Back to blog
IntunePublished on August 8, 20268 min read

Lost phone: full remote wipe or work-only wipe?

A device is lost or stolen. Wipe everything or just work data? Compare full wipe and selective wipe in Microsoft Intune and pick the right action.

It is 6 p.m. on a Friday and an employee calls you: their phone has been lost on the train, or maybe stolen, they are not sure. On that device sit their work mailbox, Teams files, OneDrive documents and authentication tokens that are still valid. The priority is crystal clear: stop any access to your Microsoft 365 data before someone with bad intentions gets their hands on it. Microsoft Intune offers you two possible responses with very different consequences, and knowing which one to trigger within minutes changes everything.

The wrong instinct is to improvise under pressure, frantically hunting for the right button in a console you rarely touch in an emergency. The right instinct is prepared in calmer times: understanding in advance the difference between a full wipe and a selective wipe, knowing which device calls for which action, and having a written procedure any administrator can follow. That gap in preparation is the difference between a leak avoided and an incident that exposes sensitive information for hours.

It all really comes down to a simple question: who owns the device, and which data must disappear? A company phone enrolled in Intune is not handled the same way as an employee's personal smartphone protected by a simple app protection policy. In this guide, you will see how to choose the right action, run it cleanly, pair it with the essential companion steps, and document everything for your GDPR obligations.

Two responses with opposite consequences

Intune clearly separates two families of actions. A full wipe resets the device to factory state. A selective wipe removes only the work perimeter and leaves the private sphere intact. This is not a second-order technical nuance: it is the choice that decides whether or not you destroy your employee's family photos and personal contacts. Picking the wrong action can turn a legitimate security response into a dispute with an employee, or even a legal problem.

Full wipe: erase the entire device

A full wipe, the 'Wipe' action in Intune, restores the device to its factory settings. All data is gone, work and personal alike, with no distinction. It is a powerful, drastic and irreversible action: once launched and applied, there is no going back. It fits a company-owned device enrolled in full management (MDM) perfectly, but it is entirely unsuitable for a personal phone.

  • Reserved for company-owned devices enrolled in Intune under MDM management.
  • Removes absolutely everything: apps, photos, accounts, personal documents included.
  • Best used when you are certain the device will not come back, or when it holds data too sensitive to take any risk with.
  • On a personal (BYOD) device, erasing private data can raise a genuine legal issue and destroy your teams' trust.
  • Depending on the platform, an option lets you keep enrollment state so a recovered device can be reprovisioned faster.

Selective wipe: remove work data only

A selective wipe removes only work data and leaves personal data perfectly intact. You can achieve it two ways: the 'Retire' action on an enrolled device, which unenrolls it and removes corporate content, or the wipe of company data triggered by the App Protection Policy (MAM) on an unenrolled device. It is the ideal response for BYOD, because it respects privacy while cutting off access to your data.

  • Removes work accounts, email and cached files inside Microsoft 365 apps such as Outlook, Teams and OneDrive.
  • Leaves personal photos, contacts, messages and apps completely untouched.
  • Works via MAM even on a device that was never enrolled in Intune.
  • Can trigger automatically after a set number of days of device inactivity, a valuable safety net for forgotten phones.
  • Ideal when an employee leaves, to regain control of the data without touching their private device.
A selective wipe removes work data without ever touching personal data.

Retire, Wipe, company data wipe: telling the actions apart

Confusing these terms is the leading cause of error in an emergency. 'Wipe' targets the whole device and resets it to factory state. 'Retire' unenrolls the device and removes only company-managed data. The company data wipe, driven by the App Protection Policy, acts inside the applications themselves and never requires the phone to be enrolled.

Which device calls for which action

The rule is easy to remember. A company device you will not recover justifies a full wipe. A personal device always calls for a selective wipe: you have neither the right nor any interest in destroying an employee's private data. When in doubt about who owns the device, the selective wipe is always the safest choice, because it protects your data without exposing your organization to blame.

Step-by-step procedure in Intune

Here is the procedure to follow when a device is reported lost or stolen. Order matters: you first cut access to active sessions, then trigger the wipe suited to the nature of the device.

  1. 1In the Intune admin center, open Devices, then find the device by its name or by the associated user.
  2. 2Check who owns the device and its management mode (MDM-enrolled or MAM-protected) to choose the right action.
  3. 3In Microsoft Entra, immediately revoke the user's active sessions to invalidate all current authentication tokens.
  4. 4Reset the account password if there is any doubt about a possible compromise.
  5. 5For a company device that is permanently lost, select the Wipe action and confirm.
  6. 6For a personal device, select the Retire action, or trigger the company data wipe from the App Protection Policy.
  7. 7Remember that a wipe only applies when the device next connects to the network, so session revocation remains your first immediate line of defense.
  8. 8Record every action taken with a timestamp, so you have a usable trail in case of an audit.

The immediate companion steps

A wipe is an asynchronous action: it only runs when the device reconnects to the internet. If the phone is off, off the network or in airplane mode, the command stays pending. That is why cutting access to tokens and sessions must never be skipped: it is what truly protects your data during the window when the wipe has not yet happened.

  • Revoke active sessions in Entra ID to instantly invalidate current access and refresh tokens.
  • Reset the affected account's password, which forces a fresh authentication everywhere.
  • Confirm compliance and MAM policies were in place beforehand: without them, a selective wipe has nothing to remove.
  • Tell the user which steps were taken, so they understand what was done on their device and why.

A concrete example

A services SMB discovers on Monday morning that a salesperson lost her personal iPhone over the weekend. The device is not enrolled in Intune, but it is covered by an App Protection Policy applied to Outlook and Teams. The administrator first revokes the salesperson's active sessions in Entra ID, resets her password, then triggers the company data wipe from the MAM policy. The result: as soon as the phone reconnects, the cached work email and files are removed from Outlook and Teams, while the employee's photos, contacts and personal apps stay completely intact. No private data destroyed, no work access left open, and a time-stamped record of every step.

The choice of action depends first on who owns the device.

Common mistakes to avoid

Losing a device is a stressful moment, and stress leads to mistakes. Here are the pitfalls we see most often, all of which are avoidable with a little preparation.

  • Triggering a full wipe on a personal phone and destroying an employee's private data, with the dispute that follows.
  • Forgetting to revoke active sessions and believing the incident is handled while tokens stay valid until the wipe actually runs.
  • Having set up no MAM policy or compliance beforehand, so there is nothing to selectively wipe on the day of the incident.
  • Keeping no time-stamped record of the actions, which makes it hard to demonstrate your responsiveness during a GDPR review.
  • Waiting several hours before acting, hoping the device will simply turn up, while every minute widens the exposure window.
The best response to a lost device is not the fastest one, it is the one you prepared before the incident ever happened.

Prepare a lost-device procedure

Calm in an emergency is not improvised: it is documented. A written procedure, known to all your administrators, turns a moment of panic into a series of controlled, repeatable steps. GDPR also expects you to demonstrate the ability to react quickly to a loss or theft that could expose personal data.

  • Document precisely who is authorized to trigger the wipe and by what decision criteria.
  • Clearly separate, in your inventory, company devices (full wipe) from personal devices (selective wipe).
  • Make session revocation and a password reset systematic steps, run in parallel with the wipe.
  • Keep a time-stamped record of each action for your compliance obligations and any notifications.
  • Test the procedure once a year on a demo device, so the action is known before it is needed.
A written procedure turns panic into controlled steps.

How AuPoint helps you react fast

In the middle of an emergency, hunting for the right action in the Intune console, hesitating between Retire and Wipe, or wondering whether the MAM policy was even active, wastes precious time. AuPoint is the SaaS that makes Microsoft Intune and Conditional Access security and compliance easy: it clarifies each option in plain language, guides you to the right move based on the nature of the device, and keeps your MAM and compliance policies ready in advance. You gain peace of mind, with no PowerShell and no provider, and you automatically document each action for your GDPR obligations.

FAQ

Does the wipe work if the phone is off or off the network?

No, not immediately. The wipe command is queued and only runs the next time the device connects to the internet. That is precisely why revoking sessions in Entra ID and resetting the password are your first protections: they cut access to the data without depending on the state of the phone.

Can I cancel a wipe once it is launched?

A full wipe is irreversible once it applies: there is no going back. As long as the device has not reconnected, you can usually cancel the pending command from Intune. If the device is eventually found and was never wiped, you can simply remove the command from the queue.

Do I need to enroll the device to wipe work data?

No. That is the whole point of MAM: the company data wipe applies inside the Microsoft 365 apps even on a device that was never enrolled. All it takes is an App Protection Policy assigned to the user beforehand. This is the ideal solution for BYOD, where full enrollment is neither desirable nor accepted.

A lost device must never become an open door into your Microsoft 365 data. With AuPoint, you prepare your app protection and compliance policies in calmer times, you know exactly which action to trigger when the day comes, and you document every step for your GDPR compliance, with no PowerShell and no consultant. Discover AuPoint and turn a lost phone into a simple, controlled incident.

Secure your tenant in 15 minutes

Free trial