Android Enterprise Factory Reset Protection

Android Enterprise Factory Reset Protection (EFRP) allows an admin to add a Google account or accounts that can unlock an Android device after a hard reset.

  1. Select the Libraries tab in top navigation.
  2. Select Restriction Sets.
  3. New restrictions only.
    1. Select Android from the Add New dropdown.
    2. Name the new restriction set.
  4. Existing restrictions only.
    1. Select a Restrictions Set Name.
    2. In the right panel, click Edit.
  5. Under Device Functionality, underAllow Enterprise Factory Reset Protection.
    1. Add the desired email address.
    2. Add the Google Account ID for the email. To get a Google account ID, follow these steps
      1. Sign in to a browser with the Google account that is to be used
      2. Go to the Google People API - Method: people.get | People API | Google for Developers
      3. Click on the Try It button on the right.

      4. Keep the default settings and hit Execute

      5. This should then return a 200 response with a JSON and the account identifier in the id field as part of the sources object.

      6. Copy the id value into the Google Account ID field in the restriction set.

  6. Click Save Restriction Set.

After a reset on an Android device where factory reset protection has been enabled, the email account in the restriction set should be able to unlock and enroll the device.