The Nightmare of a Lost Device
When an employee loses their company-issued Android phone (or has it stolen while traveling), the immediate concern is not the hardware—it is the data. If the phone contains an active Google Workspace account, the thief potentially has full access to corporate emails, sensitive Google Drive documents, and internal chat logs.
To mitigate this massive security risk, Google Workspace includes robust Mobile Device Management (MDM) capabilities. If a device goes missing, a Super Administrator can log into the Admin Console and trigger a remote wipe command. The next time the phone connects to a cellular tower or Wi-Fi network, it will instantly factory reset itself, destroying all corporate data.
Step 1: Locate the Device
- Log into the Google Workspace Admin Console (admin.google.com) using your administrator credentials.
- In the left-hand navigation menu, click on Devices > Mobile & endpoints > Devices.
- You will be presented with a list of every single mobile device (Android, iOS, ChromeOS) currently synchronized with your organization.
Step 2: Identify the Stolen Phone
If your organization has thousands of devices, finding the correct one can be difficult.
- Click the Add a filter button at the top of the device list.
- Select User email and type in the email address of the employee whose phone was stolen.
- Review the filtered list. Look at the Model (e.g., Pixel 7, Samsung Galaxy S23) and the Last Sync Date to ensure you are selecting the correct phone, not their old backup device.
Step 3: Execute the Remote Wipe
Google Workspace offers two different types of wipes. You must choose carefully based on how the device is enrolled.
- Click on the name of the stolen device to open its detail page.
- In the top right corner, you will see a Wipe Device button. Click it.
- A critical warning prompt will appear, offering you two choices:
- Wipe Device (Account Wipe): This is the most common option. It securely deletes the Google Workspace account from the phone, removing all corporate emails and Drive files, but it leaves the employee’s personal photos and apps intact. This is the correct choice for BYOD (Bring Your Own Device) scenarios.
- Wipe Device (Device Wipe): This is the nuclear option. It triggers a complete factory reset of the hardware. The phone will reboot and wipe its entire internal storage, including the OS partition, returning to the state it was in when it left the factory. This should only be used for company-owned assets.
- Select the appropriate wipe method and click Wipe to confirm.
The Aftermath
The command is immediately queued on Google’s servers. If the stolen phone is currently powered on and has an internet connection, the wipe command will execute within seconds. The screen will go black, and the data will be destroyed.
If the thief has powered the phone off or removed the SIM card, the wipe command remains pending in the Google Cloud. The absolute instant that phone is turned back on and connects to any Wi-Fi network, the command will execute.