Most businesses have an onboarding checklist. Very few have an offboarding one that goes beyond cancelling the email account. When an employee leaves, the Mac they hand back often contains unwiped personal data, active app licences, a still-enrolled DMS (formerly MDM) profile, and an Activation Lock tied to their personal Apple ID. Any one of those is a security or compliance problem. Together, they are a data breach waiting to happen.
This article covers the Mac-specific steps that a generic checklist does not: Activation Lock bypass, Managed Apple Account removal, Apple Silicon cryptographic erase, and the GDPR documentation your business needs to evidence data destruction correctly.
Why Mac offboarding fails and what it costs
The activation lock problem: why a returned Mac can become unusable
Activation Lock is the single most disruptive Mac offboarding failure, and it is entirely avoidable with the right DMS configuration. When a Mac has Find My enabled and is tied to an employee’s personal Apple ID, the device cannot be erased and reassigned without that person’s credentials. Once they have left the business, those credentials are gone with them.
The result is a device that is physically present in your office but functionally unusable. Apple Support cannot bypass Activation Lock without proof of ownership in the form of the original invoice. Recovery is possible but slow, and the device sits in limbo in the meantime.
Businesses with Supervised Mode enabled via their DMS can bypass Activation Lock entirely. The DMS has authority over the device at the platform level, which means an erase and reassignment does not require the departing employee’s Apple ID credentials. Without Supervised Mode, you have no bypass capability. This is the gap that most manual or loosely managed Mac fleets have, and it shows up at the worst possible moment: when someone leaves under difficult circumstances.
The data exposure risk: what remains on an improperly wiped device
A Mac returned without a proper erasure process may contain: personal files and downloads, browser history and saved passwords, cached credentials for business applications, locally stored email, and copies of any documents downloaded from shared drives during the employee’s tenure. Not all of this is company data. Some of it is personal data belonging to the employee. Under UK GDPR, both categories matter.
Reassigning a Mac without erasing it is a data breach. If the next employee who picks up that device can access the previous user’s files, your business has failed to protect personal data and potentially exposed business-sensitive information to an unauthorised party.
The GDPR Angle: what UK businesses are required to evidence on disposal
The ICO’s guidance on data security in the context of employee departure requires businesses to ensure personal data held on devices is destroyed or rendered irretrievable when those devices are reassigned or disposed of. “We wiped it” is not sufficient evidence. The business needs to be able to demonstrate what erasure method was used, when it was performed, and that the result was confirmed.
This is precisely the kind of gap that comes up in ICO investigations following a data breach complaint from a former employee.
The complete Mac offboarding checklist
Step 1: revoke access first, before the employee’s last day
The sequence matters. Access revocation should happen before the device is physically collected, and ideally on the last working day rather than after the employee has left. Accounts to revoke include:
- Email and calendar access (Microsoft 365, Google Workspace)
- Single sign-on and identity provider access (Okta, JumpCloud, Entra ID)
- Business application licences (Adobe, Slack, Figma, and any role-specific tools)
- Shared drive and cloud storage access (SharePoint, Google Drive, Dropbox)
- VPN and remote access credentials
Revocation after the employee has left, rather than on the last day, is the most common sequencing failure. A former employee with active credentials for 48 hours after departure is a meaningful security exposure.
Step 2: remove the device from DMS before the employee leaves
The DMS unenrolment step must happen before the device is erased, not after. If the device is erased first, the DMS record becomes an orphan entry that requires manual cleanup and may leave the device in a limbo state where it cannot be fully re-enrolled. In Jamf, use the Remove MDM Profile command from the device record. In Addigy, use the equivalent unenrolment workflow from the device console.
Confirm the device has checked out of the DMS dashboard before proceeding to the erasure step. Do not rely on the employee to confirm this.
Step 3: handle the Managed Apple Account correctly
If the employee was issued a Managed Apple Account through Apple Business, that account must be signed out of the device and removed from Apple Business enrolment before the erasure step. Removing the Managed Apple Account after the device has been erased does not fully resolve the Apple Business association and can create re-enrolment issues.
The correct sequence: sign out of the Managed Apple Account on the device, remove the employee’s account from Apple Business, then proceed to erasure. If the employee is no longer present, this step can be completed remotely via Apple Business if the device is still connected to the internet and enrolled in the DMS.
Step 4: erase the device to Apple Silicon Standard
On Apple Silicon Macs, use Erase All Content and Settings from System Settings > General > Transfer or Reset. This performs a cryptographic erase: the encryption keys used to protect the device are deleted, rendering all data on the device mathematically unrecoverable. The process takes minutes and returns the device to factory state, ready for new user setup via Apple Business.
On Intel Macs, Erase All Content and Settings is not available in the same form. The equivalent process is a full macOS reinstall via macOS Recovery, which overwrites the system volume. This is slower and more involved but achieves the same result. For any Intel Mac due for retirement rather than reassignment, consider whether the effort of a full reinstall is warranted, or whether the device should go directly to secure disposal.
Step 5: document the erasure for GDPR compliance
Record the following for each device erased:
- Device serial number
- Date and time of erasure
- Method used (Erase All Content and Settings / macOS Recovery reinstall)
- Name of the person who performed the erasure
- DMS confirmation of device unenrolment
This documentation is your evidence of data destruction for ICO purposes. Store it against the employee’s departure record in your HR system. If you are using a DMS with audit logging enabled, the erasure event will be recorded automatically, export and save the log entry as part of the offboarding record.
Step 6: reassign or retire the device
After a confirmed erasure, the device is ready for reassignment via Apple Business zero-touch enrolment, or for trade-in or disposal. Do not reassign a device that has not had a confirmed erasure documented. Do not list a device for trade-in or resale with the previous DMS profile still associated: the next owner will encounter enrolment restrictions that cannot be resolved without contacting the original business.
What DMS makes possible that manual offboarding cannot
Remote wipe without physical access to the device
The most practically significant DMS capability in an offboarding context is remote wipe. If a departing employee takes their Mac home before handing it back, or if a device is misplaced during the transition, a DMS-enrolled device can be wiped remotely from the IT dashboard with no physical access required. The wipe happens silently the next time the device connects to the internet.
Without DMS, a device that leaves the building with data on it stays that way until it is physically recovered.
Automated offboarding triggers from HR systems
DMS platforms including Jamf and Addigy can be integrated with identity providers and HR systems so that when a leaver record is created, a chain of actions triggers automatically: account suspension, DMS policy enforcement, and in some configurations, a remote lock pending device collection. This removes the human error from the sequencing problem and ensures the process runs correctly regardless of who in IT handles the departure.
Audit logs: evidencing what was done and when
DMS platforms maintain audit logs of all device management actions including remote wipes, policy changes, unenrolment events, and app removals. These logs are timestamped and attributed to the administrator who performed the action. For GDPR data destruction evidence, a DMS audit log entry is significantly more robust than a spreadsheet row updated manually.
The device itself: what to do with the hardware after offboarding
Reassigning within the fleet
A device that has been properly erased, unenrolled, and confirmed clean is ready for reassignment. Use Apple Business zero-touch enrollment to set it up for the new user: the device will apply the correct configuration profile automatically on first boot, without IT needing to be physically present.
Apple Trade In and third-party resale
A device cannot be safely listed for resale until the DMS profile has been removed and an Apple Silicon cryptographic erase confirmed. Selling a device with an active DMS profile attached means the next owner will encounter enrollment restrictions they cannot resolve. Selling a device without erasure confirmation means personal and business data is in the hands of a third party.
Once both steps are confirmed, Apple Trade In and third-party resellers including Music Magpie and CEX are viable channels. Trade-in values are better captured while the device is relatively current: a MacBook from 2022 or 2023 is worth meaningfully more today than it will be in two years. For Intel Macs approaching end-of-support, the time to capture trade-in value is before the 2028 deadline makes the market fully aware of the limitation.
Secure disposal for devices beyond use
Devices too old or damaged for resale should be disposed of through a certified WEEE-compliant IT asset disposal provider. Confirm that the disposal certificate covers data destruction, not just physical recycling. The erasure step above should still be completed before handover to a disposal provider where the device is still functional.
If your current offboarding process does not include a documented Mac-specific checklist, we can review it and close the gaps before they become a compliance problem.
Related articles
- Avoiding Security Gaps During Employee Offboarding
- The IT Manager’s Checklist for Employee Onboarding
- Apple Business Is Here: What the New All-in-One Platform Means for Your Organisation
FAQs
Is erasing a Mac with Erase All Content and Settings GDPR-compliant?
Yes, on Apple Silicon Macs. Erase All Content and Settings performs a cryptographic erase, deleting the encryption keys that protect the device’s data. The data is rendered mathematically unrecoverable. This meets ICO guidance for secure data destruction when reassigning or disposing of a device. The erasure should be documented with the device serial number, date, and method used to create a defensible GDPR evidence trail.
What happens if a leaver takes their Mac home before it is wiped?
If the device is enrolled in a DMS, it can be remotely wiped as soon as it connects to the internet. The wipe is triggered from the IT dashboard and requires no physical access. Without DMS enrolment, the only option is to request the device back and complete the wipe manually. This is why DMS enrolment is the baseline requirement for any Mac fleet where devices leave the office.
What should we do with the Managed Apple Account when someone leaves?
The Managed Apple Account should be signed out of the device before the erasure step, and removed from Apple Business. Doing this in the wrong order, or skipping it entirely, can create re-enrolment issues on the device and leave the former employee’s account associated with business-managed hardware. Complete the account removal step before the employee’s last day where possible.



















































