User guide
IT policy rule Description
Secure Wipe Delay After IT Policy
Received
This rule specifies the length of time (in hours) after a device receives an IT
policy update or the Delete all device data and remove device IT administration
command before the device deletes all BlackBerry device user data.
Secure Wipe Delay After Lock This rule specifies the length of time (in hours) after a device locks before the
device deletes all user data.
Secure Wipe if Low Battery This rule specifies whether a device deletes all user data if the battery power
level is low enough that the BlackBerry device turns off the wireless transceiver.
For more information, see the BlackBerry Enterprise Server Policy Reference Guide.
Resetting a device to factory default settings
When a BlackBerry device resets to the factory default settings, the device overwrites the device storage space. If you or a
BlackBerry device user turned on content protection, the device also uses a memory-scrub process to overwrite the
application storage on the device and built-in media storage. When the device runs the memory-scrub process, it deletes
any residual unmapped data.
You can use the Reset to Factory Defaults on Wipe IT policy rule to require that a device reset to the factory default settings
when the device receives the Delete all device data and remove device IT administration command over the wireless
network. When you change the value for the IT policy rule to Yes and send the IT administration command to the device,
the device resets to the factory default settings and permanently deletes all applicable device data from the device storage
space. If the device is running
BlackBerry Device Software 4.5 or later, the device also deletes the Reset to Factory
Defaults on Wipe IT policy and removes third-party applications.
If the device is running BlackBerry Device Software 4.5 or later and you change the value for the IT policy rule to Yes, the
device resets to factory default settings when you send the IT administration command, when the user permanently
deletes device data, or when the user exceeds the maximum number of times the user can try to type the device password.
Data flow: Deleting all device data from a device
When you delete all BlackBerry device data from a device using the Delete all device data and remove device IT
administration command, the device performs the following actions:
1. Adds a Device Under Attack flag to the NV store
If a user removes the battery or the battery power drops to zero before the device deletes all data, when the user
replaces the battery, the process continues because the Device Under Attack flag is still present.
2. Restarts
3. Deletes the IT policy public key from the NV store to remove the binding between the device and the BlackBerry
Enterprise Server
Security Technical Overview Device storage space
51