Skip to main content
This guide applies to Mac computers, iOS devices, iPadOS devices, tvOS devices, and visionOS devices

About Device Erase

You can use the Erase Device command on macOS, iOS, iPadOS, tvOS, and visionOS devices. This command doesn’t require supervision. For Windows devices, see Erase a Windows Device. For Android devices, see Erase an Android Device.

How It Works

The Erase Device command permanently removes all data and settings from a device, returning it to factory defaults. The command is delivered through the MDM framework and executes when the device is online or queued for offline devices.
A locked Apple device cannot receive an Erase Device MDM command. For more information on locking a device, see our Lock a Device support article.

Erase Apple Devices

1

Navigate to Device Record

Navigate to the Device Record in the Iru Web App.
2

Open Device Action Menu

Open the Device Action Menu (ellipsis).
3

Select Erase Device

Select Erase Device.
After you select Erase Device, the confirmation dialog and erase behavior depend on the device.
1

Confirm Erase

Type ERASE in the confirmation field and click Erase Device to send the command.

macOS Erase Behavior

Erase behavior depends on the Mac’s hardware and macOS version. The command either performs Erase All Content and Settings (EACS) or obliteration. If EACS fails, the Mac falls back to obliteration.When obliteration uses a PIN, Iru generates a 6-digit PIN and shows it on the device record after the Mac receives the command. Erase device PINs are not supported on Mac computers with Apple silicon.

EACS Requirements

  • Bootstrap token: EACS fails if no bootstrap token is escrowed.
  • Iru Web App: Use the Iru Web App rather than the local Erase Assistant.
  • Auto Advance: Using the Iru Web App prepares the Mac for re-enrollment with Auto Advance.

Legacy Firmware Passwords

On Intel-based Mac computers with the T2 Security Chip running macOS Monterey, Iru sends Erase All Content and Settings. If a legacy firmware password is still on the Mac, the device completely erases and requires a macOS reinstall instead of EACS.To keep EACS, move the Mac to a Blueprint that does not include a Recovery Password Library Item, then send the Erase Device command.

Apple Device Considerations

Supervision not required

Erase commands work on both supervised and unsupervised devices.

Immediate execution

Commands are sent through MDM and execute when the device is online.

Data recovery

All data is permanently deleted and cannot be recovered.

eSIM preservation

eSIM-based cellular plans are automatically preserved when you erase from the Iru Web App.

Erase Command Execution

Erase commands are delivered through the MDM framework.
  • Online devices: The command runs within minutes of being sent.
  • Offline devices: The command is queued until the device next connects to the internet.
Erasing a device permanently deletes all data and cannot be undone. Back up anything you need to keep before you proceed.

Erase a Windows Device

Remotely wipe a Windows device with Local, Cloud, or Protected erase

Erase an Android Device

Factory reset a managed Android device, including optional external storage and eSIM erase

Lock a Device

Remotely lock a managed device and optionally display a message on the lock screen

Enable Lost Mode

Activate Lost Mode on managed iOS and iPadOS devices to lock the device and track its location

Deleting a Device Record and Uninstalling Iru Endpoint

Delete device records and uninstall Iru Endpoint when preparing devices for reassignment or removal

Self Service for iOS, iPadOS, and visionOS

Configure Return to Service and other Self Service options for iOS, iPadOS, and visionOS