the device will be unenrolled but not removed from the respective portals. Follow these documents to remove devices from: - [ABM](https://www.manageengine.com/mobile-device-management/help/enrollment/apple_business_manager_enrollment.html#Removing_devices_from_ABM) - [Zero-touch](https://www.manageengine.com/mobile-device-management/help/enrollment/android_zero_touch_enrollment.html#dissociating_zero-touch) - [Chrome](https://support.google.com/chrome/a/answer/3523633?sjid=5552772937585314930-AP#zippy=%2Cdeprovision-a-device) - [Knox](https://www.manageengine.com/mobile-device-management/help/enrollment/knox_mobile_device_management.html#remove) ## FAQs ### 1. How do I remove MDM from an Android device that is no longer connected to the server? If the Android device is offline, the deprovision command does not reach it. In this case, the available options are to use a **Device Access Recovery Key** (for Android Device Owner devices with a forgotten passcode) or perform manual removal by factory resetting the device.