How to fully implement factory reset protection?

Solved
IS
Ian Stuart
Cross Country Couriers

Hello,

We are trying to ensure our Zebra TC56's can not be factory reset. If I add the SOTI factory reset protection to a device, and then do a reset I can easily get around the prompt by scanning a barcode to skip the google setup. So this seems pretty pointless. Is there any other way to lock this down in SOTI? I've seen some MDM's display a constant pop up and force shut down even after a factory reset. Thanks!

3 years ago
Android
ANSWERS
RS
Rafael Schäfer
3 years ago

You should really be certain if you want to put this in place.

If someone has forgotten his Pin and the device is not in Soti anymore (because deleted), you won't be able to reset it without sending it to repair.

I would recommend you to use Google Zero-Touch (if you use GSM device), then all devices will relocated during enrollment to your MDM (if enrolled online) or factory reset after 1 hour everytime someone has resettet it anywhere.

If you still want to protect, take a look here: https://developer.zebra.com/blog/factory-reset-protection

Not sure if possible but maybe Zebra MX or OEM App could provide that also.

IS
Ian Stuart
3 years ago

Hello Rafael,

Thanks for the response! We are sure we want this in place, as our users do not have pins or lock screens. These are enrolled  as Work Managed Devices we want full control over, and they have a lockdown with kiosks.

The issue is people can walk off with them, factory reset through a hardware key combination and then simply scan a barcode to bypass the Google setup wizard.

I will take a look at Google Zero-Touch, but I have looked at the Zebra page and MX options but none of them prevent a factory reset + barocde scan workaround.

Thank you!

RS
Rafael Schäfer
3 years ago

We use Google Zero-Touch on all our devices, which doesn't prevent from factory reset but it prevent's from using the phone online afterwards (they could only use them in a "always offline" state, which i bet no one wants to). So, in final it's some kind of useless. Also we locate the devices when enrolled into our system. So we know where it's and are able to provide the information to police etc. gotten from the device.

Solution
IS
Ian Stuart
2 years ago

Google Zero Touch is truly the only full lockdown solution here. This is what we have implemented.