Free tools Windows power users keep installed
One-click scans. No signup required.
Remote lock restricts access to a device, remote wipe removes data, and device isolation restricts network communications. They solve different problems: a lock protects against someone using a device, a wipe removes data from a device or account, and isolation helps contain a suspected compromise. The exact effect depends on the product, the action selected, and whether the device can receive the command.
How the three actions differ
| Action | Primary goal | What it changes | Main caveat |
|---|---|---|---|
| Remote lock | Prevent ordinary local access | Locks the device; Microsoft Intune’s documented action also resets its password. | It is not a data-erasure or network-containment action. Exact passcode behavior depends on the platform. Microsoft Intune; Microsoft Graph. |
| Remote wipe | Remove data | Depending on the selected command, removes a work account, organizational data, or all device data and settings. | A full device wipe can erase personal data too; removable-storage data may remain. Google Workspace; Microsoft Intune. |
| Device isolation | Contain a suspected compromised endpoint | Restricts network communications while allowing specified security-service connections or other permitted traffic. | Can disrupt business connectivity or affect management reachability; behavior depends on platform and configuration. Microsoft Defender for Endpoint; Microsoft Defender isolation guidance. |
These are not interchangeable actions, and the cited product documentation does not prescribe one universal response sequence. Choose based on the immediate risk, the data involved, and the device’s management and network state.
What remote lock does
A remote-lock command tells a management service to lock the device. In Intune, Microsoft says Remote lock locks the device and resets its password. Microsoft Graph also exposes remote lock as an action for a managed device. Neither description defines it as erasing stored data or containing network traffic.
Use a lock when the priority is to prevent ordinary access while preserving the device and its data. Confirm how the platform handles the passcode or password before relying on the action; the details are not universal.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
What remote wipe removes
“Wipe” can mean different scopes, so check the exact command before issuing it. A full wipe is destructive: Intune describes Wipe as restoring factory settings and removing all data and settings. Microsoft Configuration Manager describes full wipe similarly, including organizational and user data and settings. Intune Wipe; Configuration Manager remote wipe.
Device wipe versus account wipe
Google Workspace distinguishes wiping a device from wiping a work account. A device wipe can erase both work and personal data, and may not delete data on removable storage such as an SD card. Wiping the work account removes that account rather than issuing the same whole-device command. Check which option is available and selected before proceeding. Google Workspace device management guidance.
Rank #2
- HARDWARE 2FA AND MFA: FIDO Alliance Certified FIDO2 v2.1 with CTAP2 plus legacy U2F and CTAP1 for strong two-factor login and passwordless sign-in on services that support security keys
- BUILDING ACCESS ON ONE CARD: MIFARE DESFire EV2 4K applet with AES encryption adds office door and physical access control alongside digital authentication
- CERTIFIED SECURE ELEMENT: An NXP Common Criteria EAL6+ certified secure controller and Java Card platform protects your keys on a tamper-resistant chip
- DUAL INTERFACE SMART CARD: Contactless NFC ISO 14443 plus ISO 7816 contact reader support in an ISO 7810 ID-1 format that is passive and needs no battery
- SWISS ENGINEERED DESIGN: Built by Cryptnox as a single card for authentication and access control and backed by a 2 year warranty
Wipe versus retire in Intune
For a worker-owned device being separated from organizational management, Intune’s Retire action removes company data and settings while leaving personal data intact. Wipe restores factory settings and removes all data and settings. The choice therefore depends on whether the aim is to remove organizational management or clear the whole device. Microsoft Intune.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What device isolation does
Microsoft Defender for Endpoint describes isolation as disconnecting a compromised device from the network while retaining connectivity to the Defender for Endpoint service, which continues monitoring it. The aim is to limit an attacker’s ability to control the device or carry out activity such as data exfiltration and lateral movement.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Rank #3
- FIDO2/Passkey Authentication – Secure, passwordless login with supported platforms. Check if your intended service supports hardware keys before purchase. Works with Gmail, Facebook, GitHub, Dropbox, and more.
- Enhanced Multi-Factor Authentication (MFA): Strengthen account security using either FIDO2.0 authentication or TOTP/HOTP codes, providing flexible options for added protection.
- Universal Connectivity: Features USB-A and NFC compatibility, making it easy to use across various devices including PCs, Macs, iPhones, and Android phones for seamless integration.
- Durable & Portable Design: Built with a 360° rotating metal cover for extra durability. Compact and lightweight, it easily attaches to a keychain for on-the-go convenience. No batteries or network required, ensuring dependable use anywhere.
- FIDO Certified & Business-Ready: Certified for FIDO standards and supported by a range of management software suites, ideal for both individual users and enterprise deployment.
Isolation targets communications, not the screen or stored files. Defender also offers selective isolation, which limits network access for a restricted set of applications while allowing specified processes or destinations. Do not assume that isolation locks a device or erases data. Microsoft Defender for Endpoint response actions; Microsoft Defender isolation guidance.
Quick Recap
Check these limits before relying on a command
- The device must be reachable. Google Workspace says My Devices management is available only when the device is turned on and connected to a network. Its device-wipe option must also be enabled by an administrator to appear. Google Workspace.
- A full VPN tunnel can interfere with isolation management. Microsoft warns that a device behind a full VPN tunnel may be unable to reach the Defender cloud service after isolation. Its guidance recommends split tunneling for Defender and antivirus cloud-protection traffic. Microsoft Defender isolation guidance.
- An offline isolation command may be delayed. Microsoft says Defender retries an isolation action for up to three days if the device is inactive or offline. If it does not reconnect within that period, the administrator should issue the action again once it is active. Microsoft Defender isolation guidance.
- Isolation has product requirements and a time limit. Microsoft’s guidance lists supported operating systems and role and device-group requirements, and says isolation is automatically lifted after seven days. Check the current requirements for the specific Defender product and operating system. Microsoft Defender isolation guidance.
- A wipe can affect personal data. Google advises consulting the administrator and using device erase when the device is believed lost or stolen; its described device wipe can affect work and personal data. Google Workspace.
How to choose the right action
- If someone may use a missing device, consider a remote lock to block ordinary access while you establish its status. Do not treat the lock as proof that data is erased or network access is contained.
- If data must be removed, identify whether the right scope is a work account, company data, or the entire device. Verify the effect on personal and removable-storage data before sending a destructive command.
- If a device may be compromised, use the isolation capability provided by its security product to restrict communications, and check that the product can still reach the services needed to monitor or manage it.
- Confirm delivery and outcome. A command may not take effect immediately if a device is offline, turned off, or unable to reach the management service. Follow the relevant vendor’s status and retry guidance.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




