Retire a device
Taking a device out of service for good.
Retiring means the device leaves your fleet: it stops counting in your numbers, stops raising alerts, and holds none of your data.
Step 1 — Make sure nothing is needed from it
Check with the last person who used it. Once you erase it, nothing comes back.
Step 2 — Erase it
While the device still works and is online, send the wipe from its device page. A device you have already switched off and put in a drawer cannot receive the command.
- Organisation-owned → Wipe. Full factory reset.
- Personally owned → Selective wipe. Work data only.
Wait for the command to reach Done on the device's timeline. That is your proof the data is gone.
Step 3 — If the device is broken or will not turn on
You cannot wipe it remotely. Instead:
- Keep it locked away until it is destroyed.
- Use a certified disposal service and keep the certificate — it lists the serial numbers destroyed.
- Note in your records that the device was destroyed rather than wiped.
Step 4 — Remove it from the console
Ask an admin to remove the device record once it is erased. Removing it:
- takes it out of your device counts and reports,
- stops it appearing in alerts as a silent device, and
- leaves the full history in the audit log.
Step 5 — Record it
Keep a line for each retired device: serial number, date, how it was erased or destroyed, and who authorised it. Auditors ask for exactly this, and it takes seconds now versus hours later.
What happens if you skip retirement
Devices left enrolled but dead show up forever as non-compliant and silent. After a few months your alerts screen is full of ghosts, and real problems get lost in the noise.