Updated: May 2025
This post was updated to include new Microsoft Intune functionality that allows organizations to require multiple authorizers for remote actions like Force Wipe.
Introduction to Force Intune Wipe
When managing a mobile workforce, safeguarding your corporate data is crucial, especially when devices are lost, stolen, or compromised. One of the most effective ways to protect sensitive information in such scenarios is by enforcing a remote wipe through Microsoft Intune. In this guide, we’ll explore how to force an Intune wipe, ensuring that devices can be remotely wiped to prevent unauthorized access.
We’ll differentiate between a full device wipe and a selective wipe, helping you understand which option is best suited for specific scenarios. Whether you’re managing corporate-owned devices or BYOD (Bring Your Own Device) policies, knowing how to remotely enforce a wipe can be the difference between a potential data breach and maintaining the integrity of your organization’s security posture.
Why Device Wipes Matter for Security
A force Intune wipe becomes a critical tool in preventing unauthorized access when a device is lost, stolen, or compromised. With employees accessing confidential information from various locations, the risk of data exposure is higher than ever.
Implementing an Intune remote wipe ensures that any device, regardless of its location, can be securely wiped to prevent data leaks or misuse. This ability to do this is especially important in scenarios such as:
- When devices are lost or stolen, where the risk of unauthorized access to sensitive data is immediate.
- When employees are leaving the organization, where company data needs to be fully erased from BYOD scenarios to prevent retention of proprietary information.
- When devices have been compromised through malware or unauthorized access, where a wipe becomes a rapid response to mitigate further damage.
- If you are giving an employee a new device and want to store and retain the old one for re-distribution later.
We’ll keep you up to date on the latest in Microsoft Cybersecurity.
Types of Wipes Available in Intune
Microsoft Intune provides several options for wiping devices, each designed to meet different security needs and scenarios. Understanding these options will help you determine the best wipe method based on the situation at hand. Here’s a breakdown of the available wipe types:
Full Device Wipe
A full device wipe completely removes all data, including the operating system, apps, and personal files, returning the device to its factory settings. This is ideal for corporate-owned devices that are lost, stolen, or no longer in use by employees. A full Intune wipe ensures that no residual data remains on the device, making it the most secure option in critical situations.
Selective Wipe
Selective wipe is designed for BYOD (Bring Your Own Device) scenarios, where personal devices are enrolled for accessing corporate data. This option removes only the organization’s data, leaving personal files and apps intact. It’s an effective balance between protecting corporate information and respecting employees’ personal data. Intune wipe for BYOD allows for continued personal use of the device without exposing company data.
Autopilot Reset
This option is useful for reassigning or repurposing devices. The Autopilot Reset feature removes personal files, apps, and settings while keeping the device enrolled in Intune and maintaining the network settings. It’s typically used in scenarios where devices are being passed to new users within the organization.
Fresh Start
Similar to the full device wipe, Fresh Start removes all user-installed apps and resets the device, but it retains some core settings like the current version of Windows. This method is ideal for refreshing devices without completely wiping the OS and configuration settings.
How to Perform a Force Intune Wipe
Now that we’ve covered the different types of wipes, let’s dive into the step-by-step process of performing a force Intune wipe using the Microsoft Endpoint Manager. This guide will walk you through remotely wiping a device, even in cases where it might not be actively connected to the internet.
Force Intune Wipe: A Step-by-Step Guide
Accessing Microsoft Endpoint Manager
- Begin by logging into the Microsoft Endpoint Manager Admin Center. This is where all device management tasks, including wipes, are performed.
- Navigate to Microsoft Endpoint Manager and sign in using your admin credentials.
Locating the Device
- Once logged in, select Devices from the left-hand navigation menu.
- Click on All Devices to display a list of the devices currently enrolled in Intune.
- Search for or manually locate the device that requires a wipe. You can use the device name, user, or device identifier to find the target device quickly.
Initiating the Wipe
- After selecting the device, click on the Wipe You will be prompted to confirm the wipe action.
- If you need to force the wipe, even if the device is not currently connected to the internet, choose the option that enables the wipe command to be queued and executed once the device reconnects. This ensures that the wipe will occur as soon as the device comes online.
- Confirm the wipe to initiate the process.
Monitoring the Wipe Status
- After initiating the Intune remote wipe, you can monitor its status by navigating to the Device Overview Here, you’ll be able to see if the wipe has started, is pending, or has successfully completed.
- The Force Intune Wipe command will remain in the queue until it’s successfully carried out, providing you peace of mind that the device will be wiped at the earliest opportunity.
This method ensures that even if the device is offline at the time of the wipe request, the command will be enforced once the device reconnects, guaranteeing data protection.
See How To Do An Intune Wipe In Real Time
In this video, Levacloud’s Founder and Chief Architect, Gareth Young, discusses Intune wipes, their use cases, and how to perform them.
How to Perform a Selective Wipe
Now that we’ve looked at force wipe, let’s take a look at the step-by-step process of performing a selective wipe. This guide will show you how to securely wipe only corporate data from a device, allowing personal data to remain intact, which is especially useful for bring-your-own-device (BYOD) scenarios.
Accessing Microsoft Endpoint Manager
- Begin by logging into the Microsoft Endpoint Manager Admin Center. This is where you manage devices and initiate selective wipes.
- Navigate to Microsoft Endpoint Manager and sign in using your admin credentials.
Initiating the Selective Wipe
- Go to Apps in the left-hand navigation menu, then select App Selective Wipe.
- Search for the user’s device (e.g., iPhone or Android) by using their name or user information.
- Click on Create Wipe Request to initiate a selective wipe. This action will only remove corporate data from the apps while leaving the user’s personal data intact.
App Protection Policy
- Ensure an App Protection Policy is in place, which creates an encrypted container for corporate apps on the device.
- This policy ensures that only the encrypted corporate data is removed during the wipe, leaving the personal data unaffected.
Wondering if Levacloud can solve your Microsoft Cybersecurity related challenge? Drop us a message!
Common Issues and Troubleshooting Tips
While performing a force Intune wipe is generally straightforward, there are some common issues you might encounter. Understanding these potential challenges and knowing how to troubleshoot them can save you time and ensure the wipe is successful.
Device Connectivity Issues
One of the most frequent challenges when performing a force Intune wipe is device connectivity. If a device is offline or out of range, the wipe command will not execute until the device reconnects to the internet. To mitigate this issue:
- Ensure the device is set to automatically connect to known Wi-Fi networks when available.
- Queue the Intune remote wipe command, which will trigger once the device is back online.
- Use device monitoring tools in Microsoft Endpoint Manager to check connectivity status.
Issues with Device Enrollment Status
If the device is not properly enrolled or has been unenrolled from Intune, the wipe command may not go through. This can happen if the device was decommissioned or removed from the organization’s Intune management system.
- Confirm the device’s enrollment status under the Device Overview page.
- If the device was unenrolled by mistake, re-enroll the device to re-establish management before issuing the wipe command.
Verifying the Wipe Completion
Sometimes, after initiating a wipe, administrators may not be sure if the wipe successfully completed, especially in cases where devices were offline. To confirm that the force Intune wipe has been executed:
- Check the Device Overview page for status updates. A completed wipe will show a confirmation message indicating that the device has been reset.
- If the device remains offline for an extended period, use alternate methods such as contacting the device user or monitoring network activity to check if the device has come back online.
Wipe Command Not Executing
In rare cases, the wipe command may not execute even after the device reconnects. This could be due to:
- Device-specific issues, such as hardware failures or a corrupted OS.
- Misconfigurations in Intune policies or device compliance settings.
To resolve this:
- Verify that the device complies with all Intune policies.
- Consider resetting the device manually if remote wipe fails.
You have a pressing issue, but you’re not sure if Levacloud can help. We get it. Everyone has unique challenges they face in their IT environments. Schedule a free call today and talk us through it.
We’ll let you know how we can best support you.
Best Practices for Using Force Intune Wipe Features
To ensure optimal use of the Intune wipe capabilities, it’s important to follow certain best practices that balance security, user experience, and operational efficiency. This section outlines key strategies to effectively manage and wipe devices within your organization.
Which wipe should you choose?
Choosing between a full wipe and a selective wipe depends on the context:
- Full Wipes should be used for corporate-owned devices or scenarios where a device is lost, stolen, or permanently decommissioned. This removes all data and settings, ensuring that no sensitive information can be accessed.
- Selective Wipes are ideal for BYOD environments, where personal devices are used for work. This type of wipe ensures that only corporate data is removed, leaving personal files and apps untouched. This helps maintain user satisfaction while protecting business data.
- Wipe and Retain Enrollment State, this is for troubleshooting or reassignment of devices, Wipe with Retained Enrollment State is the best option. It wipes the device’s data while keeping the device enrolled in Intune and maintaining the associated user account. This allows for quick issue resolution or device reassignment without requiring a full re-enrollment.
- Wipe and Continue if Device Loses Power or Internet. In cases where a device is lost or stolen, you can use the Wipe and Continue option. This ensures that the wipe will execute even if the device loses power or internet connectivity. As soon as the device reconnects to the internet, the wipe command is completed, providing an additional layer of security in high-risk situations.
When possible, automate these choices through device policies that apply Intune remote wipe commands based on device ownership or user role.
Automating Wipes Using Conditional Access Policies
Integrating device wipes into your organization’s conditional access policies can enhance security and streamline the process:
- Create policies that automatically initiate a wipe for devices that fall out of compliance or are marked as lost or stolen.
- Implement triggers for force Intune wipe actions when specific risk conditions are met, such as failing a compliance check or attempting to access sensitive data from a non-compliant device.
- Use Microsoft Defender and Azure Active Directory Conditional Access to create dynamic policies that help detect compromised devices and enforce security protocols, including device wipes.
Wipe Policies for Decommissioned Devices
Ensure that devices leaving the organization are wiped as part of the decommissioning process. This is especially important in regulated industries where data security is mandated by compliance standards such as HIPAA for healthcare or GDPR in Europe:
- Regularly audit device inventory and ensure that any decommissioned devices are either wiped or reset.
- For devices returned by departing employees, enforce a full Intune wipe before redeploying them to other users.
Routine Audits and Policy Updates
Regularly audit your device management policies to ensure that your Intune wipe practices are aligned with your organization’s security needs:
- Perform periodic checks to ensure devices are properly enrolled and compliant.
- Update wipe policies to reflect changes in your workforce, such as remote work trends or new regulatory requirements.
- Conduct routine wipe tests on non-critical devices to confirm that your force Intune wipe processes work as expected.
Security and Compliance Considerations
Leveraging Intune remote wipe ensures that your devices are secure, even in the event of theft, loss, or employee turnover. Here’s how using force Intune wipe capabilities helps meet security and compliance requirements:
Enhancing Security Posture
A comprehensive remote wipe strategy helps reduce the risk of sensitive data exposure. Whether dealing with a compromised device or implementing a proactive security measure, force Intune wipe ensures that data is erased before it can be accessed by unauthorized users. Integrating these wipes with security monitoring tools like Microsoft Defender helps create a seamless security workflow, identifying threats and neutralizing potential data breaches before they happen.
Additionally, when combined with Azure Active Directory Conditional Access, you can define rules that automatically initiate a device wipe based on non-compliance or risky behavior. This approach strengthens your organization’s defense against cyberattacks by taking action in real time.
Meeting Compliance Requirements
In many industries, especially those with strict data protection regulations like healthcare (HIPAA) or finance (PCI DSS), device management policies must include provisions for data removal. A well-documented Intune remote wipe policy helps meet these regulatory demands by ensuring that:
- Devices that are no longer in use or have left the organization are securely wiped.
- Sensitive data stored on mobile or remote devices can be erased quickly in case of compromise, theft, or unauthorized access.
- BYOD policies that permit personal device use for work purposes are aligned with privacy laws, ensuring that only corporate data is wiped and personal data remains intact.
By enforcing remote wipes, organizations can avoid fines or penalties associated with non-compliance and demonstrate their commitment to data security.
Integration with Microsoft Compliance Tools
Microsoft Intune integrates seamlessly with compliance tools such as Microsoft Purview and Microsoft Defender for Endpoint, providing organizations with a robust security and compliance framework. These tools work together to ensure data protection and regulatory compliance, allowing for a complete lifecycle of device management, including wiping devices when necessary. Enforcing Intune remote wipe policies in this ecosystem ensures compliance is maintained across the board.
Wondering if Levacloud can solve your Microsoft Cybersecurity related challenge? Drop us a message!
Conclusion
Implementing a remote wipe strategy with Microsoft Intune is essential for securing devices and protecting sensitive data. Whether it’s a force Intune wipe to fully reset a lost or compromised device or a selective wipe for BYOD devices, having the ability to remotely control what happens to your organization’s data is a critical aspect of your overall security posture.
An effective Intune remote wipe strategy not only secures your devices but also helps you meet compliance obligations, reduce risks, and maintain operational efficiency. If you’re already using Intune and need assistance with optimizing device management, or you want to strengthen your IT team’s capabilities, Levacloud is here to help.
We offer specialized support services and engagements with hands-on training for your IT Team that are tailored to your organization’s needs. Our experts work closely with IT teams to ensure you’re fully utilizing Intune’s features to enhance security and compliance. If you need support or want to elevate your team’s expertise, reach out to Levacloud.
New Multi-Admin Approval Feature (May 2025 Update)
As of May 2025, Microsoft Intune has introduced multi-admin approval for high-impact remote actions like Force Wipe, Remote Lock, and Retire. This feature is designed to add a governance layer that helps reduce the risk of accidental or unauthorized device commands—particularly important in environments with multiple administrators or elevated permissions.
Why This Matters
Previously, a single administrator with the correct permissions could execute remote actions like Force Wipe immediately. While this enabled speed, it also created risk—whether through error (e.g., wiping the wrong device) or insider threats. With multi-admin approval, organizations can now require that two or more authorized users review and approve the action before it’s executed.
This added step increases accountability, provides an audit trail, and aligns with zero trust and least privilege principles. It’s especially valuable in regulated industries or environments with strict change management policies.
How It Works
Administrators can enable and configure this capability in the Microsoft Intune admin center under:
Endpoint security → Administrative approval
Once enabled, selected remote actions will enter a Pending state until they receive the required number of approvals. Each approval request includes device metadata, user details, and a timestamp—ensuring transparency across the approval process. Approvers are notified and can review and approve the request directly within the Intune console.
Best Practice Recommendation
If your organization handles sensitive data or uses shared administrative roles, we strongly recommend enabling multi-admin approval for actions like Force Wipe. This ensures that destructive commands are subject to a second set of eyes and reduces the likelihood of accidental data loss or service interruption.




