Skip to content
Avanet

Prepare and verify Android Factory Reset Protection in Sophos Mobile

Before a reset: For an Android Enterprise fully managed device, first verify ownership and management mode, a Google recovery account accessible to the organisation and its credentials, the account’s correct internal Google ID, and synchronisation of the target device. An FRP entry saved in the console does not prove that the device has applied the setting. If access is unavailable or the reset method is unclear, do not reset: a device with Factory Reset Protection (FRP) enabled could otherwise remain unusable during setup.

This procedure applies only to fully managed Android Enterprise devices. A personal device with a work profile is outside this procedure. FRP protects against unauthorised use after certain factory resets; it does not apply universally to every reset and is not a way to unlock a device that is already locked. Wipe and deleting a device from Sophos Mobile are separate actions.

Secure recovery before configuring FRP

  1. Check the device identity and ownership authorisation against your inventory. Clarify the management mode, responsible tenant, authorisation for the Sophos Mobile action and intended reset method. Safeguard any device data needed before a planned factory reset and establish how the device will be set up afterwards; a reset is not a reversible setting.
  2. Choose one or more organisation-managed Google accounts for FRP. Make their credentials available to authorised people under controlled conditions and verify sign-in beforehand using each intended account. Credentials and internal IDs do not belong in screenshots, tickets or a public article.
  3. Determine the internal Google ID for each account, not its email address or password: Sign in to Google with that exact account (sign out of another account first if necessary). On the Google People API page for people.get, open Try it! (called Try this API in the Sophos instructions), set resourceName to people/me and personFields to names, then run the request. Extract the 21-digit number after people/ from the response field resourceName and associate it internally with the signed-in account. Do not use another account’s ID or a guessed ID. If the request fails or the association remains unclear, stop here.
  4. In Sophos Fusion, first open My Products > Mobile. In the side menu, select Setup > Google setup, then open the Android Enterprise tab. Under Factory Reset Protection, enable Use FRP, enter the verified internal IDs in Google+ IDs and select Save. According to the product documentation, the setting applies to Android Enterprise fully managed devices at their next synchronisation—not necessarily as soon as it is saved.
  5. On the intended pilot device, check the displayed FRP status under Devices > [device] > Show device > Status after confirming synchronisation. Do not approve fleet-wide resets without verifiable device synchronisation and an authorised test of the subsequent setup. The status display alone proves neither that the setting has taken effect on the device nor that sign-in will work after a reset.

Caution: An invalid internal ID or lost Google credentials could leave a device unusable after a reset with FRP enabled. Before taking a destructive action, also have the actual planned reset method for this device and the accessible recovery account approved.

Which reset enables FRP?

According to Sophos, the following distinctions apply only if FRP is configured for the fully managed device. They are not instructions for triggering a reset through Recovery or ADB:

  • Sophos Mobile Admin: Wipe: FRP is enabled for the configured device if Turn on Factory Reset Protection is selected in the confirmation dialogue. Do not guess the default settings instead of checking the dialogue and device selection. A queued Wipe task does not prove that a physical reset has completed.
  • Automatic reset after too many incorrect device passwords, Android Recovery Mode, Android Debug Bridge (ADB), or other methods that do not require user credentials before the reset: FRP is enabled on a configured device. Do not use these methods as recovery shortcuts.
  • Settings > Erase all data (factory reset): According to Sophos, this user-initiated method does not enable FRP. This does not mean a lost device can safely be erased this way, nor does it establish what happens on all Android versions and devices from all manufacturers without practical testing.
  • Delete a device from Sophos Mobile: The separate device-deletion documentation describes an automatic factory reset for Android Enterprise fully managed devices. However, the three FRP sources specify no FRP outcome for this deletion method. Do not equate deletion with Wipe and its FRP checkbox; authorisation and verification belong in the separate offboarding procedure.

Change FRP on an individual device

After global configuration, FRP is enabled by default for fully managed devices according to Sophos. An exception to make setup easier should be considered only for a device confirmed to be neither lost nor stolen. First verify the target device and authorisation; disabling FRP for a missing device undermines the intended protection.

Under Devices, select the target device, go to Show device > Actions > Set Factory Reset Protection, and deliberately choose Turn on FRP or Turn off FRP. After confirming device synchronisation, check the display under Show device > Status. For a temporary exception, verify that FRP has been re-enabled and check its status once the authorised setup is complete. A pending action or the status display alone does not guarantee that the change has taken effect on the device.

Already blocked by FRP after a reset? Do not reset any more devices. First check who is responsible and verify the device identity, the association of the stored ID with a Google account configured for FRP, and the authorisation and valid credentials. During setup on the affected device, attempt to sign in with the valid credentials of one of the Google accounts configured for FRP. Do not promise that any personal account previously signed in will suffice. If the configured account is unknown, credentials are unavailable or sign-in fails, stop here and escalate through approved account recovery or Sophos or device support. Neither a subsequent Turn off FRP action nor ADB or undocumented bypasses are established recovery methods; successful unlocking on this device cannot be confirmed without an authorised device test.