Recovering a device stuck in 'Policy Application In Progress'
After provisioning, occasionally a device gets stuck in a Policy Application In Progress state and never transitions to a stable managed state. When this happens, several console actions become unavailable for that device — including Rename Device, Change Blueprint, and factory reset via the console.
This article explains how to recover the device locally when cloud-side options are blocked.
Why this happens
The Esper agent records the device as mid-convergence — policy application was started during enrollment but never completed or confirmed. This can be caused by a network interruption during provisioning, an incomplete enrollment handshake, or a timing issue during initial DPC initialization.
Because the console treats the device as actively converging, it prevents reconfiguration actions that could conflict with a convergence in progress. The device is effectively in a permanent intermediate state with no cloud path to break out of it.
What you'll need
- Physical access to the device
- The Esper Settings Admin Mode PIN (if one has been set)
Recovery steps
Step 1: Open Esper Settings via the hidden dock
Use one of these two gestures on the device screen:
- Tap gesture: Tap the top-right corner of the screen (just below the status bar) 3 to 6 times in quick succession until the Esper Settings panel appears.
- Power button sequence: Press the power button 3 to 7 times with approximately 0.75 seconds between each press.
Step 2: Factory reset from Esper Settings
Once the Esper Settings panel opens, navigate to the Factory Reset option and confirm the reset. The device will wipe and reboot.
Step 3: Re-provision the device
After the device reboots, re-enroll it from scratch using your standard provisioning method (QR code, Zero Touch, KME, or ABM). Make sure to assign the device to the correct group and Blueprint before or during provisioning.
Verify: After re-enrollment, confirm the device appears in the console with an Active or Enrolled status and that Blueprint convergence completes without errors.
Tips to avoid this during provisioning
- Provision devices on a reliable network connection. Weak or intermittent Wi-Fi is the most common cause of incomplete initial convergence.
- Do not lock or put the device to sleep during the initial provisioning sequence — some devices suspend the DPC initialization if the screen turns off too early.
- If you're provisioning at scale, consider doing a small test batch on a new network or site before deploying the full fleet to catch any environment-specific issues early.
If the hidden dock gestures don't open Esper Settings on a specific device model, submit a support ticket with the device model and Android version — we can provide model-specific instructions.
Please sign in to leave a comment.
Comments
0 comments