> ## Documentation Index
> Fetch the complete documentation index at: https://docs.iru.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Erase a Device

> Remotely erase a managed device from Iru Endpoint. Wipe all data and settings on Mac, iPhone, iPad, Apple TV, Windows, and Android devices.

<Callout icon="earth-americas" color="#B84A7A" iconType="regular">This guide applies to all device platforms</Callout>

### About Device Erase

You can use the **Erase Device** command on macOS, iOS, iPadOS, tvOS, visionOS, Windows, and Android devices. For Apple devices, this command doesn't require supervision.

### How It Works

The Erase Device command permanently removes all data and settings from a device, returning it to factory defaults. The command is delivered through the platform's MDM framework and executes when the device is online or queued for offline devices.

<Warning>
  A locked Apple device cannot receive an Erase Device MDM command. For more information on locking a device, see our [Lock a Device](/en/endpoint/devices/device-actions/lock-a-device) support article.
</Warning>

## Platform-Specific Erase Information

<Tabs>
  <Tab title="Apple Devices">
    ### Erase Apple Devices

    <Steps>
      <Step title="Navigate to Device Record">
        Navigate to the **Device Record** in the Iru Web App.
      </Step>

      <Step title="Open Device Action Menu">
        Open the **Device Action Menu** (ellipsis).
      </Step>

      <Step title="Select Erase Device">
        Select **Erase Device**.
      </Step>

      <Step title="Configure Erase Options">
        In the confirmation dialog, review the erase details. For iOS and iPadOS 17+ devices, you can select **Return to Service** and provide a valid Wi-Fi profile if desired.
      </Step>

      <Step title="Confirm Erase">
        Type `ERASE` in the confirmation field and click **Erase Device** to send the command.
      </Step>
    </Steps>

    <Note>
      The erase command will remove all data and settings from the device, returning it to factory defaults.
    </Note>

    ### Apple Device Considerations

    * **Supervision not required** - Erase commands work on both supervised and unsupervised devices
    * **Immediate execution** - Commands are sent via MDM and execute when the device is online
    * **Data recovery** - All data will be permanently deleted and cannot be recovered
    * **eSIM preservation** - eSIM-based cellular plans are automatically preserved when using the Iru Web App

    ### Apple Erase Behavior

    #### macOS Erase Behavior

    Depending on the macOS version and hardware support, different erase behaviors will occur:

    ##### Erase All Content and Settings (EACS)

    * **Apple Silicon Macs (macOS 12+)**: Performs EACS
    * **Intel Macs with T2 (macOS 12+)**: Performs EACS
    * **Fallback**: If EACS fails, device reverts to obliteration behavior

    ##### Obliteration Behavior

    * **Apple Silicon Macs (macOS 11 and earlier)**: Obliteration without PIN
    * **Intel Macs with T1/No security chip (macOS 12+)**: Obliteration with 6-digit PIN
    * **Intel Macs with T1/No security chip (macOS 11 and earlier)**: Obliteration with 6-digit PIN

    <Note>
      A 6-digit PIN is automatically generated and available on the device record once the device receives the command. Erase device PINs are not supported on Mac computers with Apple silicon.
    </Note>

    #### iOS and iPadOS Erase Behavior

    * **Erase All Content and Settings**: Device restarts and presents Setup Assistant
    * **Not a full system restore**: Device will not be updated to the latest version
    * **eSIM preservation**: Cellular plans are automatically preserved when using the Iru Web App

    <h4 id="return-to-service-ios-ipados-17">
      Return to Service (iOS/iPadOS 17+)
    </h4>

    When erasing iOS or iPadOS 17+ devices, you can select **Return to Service** which:

    * **Automatic setup**: Device proceeds through Setup Assistant to home screen without user intervention
    * **Auto re-enrollment**: Device automatically re-enrolls into Iru after erasure
    * **Wi-Fi configuration**: Automatically joins Wi-Fi network from selected Library Item
    * **Ethernet support**: Works with tethered Ethernet connections (kiosks) without Wi-Fi profile

    <Warning>
      **Return to Service Considerations:**

      * Activation Lock must be removed before issuing Return to Service command
      * Do not select Library Items with EAP-TLS 802.1X networks with SCEP client identity
      * Return to Service will not work with Automated Device Enrollment that requires authentication
      * Self Service apps will not automatically reinstall when erased from Iru (unlike user-initiated erases)
    </Warning>

    #### tvOS and visionOS Erase Behavior

    * **tvOS**: Initiates a Reset, device reboots and presents Setup Assistant
    * **visionOS**: Initiates Erase All Contents and Settings

    #### EACS Requirements

    * **Bootstrap token required**: EACS will fail if no bootstrap token is escrowed
    * **Recommended method**: Use Iru Web App rather than local Erase Assistant for better results
    * **Auto Advance preparation**: Properly prepares Mac for re-enrollment using Auto Advance

    #### Legacy Firmware Passwords

    <Warning>
      In macOS Monterey, Intel-based Macs with T2 Security Chip will perform EACS when receiving an Erase Device command from Iru. However, if a legacy firmware password is present, the device will completely erase and require macOS reinstallation. To preserve EACS behavior, move the device to a Blueprint without a Recovery Password Library Item before sending the Erase Device command.
    </Warning>

    ### Erase Command Execution

    #### Command Delivery

    * **MDM Channel**: Erase commands are delivered through the platform's MDM framework
    * **Immediate Delivery**: Commands are sent immediately when the device is online
    * **Queue for Offline Devices**: Commands are queued and delivered when the device comes online

    #### Execution Timeline

    <CardGroup cols={2}>
      <Card title="Online Devices" icon="wifi">
        Commands execute within minutes of being sent for devices that are currently online.
      </Card>

      <Card title="Offline Devices" icon="wifi-off">
        Commands are queued and will execute when the device next connects to the internet.
      </Card>
    </CardGroup>
  </Tab>

  <Tab title="Windows">
    ### Erase Windows Devices

    <Steps>
      <Step title="Navigate to Device Record">
        Navigate to the **Device Record** in the Iru Web App.
      </Step>

      <Step title="Open Device Action Menu">
        Open the **Device Action Menu** (ellipsis).
      </Step>

      <Step title="Select Erase Device">
        Select **Erase Device**.
      </Step>

      <Step title="Choose Erase Type">
        In the confirmation dialog, choose an **Erase type**:

        * **Local**: Uses the local recovery image present on the device
        * **Cloud**: Downloads the latest Windows installation files from Microsoft's servers
        * **Protected**: Recommended for lost or stolen devices. Continues retrying the reset until successful
      </Step>

      <Step title="Confirm Erase">
        Type `ERASE` in the confirmation field and click **Erase Device** to send the command.
      </Step>
    </Steps>

    <Note>
      The erase command is queued and will execute the next time the device is connected to the internet.
    </Note>

    ### Windows Erase Behavior

    Windows devices support three different erase types with varying behaviors:

    #### Local Erase

    * Uses the recovery image already present on the device
    * Fastest option but requires valid recovery partition
    * Executes immediately when device is online

    #### Cloud Erase

    * Downloads latest Windows installation files from Microsoft's servers
    * Ensures device is reset to most current version
    * Requires internet connectivity during erase process

    #### Protected Erase

    * Recommended for lost or stolen devices
    * Continues retrying reset operation until successful
    * Provides maximum security for sensitive data
  </Tab>

  <Tab title="Android">
    ### Erase Android Devices

    <Steps>
      <Step title="Navigate to Device Record">
        Navigate to the **Device Record** in the Iru Web App.
      </Step>

      <Step title="Open Device Action Menu">
        Open the **Device Action Menu** (ellipsis).
      </Step>

      <Step title="Select Erase Device">
        Select **Erase Device**.
      </Step>

      <Step title="Configure Erase Options">
        In the confirmation dialog, review the erase details and optionally configure:

        * **Erase external storage**: Erase any connected SD cards or external storage drives
        * **Erase eSIMs**: Erase any installed eSIMs
      </Step>

      <Step title="Confirm Erase">
        Type `ERASE` in the confirmation field and click **Erase Device** to send the command.
      </Step>
    </Steps>

    <Note>
      Android erase commands work through the Android Management API and will factory reset the device.
    </Note>

    ### Android Erase Behavior

    Android erase commands perform a factory reset on the device. All data, applications, and settings are removed, and the device returns to initial setup state.
  </Tab>
</Tabs>

<Warning>
  **Important**: Erasing a device will permanently delete all data and cannot be undone. Ensure you have backed up any important data before proceeding.
</Warning>
