Managing 'Erase All Content and Settings' on iOS Devices

Managing 'Erase All Content and Settings' on iOS Devices

The Erase All Content and Settings feature on Apple devices allows a user to wipe all personal data and restore the hardware to its factory default state. Within the WeGuard ecosystem, administrators typically disable this option to prevent unauthorized wipes, ensuring that devices remain enrolled in Management and protected against data loss.


Why Disable This Feature?

Restricting the ability to factory reset a device provides several key security benefits:

  • Prevent MDM Removal: Ensures the MDM profile remains active and the device stays under organizational control.

  • Data Protection: Reduces the risk of intentional or accidental data loss during employee exits or device transitions.

  • Policy Compliance: Prevents users from bypassing security configurations by resetting the device to an unmanaged state.

  • Asset Recovery: Maintains device recoverability and enrollment, especially for shared corporate hardware or lost devices.


Step-by-Step Configuration

Follow these instructions to disable the reset option via the WeGuard Console:

  1. Access the Console: Log in to your WeGuard Console.

  2. Navigate to Policy Groups: Select Policy Groups from the left-hand sidebar.

  3. Select Target Policy: Locate and click on the specific iOS DEP (Device Enrollment Program) policy you wish to modify.

  4. Open Restrictions: Within the policy configuration, navigate to the RESTRICTIONS tab.

  5. Toggle the Feature: Find the option labeled ‘ENABLE ERASE CONTENT AND SETTINGS’.

  6. Disable & Save: Switch the toggle to OFF, then click SAVE AND CONTINUE at the bottom of the page.


Expected Result

Once the updated policy syncs with the managed iOS device:

  • The Erase All Content and Settings option within the device Settings menu will appear grayed out.

  • Users will be blocked from initiating a factory reset, ensuring the device remains in its managed state.



We hope this article was helpful. For additional support:

  • 📘 Explore our Visual Knowledge Base Series

  • 📞 Call WeGuard Support:

    •  Other Countries: +1 (737) 931-1410 Ext. 102, IND: +919652933199

  • 📧 Email: WeGuard Support Email

💬 Start a live chat with our support team, Support Portal, WeGuard Admin Portal


    • Related Articles

    • Managing Bluetooth Settings via WeGuard Policy

      Controlling Bluetooth connectivity is essential for maintaining both security and operational efficiency. Unrestricted Bluetooth can pose data leakage risks or allow unauthorized peripheral connections. WeGuard enables administrators to enforce ...
    • Security - How to Disable Factory Reset?

      Hello and Welcome to WeGuard Enterprise Visual Knowledge-base Series. In this KB article, We will explain how to Disable/Enable Factory Reset option on WeGuard Enterprise Portal. Note: This option is available ONLY on Kiosk and Work Managed policies. ...
    • Security - Security Settings

      Hello and Welcome to WeGuard Enterprise Visual Knowledge-base Series. In this KB article, We will explain about security settings available on WeGuard Enterprise Portal. Security settings, In this section, you have a wide variety of security setting ...
    • How to Enroll iOS Supervised and Non-Supervised Devices into WeGuard

      WeGuard ensures that admins get a hassle-free experience with iOS Device Enrollments through ABM devices sync enrolling the Supervised and Non-Supervised (BYOD) Supervised devices: A Supervised iOS device is an iPhone or iPad that is placed under a ...
    • Managing Device Password Policies and Enforced Resets on Android Devices

      WeGuard provides administrators with two levels of password management: Restrictions, which define the rules for user-created passwords, and Enforcement, which allows an administrator to push a specific password to all devices in a policy group. This ...