Factory reset protection bypassed when additional Google account is added: verify Factory Reset is disabled in Blueprint
Android
If you've noticed that users can factory reset Esper-managed devices after adding a secondary Google account, this is likely caused by your Blueprint configuration. Learn how to verify and correct your Factory Reset settings to prevent unauthorized device resets.
Before you begin
Ensure you have access to the Esper Console with permissions to edit Blueprints. You'll need to identify which groups contain the affected devices.
How to prevent factory reset when additional Google accounts are added
- Open the Esper Console and navigate to Devices & Groups.
- Identify the group or groups containing your affected devices.
- Open the Blueprint applied to the group by selecting Groups → [Your Group Name] → Blueprint → Edit.
- Locate the Device Security or Device Restrictions section.
- Find the Factory Reset setting.
- Change the Factory Reset setting from Allowed to Blocked.
- Save and apply the Blueprint to the group. All devices in that group will receive the updated policy on their next check-in.
- Repeat this process for all other groups using the same Blueprint configuration.
Verify the change took effect
After applying the updated Blueprint:
- Attempt to initiate a factory reset from the device's Settings menu. The option should now be unavailable or return a restriction error.
- Check the device status in Devices & Groups → [Device Name] → Activity / Compliance to confirm the Blueprint was successfully pushed and acknowledged by the device.
Troubleshoot if factory reset is still accessible
Factory Reset remains accessible after the Blueprint update:
- Confirm the Blueprint was successfully pushed to and acknowledged by the device. Check Devices & Groups → [Device Name] → Activity / Compliance.
- If the device is offline, the policy update won't take effect until it reconnects.
You see "Action not allowed" when removing secondary Google accounts:
- Verify that your Blueprint's Account Management policy grants Esper permission to manage user accounts. If account removal is restricted at the Android system level, you may need to wipe and re-provision the device as a full Device Owner.
Factory Reset is confirmed as Blocked in your Blueprint but the issue persists:
- Collect device logs using the following ADB command and Esper Support:
Include the Blueprint JSON export and your device's Esper ID when you submit your request.adb shell logcat -d > dpc_logs.txt
Important notes
When a Blueprint allows factory reset, users who add a secondary Google account can bypass your MDM restrictions because Android's native factory reset protection becomes available. To prevent this, ensure Factory Reset is set to Blocked in all your Blueprints. We recommend auditing all Blueprints in your account, not just the one applied to the immediately affected group.
Still need help?
Contact Esper Support if you continue to experience issues after updating your Blueprint configuration.
Please sign in to leave a comment.
Comments
0 comments