Factory Reset Bypass via Recovery Mode and *777# Code: OEM-Level Controls Required — Esper Cannot Block at Platform Level
Android
If end users on your Esper-managed Android devices can bypass Google Factory Reset Protection (FRP) and device lock controls using Recovery Mode or dialer codes like *777#, you need to understand why Esper cannot block these methods at the platform level, and what steps you can take.
Understand why Esper cannot block these bypass methods
Esper's Esper Agent (Esper Agent) agent runs within Android after the device boots. It cannot intercept or block actions taken in Recovery Mode, because Recovery Mode runs outside of Android entirely—the Esper Agent is not active at that stage.
Similarly, OEM-specific dialer codes that trigger a hardware or firmware-level reset (such as *777#) are not exposed to or controllable by any MDM platform, including Esper. These reset mechanisms are hardware and firmware-level features that exist below the Android OS layer where Esper operates.
FRP is Google's protection mechanism, and its enforcement depends on the OEM correctly implementing Android requirements. If your OEM's Recovery Mode exposes an unguarded factory reset option, or if a dialer code bypasses FRP checks, this is a gap at the OEM firmware level—not something Esper configuration or policy can address.
Identify which bypass method your devices are experiencing
Confirm which of the following bypass vectors are affecting your fleet:
- Recovery Mode factory reset (accessed via hardware key combination at boot)
- Dialer code reset (such as
*777#or similar OEM-specific code) - Both methods
Contact your device OEM
Engage your device OEM directly with these specific requests:
- For Recovery Mode bypass: Request that the OEM remove or password-protect the Factory Reset option within Recovery Mode at the firmware level.
- For dialer code bypass: Request that the OEM disable or restrict this dialer code, or ensure it enforces FRP re-authentication after reset.
Ask your OEM whether a separate enterprise or kiosk firmware variant is available for your device model. Many OEMs do remove the factory reset option from Recovery Mode by default on enterprise firmware.
Involve Esper Support in OEM coordination
If you need cross-party coordination between your OEM and Esper, loop Esper Support into your ticket. Esper can work directly with your OEM's technical team once they are included in the ticket thread.
Verify the fix
After your OEM applies firmware changes, confirm the fix by testing on an enrolled device:
- Attempt a Recovery Mode factory reset using the hardware key combination.
- Attempt the dialer code reset (if applicable).
- Verify that the bypass options are either absent, require authentication, or trigger FRP lock on re-setup.
If your OEM cannot or will not make changes
If your OEM is unresponsive or unwilling to make firmware changes, the only available mitigations are physical or operational controls:
- Use device enclosures that prevent reboot key combinations.
- Remove SIM or dialer access where applicable.
If you are using a different OEM device model and it exhibits similar behavior, contact Esper Support with the specific device model, Android version, and firmware build number so Esper can assess whether any MDM-level workaround exists for that hardware.
Still need help?
If you have questions about FRP settings, Blueprint policy configuration, or need assistance coordinating with your OEM, submit a support ticket. include your device model, Android version, firmware build number, and which bypass method you are experiencing.
Please sign in to leave a comment.
Comments
0 comments