This guide applies to Mac computers, iOS devices, iPadOS devices, tvOS devices, and visionOS devices
About Device Erase
You can use the Erase Device command on macOS, iOS, iPadOS, tvOS, and visionOS devices. This command doesn’t require supervision. For Windows devices, see Erase a Windows Device. For Android devices, see Erase an Android Device.How It Works
The Erase Device command permanently removes all data and settings from a device, returning it to factory defaults. The command is delivered through the MDM framework and executes when the device is online or queued for offline devices.Erase Apple Devices
1
Navigate to Device Record
Navigate to the Device Record in the Iru Web App.
2
Open Device Action Menu
Open the Device Action Menu (ellipsis).
3
Select Erase Device
Select Erase Device.
- macOS
- iOS/iPadOS
- tvOS/visionOS
1
Confirm Erase
Type
ERASE in the confirmation field and click Erase Device to send the command.macOS Erase Behavior
Erase behavior depends on the Mac’s hardware and macOS version. The command either performs Erase All Content and Settings (EACS) or obliteration. If EACS fails, the Mac falls back to obliteration.When obliteration uses a PIN, Iru generates a 6-digit PIN and shows it on the device record after the Mac receives the command. Erase device PINs are not supported on Mac computers with Apple silicon.
EACS Requirements
- Bootstrap token: EACS fails if no bootstrap token is escrowed.
- Iru Web App: Use the Iru Web App rather than the local Erase Assistant.
- Auto Advance: Using the Iru Web App prepares the Mac for re-enrollment with Auto Advance.
Legacy Firmware Passwords
On Intel-based Mac computers with the T2 Security Chip running macOS Monterey, Iru sends Erase All Content and Settings. If a legacy firmware password is still on the Mac, the device completely erases and requires a macOS reinstall instead of EACS.To keep EACS, move the Mac to a Blueprint that does not include a Recovery Password Library Item, then send the Erase Device command.Apple Device Considerations
Supervision not required
Erase commands work on both supervised and unsupervised devices.
Immediate execution
Commands are sent through MDM and execute when the device is online.
Data recovery
All data is permanently deleted and cannot be recovered.
eSIM preservation
eSIM-based cellular plans are automatically preserved when you erase from the Iru Web App.
Erase Command Execution
Erase commands are delivered through the MDM framework.- Online devices: The command runs within minutes of being sent.
- Offline devices: The command is queued until the device next connects to the internet.
Related Articles
Erase a Windows Device
Remotely wipe a Windows device with Local, Cloud, or Protected erase
Erase an Android Device
Factory reset a managed Android device, including optional external storage and eSIM erase
Lock a Device
Remotely lock a managed device and optionally display a message on the lock screen
Enable Lost Mode
Activate Lost Mode on managed iOS and iPadOS devices to lock the device and track its location
Deleting a Device Record and Uninstalling Iru Endpoint
Delete device records and uninstall Iru Endpoint when preparing devices for reassignment or removal
Self Service for iOS, iPadOS, and visionOS
Configure Return to Service and other Self Service options for iOS, iPadOS, and visionOS