Intelligent Mobile Device Wipes With Administrative Grace Period
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing mobile device management systems unintentionally wipe devices due to compliance policy triggers, leading to revenue and productivity loss, especially when devices fail to check-in with management services due to software incompatibilities or other issues.
Innovation Solution
Implement a system that evaluates device conditions to determine whether to initiate a remote wipe, providing a time delay for administrative approval or remedial actions, such as locking devices, and allowing user appeals to prevent unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If compliance policies automatically wipe devices that fail to check-in within the specified time window, then security compliance is improved, but unintended device wipes occur leading to productivity loss
Solution Approach 1:
The system performs preliminary actions before the automatic wipe by notifying the user and providing a grace period. During this time, the user can remediate the compliance issue (e.g., update software, enable required features) to prevent the wipe from occurring, thus maintaining productivity while still ensuring security compliance.
Solution Approach 2:
The system implements feedback mechanisms by notifying users of compliance failures and providing information about what actions are needed to achieve compliance. This feedback loop allows users to understand the security requirement and take corrective action, preventing unintended wipes of compliant devices.
2Productivity
If the system provides a grace period for user remediation, then unintended wipes are reduced, but the response time for security enforcement is delayed
Solution Approach 1:
The grace period serves as a preliminary action that allows users to remediate compliance issues before the actual wipe occurs. This preliminary intervention prevents unintended wipes of devices that are merely temporarily non-compliant, thereby maintaining productivity while still enabling timely security enforcement for truly compromised devices.
3Productivity
If the system notifies users and allows remedial actions, then device wipes are prevented, but the complexity of the management system increases
Solution Approach 1:
The system enables self-service by allowing users to automatically receive notifications and independently perform remedial actions on their devices without requiring manual intervention from IT administrators. This self-service approach reduces the operational complexity of the MDM system while maintaining productivity by preventing unintended wipes.
Data Source
AI summary
Disclosed are various embodiments for determining whether to initiate a remote device wipe in a mobile device management context. In one example, a system comprises a computing device configured to identify a device wipe condition for a client device and determine a wipe policy associated with the device wipe condition. A time for a time delay is initiated for a device wipe action of the client device. A wipe instruction is transmitted to execute the device wipe action based on an expiration of the time delay for the device wipe action.


