Protecting Sensitive Data with Remote Wipe

Josh Patton
Josh Patton
  • Updated

OnBoard Remote Wipe

What is the OnBoard Remote Wipe Feature?

The OnBoard Remote Wipe feature allows Organization Administrators to remove downloaded OnBoard data from a user's mobile and tablet devices remotely. This helps protect sensitive board and organizational information when a device is lost, stolen, retired, or when a user leaves an organization.

When a Remote Wipe is triggered:

  • The user is signed out of the OnBoard application on all mobile and tablet devices.
  • All downloaded and encrypted OnBoard data stored within the OnBoard App is removed from all devices associated with the user.
  • Data from all organizations the user belongs to is removed from all devices.
  • The user can regain access by signing in again with their OnBoard ID and password, provided they still belong to the organization.
NOTE: A Remote Wipe removes locally downloaded OnBoard data from devices. It does not permanently delete the user's account unless the account is separately removed or deactivated.

Remote Wipe for Lost or Stolen Devices

How Do I Remotely Wipe a Lost or Stolen Device?

If a device is lost, stolen, or misplaced, an Organization Administrator can initiate a Remote Wipe to prevent unauthorized access to downloaded OnBoard information.

This action logs the user out of all devices and removes all downloaded OnBoard data from every device associated with their account.

Steps to Initiate a Remote Wipe

  1. Navigate to Directory from the main navigation menu.
    • Locate the user's name.
  2. Hover over the user's name to display the three-dot (⋯) menu.
  3. Select Wipe Devices Remotely.

mceclip0.png

After the wipe is completed:

  • The user will be signed out of all OnBoard sessions.
  • Downloaded OnBoard content will be removed from all devices.
  • Anyone who gains possession of the device will not be able to access OnBoard data without valid login credentials.

Managing Access Removal and Remote Wipes

What Is the Difference Between Deactivating and Deleting a User?

Understanding the difference between deactivating and deleting a user is important because these actions have different effects on OnBoard data stored on mobile devices.
  • Deactivating a user can trigger a Remote Wipe of the user's registered mobile devices.
  • Deleting a user removes their access and profile from a single organization's Directory but does not trigger a Remote Wipe.
  • To ensure downloaded OnBoard data is removed from a user's devices, the recommended process is to deactivate the user first, then delete them from the Directory.
NOTE: Remote Wipe is only available if the feature has been enabled for your organization.

Remote Wipe Through User Deactivation

How Does Deactivating a User Trigger a Remote Wipe?

When a user is deactivated, OnBoard can automatically initiate a Remote Wipe for all mobile devices registered to that user.
The system sends a wipe request to the notification service, which instructs the OnBoard mobile app to remove all downloaded OnBoard data from the user's devices.

What Happens When a User is Deactivated?

When Remote Wipe is enabled for your organization and a user is deactivated:
  • All registered mobile devices associated with that user are marked for Remote Wipe.
  • Downloaded OnBoard documents are deleted.
  • The application's local database is removed.
  • Local application settings are removed.
  • The user is signed out of the OnBoard mobile app.
  • All OnBoard data stored on the affected mobile devices is removed.
NOTE: If Remote Wipe is not enabled for your organization, deactivating a user will not remove any downloaded data from their devices.

Does the Wipe Affect Only One Organization?

No. The Remote Wipe is tied to the user, not to a specific organization.
If the user belongs to multiple organizations in OnBoard:
  • All OnBoard data stored on the affected mobile devices is removed.
  • The wipe cannot be limited to a single organization.
  • Content from every organization available through the OnBoard app on that device is erased.

Does the Wipe Only Work if the Push Notification is Received?

No. The wipe does not depend solely on the push notification being delivered.
The OnBoard app is initially notified through a silent push notification, but the wipe instruction is also stored by OnBoard. If a device does not receive the push notification, it will still perform the wipe the next time it connects and checks in with the server.

Does the Wipe Affect Web Browser Sessions?

No. Remote Wipe only affects the OnBoard mobile application.
The wipe:
  • Removes downloaded mobile app data.
  • Signs the user out of the mobile app.
The wipe does not:
  • End active browser sessions.
  • Automatically sign the user out of OnBoard in a web browser.
Access to the web application is removed only after the user's access has been revoked.

How Do I Deactivate a User?

You can deactivate a user directly from the Directory.

Steps to deactivate a user

  1. Open the Directory.
    1. Locate the user account.
  2. Select the three-dot (⋯) menu next to the user's name.
  3. Click Deactivate Member.
mceclip2.png
  1. Confirm the deactivation if prompted.
mceclip3.png
After the user is deactivated, any configured Remote Wipe actions will be initiated automatically.

Removing a User from the Organization

What Happens When I Delete a User?

Deleting a user removes their access to the organization and removes their profile from the Directory.
However, deleting a user does not send a Remote Wipe request.

What Does Deleting a User Do?

When a user is deleted:
  • Their access to the organization is removed.
  • Their Directory profile is removed.
  • No wipe request is sent to their devices.
  • Previously downloaded OnBoard data remains on their mobile devices unless a Remote Wipe was already performed.
NOTE: If a user is deleted without first being deactivated, OnBoard data that was previously downloaded to their phone or tablet may remain on that device.

What Is The Recommended Process When a User Leaves?

The recommended process when a board member or user leaves the organization is to deactivate them before deleting them.

Recommended Process

  1. Deactivate the user to trigger a Remote Wipe (if enabled for your organization).
  2. Allow the wipe instruction to be issued to the user's registered mobile devices.
  3. Delete the user from the Directory to remove their access and profile.

Steps to Delete a Member

  1. Open the Directory.
    • Locate the user you want to remove.
  2. Select the three-dot (⋯) menu next to the user's name.
  3. Click Delete Member.
mceclip1.png
  1. Confirm the action when prompted.

CleanShot_2020-11-19_at_11.42.06.png

Following this order helps ensure that downloaded OnBoard data is removed before the user's account is removed from the organization.

Wiping Devices Without Removing Access

Can I Wipe a User's Devices Without Deactivating or Deleting Them?

Yes. OnBoard includes a separate Wipe Devices action that allows administrators to remotely remove OnBoard data from a user's registered mobile devices without changing their access status.
This option can be useful when:
  • A device is lost or stolen.
  • A user is replacing a device.
  • A device needs to be cleared for security reasons.
  • The user still needs active access to OnBoard.
NOTE: The user must still be an active member of the organization for the Wipe Devices action to be available.

Automatic Idle Wipe for Inactive Devices

What is an Idle Wipe?

An Idle Wipe is an automatic security feature that removes downloaded OnBoard data from a device that has not connected to the internet for an extended period.

This helps protect sensitive information on devices that are no longer in use or have been retired.

When Does an Idle Wipe Occur?

An Idle Wipe occurs when a device has not connected to the internet for 90 days.

When the wipe occurs:

  • Downloaded OnBoard data is removed from that device's mobile app.
  • Data from all OnBoard organizations is deleted from the device's mobile app.
  • The user's account remains active.

How Can a User Regain Access After an Idle Wipe?

If the user needs access again after an Idle Wipe:

  1. Connect the device to the internet.
  2. Open the OnBoard application.
  3. Sign in using your OnBoard credentials.
  4. Allow OnBoard to re-download the necessary content.

Understanding the Difference Between Remote Wipe and Idle Wipe

What Is the Difference Between a Remote Wipe and an Idle Wipe?

FeatureRemote WipeIdle Wipe
Initiated by AdministratorYesNo
Happens AutomaticallyNoYes
Logs User OutYesYes
Removes Downloaded DataYesYes
Affects All DevicesYesNo, only the inactive device
Triggered by User Removal or DeactivationYesNo
Occurs After 90 Days OfflineNoYes

FAQs

Does a Remote Wipe permanently delete a user's OnBoard account?

  • No. A Remote Wipe only removes downloaded OnBoard data from devices and signs the user out. If the user still belongs to the organization, they can sign in again and re-download their information.

Does a Remote Wipe affect all devices?

  • Yes. A Remote Wipe logs the user out of all devices and removes downloaded OnBoard data from all devices connected to that account.

Does a Remote Wipe only remove data from one organization?

  • No. Remote Wipe removes downloaded OnBoard data from all organizations associated with the user's account.

Can a user access OnBoard data after a Remote Wipe?

  • Yes. If the user's account remains active and they still belong to the organization, they can sign back in using their OnBoard ID and password and download the data again.

Does deleting a user automatically wipe their devices?

  • No. Deleting a user removes their access and Directory profile but does not trigger a Remote Wipe.

Does deactivating a user always wipe their devices?

  • No. Deactivation only triggers a Remote Wipe if the Remote Wipe feature is enabled for your organization.

What happens if a device misses the wipe notification?

  • The wipe command is stored by OnBoard in addition to being sent through a silent push notification. If the device misses the notification, it will still wipe the next time it communicates with the server.

Does Remote Wipe log the user out of the web application?

  • No. Remote Wipe affects the OnBoard mobile app only. Existing browser sessions are not automatically signed out.

Does an Idle Wipe remove a user's account?

  • No. An Idle Wipe only removes downloaded data from an inactive device. The user's account remains active unless separately removed or deactivated.

How long does a device need to be offline before an Idle Wipe occurs?

  • A device that has not connected to the internet for 90 days will automatically receive an Idle Wipe.

Can data be downloaded again after an Idle Wipe?

  • Yes. Users can reconnect to the internet, sign into OnBoard, and re-download their content if they still have access to the organization.

Was this article helpful?

2 out of 2 found this helpful

Have more questions? Submit a request

Comments

0 comments

Please sign in to leave a comment.