Retire devices and offboard employees
When a phone reaches the end of its life, or an employee leaves, NounDesk gives you three separate tools. This page explains what each one does and the safe order to use them.
Who: Erase device and retiring need Owner or Admin. Deactivating an employee needs Owner, Admin or Operator, but only Owners and Admins can choose to erase their devices.
Erase, retire and deactivate compared
| Action | What it does | Company data on the device | Can be undone? |
|---|---|---|---|
| Erase device | Factory resets the device and removes it from management. | Removed | No |
| Retire device | Takes an erased (or never-enrolled) device off your active list. Its history stays in the audit log. | Already gone | No |
| Deactivate employee | Removes a person from the active employee list. You choose what happens to their devices. | Only removed if you choose Erase devices | Yes: Reactivate brings the employee back |
Retiring doesn’t erase anything. NounDesk only lets you retire a device that’s already Erased, or that never finished enrolling (Waiting for device). Otherwise you’ll see “Erase the device before retiring it so company data is removed.”
Erase a device
- Open the device and select Erase device.
- Read the warning: “This permanently removes all data from device.” and “This cannot be undone.”
- Type
ERASEin capital letters under Type ERASE to continue. The button stays disabled until you do. - Leave Keep factory reset protection (recommended) ticked (see below).
- Select Erase device.
The device shows Erasing… until it confirms, then Erased. The device must be online to receive the erase within 10 minutes; if it doesn’t, the action Expired, nothing is erased and the device goes back to Active. See Command statuses.
Factory reset protection
With Keep factory reset protection (recommended) ticked, after the erase one of the factory reset protection accounts in the device’s policy must sign in to set the phone up again. This stops a thief from simply setting up an erased phone. It has no effect if the device’s policy lists no accounts. Untick it only when you’re handing the phone to someone outside the company, such as a buyer or recycler. See Factory reset protection.
Retire a device
- Open a device that’s Erased or Waiting for device.
- Select Retire device.
- Confirm with Retire device.
“The device is removed from your active list and no longer counts toward your plan. Its history stays in the audit log.” Retired is the last stage: a retired device can’t come back. To use the same phone again, enroll it as a new device. See Add devices.
Retire many devices at once
- In Devices, tick the devices.
- Select Retire in the bar that appears.
- Type the number of selected devices under Type N to confirm, then select Retire.
Only devices that were erased, or that never finished enrolling, are retired. Any other device in the selection is reported as skipped. There’s no bulk erase, on purpose.
The device lifecycle at the end
Active (or Lost mode) → Erasing… → Erased → Retired
A device can also go straight from Waiting for device to Retired, for example if you cancel an unused code. If Google stops listing a device, for example because it was removed from management outside NounDesk, NounDesk shows it as Erased. See Device status.
Offboard an employee
- Go to Employees and open the person.
- Under Deactivate employee, select Deactivate employee….
- Under Their devices, choose one option:
| Option | What happens |
|---|---|
| Keep devices managed but unassigned | Devices stay enrolled with their current security policy and show as unassigned until you give them to someone else. |
| Reassign devices to another employee | Devices keep their policy and group and move to the person you pick under Reassign to. |
| Retire eligible devices | Only devices that are already erased or never finished enrolling can be retired. Others are left managed and unassigned. |
| Erase devices | Factory-resets every managed device this employee has and removes company data. This cannot be undone. |
- Check the summary. It lists each device and what will happen to it, for example “2 devices will be erased.” Devices that can’t be handled the way you chose are skipped and left unassigned, with the reason.
- For Erase devices, type
ERASEunder Type ERASE to confirm. - Select Deactivate (or Erase devices and deactivate).
NounDesk shows Employee deactivated with the result for each device.
- Erase devices is greyed out for Operators: “Only owners and admins can erase devices.” Retiring devices also needs an Owner or Admin.
- Erasing from here always keeps factory reset protection on.
- Deactivating doesn’t delete the employee. Select Reactivate on their page to bring them back. Their devices aren’t reassigned automatically.
A safe order when someone leaves
- Get the device back if you can.
- Deactivate the employee and choose Keep devices managed but unassigned or Reassign devices to another employee if the phone will be reused, or Erase devices if it won’t come back.
- When an erased phone is ready to leave the company, retire it.