Every hardware refresh ends the same way: a store cupboard filling with kit that nobody has time to deal with. Somewhere in that pile are MDM locked devices — laptops, iPhones and Android handsets that have been wiped, look ready to go, and still belong to your organisation in software terms. A refurbisher powers one on and it stops at a prompt asking for credentials that walked out of the building with whoever set it up. This is the most common reason a fleet that should have paid for part of its own replacement ends up recycled for scrap value instead.
Key facts: what device locks do to retired IT
- A wipe is not an unlock. Erasing a device removes the data, not the enrolment record that ties the hardware to your tenant.
- Only your IT team can clear it, in your own management console, while that console is still live.
- Apple, Microsoft and Google all document the release steps — and all three have an order that cannot be reversed once you get it wrong.
- A locked device has no resale market. It goes to recycling, and any rebate goes with it.
- The fix costs nothing. It is a checklist run before collection rather than a rescue attempt afterwards.
What are MDM locked devices?
MDM locked devices are units still registered to an organisation's mobile device management or deployment service. After a factory reset the device checks in, recognises the enrolment record and demands the original administrator credentials. The data is gone; the ownership claim is not. Until that record is removed at the console, the hardware cannot be resold or redeployed by anyone.
Three systems account for nearly all of it in a typical UK business: Apple Activation Lock paired with Apple Business Manager, Microsoft Intune with Windows Autopilot, and Android Enterprise factory reset protection. They behave differently from one another, which is why a single "wipe everything" instruction to the service desk does not clear the problem. Each has its own console, its own record and its own release procedure.
Why does a locked laptop lose its resale value?
Because nobody can use it. A refurbisher buys working hardware to resell, and a machine that stops at an enrolment prompt is worth only its components. Apple states the position plainly in its deployment documentation: when Activation Lock is on, "it's difficult for someone else to use or sell" the device.
That is the entire point of the feature, and it works. The awkward part is that it does not distinguish between a thief and your own disposal partner. The gap matters most on exactly the kit that is worth something: three-year-old business laptops, MacBooks and recent iPhones all carry real residual value, which is the argument for IT equipment buyback rather than straight recycling. Locked, they drop out of the resale channel entirely. The organisations hitting this hardest at the moment are those working through the Windows 10 support decision, because that refresh moves whole fleets in one go.
How do you clear Apple Activation Lock before disposal?
In the right order, and before the device leaves Apple Business Manager. Apple's deployment guide separates organisation-linked Activation Lock, which your device management service can control directly, from user-linked Activation Lock, which depends on a personal Apple Account belonging to the employee.
Apple is explicit about what makes the organisation-linked version clearable: the bypass codes held by the device management service are "crucial to your ability to clear Activation Lock", as its own documentation puts it. Two codes are involved, one generated by the device and one created by the server when the lock was switched on. If the MDM platform was decommissioned before the hardware was, those codes may simply no longer exist anywhere.
The sequencing trap is releasing devices too early. Apple's instruction on releasing devices from Apple Business Manager is that release is a permanent action, that a released device cannot be added back through automated device enrolment, and that managing Activation Lock through Apple Business Manager is not possible once a device has been released. Turn the lock off first. Release second. The other way round leaves the device stranded with nobody able to help.
What has to happen in Intune and Windows Autopilot?
Two deletions, in sequence. Microsoft's Windows Autopilot registration guidance says that "whenever a device permanently leaves an organization, the device should always be deregistered from Windows Autopilot", explicitly including the point at which it reaches the end of its life cycle. The device comes out of Intune first, then out of Autopilot.
Order is not cosmetic here either. Microsoft warns that "skipping steps or removing records out of order can result in orphaned records or unrecoverable devices", and that deregistering through a partner portal on its own neither unenrols the device from Intune nor disjoins it from Microsoft Entra ID. A practical detail from the same page: note the serial number while you are still in Intune, because that is how you find the device in the Autopilot list afterwards.
What about Android factory reset protection?
Android forces the decision before the reset rather than after it. Google's documentation for company-owned devices is direct: disabling factory reset protection, or enabling the enterprise version of it, must be done prior to the device being factory reset. Once a protected handset has been wiped, that window has closed.
Enterprise factory reset protection is the sensible setting for fleets still in service, because it names the accounts allowed to reactivate a wiped device — a lost handset stays useless to a stranger while your own team can still recover it. At disposal, though, that protection has to come off deliberately. It is worth auditing which of your Android estate is enrolled as company-owned before the collection is booked, because personally enrolled devices behave differently again.
Which devices are worth unlocking?
All of the ones that still work. The unlock takes minutes per device in a console you are already paying for, and it is the difference between a rebate and a disposal cost. The table below is the short version of what has to happen on each platform before anything leaves your building.
| Platform | Where the lock lives | What has to happen before collection |
|---|---|---|
| Apple: Mac, iPhone, iPad | Activation Lock, managed through Apple Business Manager and your MDM | Clear Activation Lock using the stored bypass codes, then release the device from Apple Business Manager |
| Windows laptops and desktops | Intune enrolment plus a Windows Autopilot registration bound to your tenant | Delete from Intune first, then deregister from Autopilot; note the serial number before you start |
| Android handsets and tablets | Factory reset protection on company-owned devices | Disable factory reset protection, or set the enterprise version, before the device is wiped |
| Any platform, tenant already gone | An orphaned enrolment record with no live console behind it | Flag it as unlockable, keep it in the data-bearing pile and route it to destruction |
What should you do when the credentials have already gone?
Sort the pile before you book anything. Split the kit three ways: devices you can still unlock in a live console, devices whose management tenant no longer exists, and devices nobody has been able to identify at all. The first group is resale stock. The second and third are a destruction and recycling job, and they should be treated as such.
- Check the console before the cupboard, and pull the enrolment list while the tenant is still paid for
- Unlock in place first, release second, never the other way round
- Keep leaver devices out of general storage until the enrolment record has been cleared
- Write down which devices could not be unlocked, and tell your disposal partner before collection day
- Treat every locked device as data-bearing until it has been verifiably erased or destroyed
That last point is the one that catches people out. A locked device is not a wiped device. Plenty of the units sitting in a leaver drawer were never reset at all, because whoever collected them could not get past the login screen either. Assume the data is still there until someone proves otherwise.
How does Innovent handle locked and unidentified kit?
We do not turn it away. Devices that cannot be unlocked are treated as data-bearing and routed to destruction rather than resale: drives are erased to a verified, NIST SP 800-88 Rev 2 compliant standard where the hardware still allows it, and destroyed by video-recorded shredding at our facility where it does not. Destruction at our facility is free, and so is collection.
Where destruction has to happen at your own premises before anything moves, that is done by crushing, on site, and it is a chargeable service. Everything on a collection is counted, and every data-bearing device is labelled with the job number so the paperwork matches the hardware. The full process is set out on our secure data destruction page.
Where does unlocking fit in the wider decommissioning process?
It is one control inside a chain of custody, not a replacement for one. The enrolment record proves who owned a device; the collection paperwork proves who holds it now. Both need to survive the handover, which is why the unlock status is worth establishing before a disposal partner quotes rather than on the day.
For the wider picture, our guide to ITAD chain of custody covers what to demand from a disposal partner, and the comparison of selling old company laptops to staff against business buyback looks at the route most likely to leave devices locked and untraceable a year later. Innovent has run more than 10,000 business collections since 2015, from single offices to multi-site refreshes, including regular computer recycling in Manchester and across the North West.
Book a Free Collection Call 0151 355 5482
What else do IT teams ask about locked devices?
The questions below come up on almost every fleet decommissioning, usually once the kit is already stacked up and the answers have become expensive. The short version is that the unlock is always your action to take, in your own tenant, and it is always easier before the hardware moves than after.
Does wiping a device remove the MDM lock?
No. A wipe removes the data. The enrolment record sits with your management service rather than on the device, so a factory-reset unit will still check in and ask for administrator credentials. The record has to be deleted in the console by an administrator.
Can a disposal company unlock our devices for us?
No, and be wary of anyone who says they can. The unlock is an action inside your own tenant, performed by your administrators. A disposal partner's job is to identify which units are locked, tell you before collection, and handle them correctly if they cannot be cleared.
Is Activation Lock the same thing as an MDM lock?
They are related but separate. MDM enrolment ties a device to a management platform; Activation Lock is Apple's anti-theft feature layered on top. An Apple device can be caught by either, or both, and each is cleared in a different place.
What happens to a device we genuinely cannot unlock?
It leaves the resale route and joins the destruction route. The drive is erased where that is still possible, destroyed where it is not, and the chassis is recycled. You lose the residual value, but you do not lose control of the data on it.
None of this is difficult. It is simply work that has to happen while the management console is still switched on, which is rarely the same week the hardware is finally cleared out. Building the unlock into your leaver process, rather than your disposal process, is the whole fix.