Factory Reset Protection (FRP) and Enterprise Factory Reset Protection (EFRP) serve similar anti-theft purposes but work differently.
Standard FRP is tied to the Google account signed into the device. If the device is factory reset (via recovery, not through Settings), the device will require the previously signed-in Google account credentials before it can be set up again. This is a consumer anti-theft feature present on all GMS-certified Android devices.
On fully managed devices, FRP typically activates - if enabled via policy - based on whichever Google account was present on the device - this could be the managed Google Play account provisioned by the EMM. If that account is deleted or no longer accessible (common after EMM unenrolment), recovering the device can be difficult.
Enterprise FRP is a policy-driven feature that allows administrators to specify one or more Google account email addresses that can unlock the device after a factory reset. This is configured through the EMM as part of the device policy.
Key differences:
From Android 15, FRP behaviour has changed significantly:
This makes configuring EFRP more important than ever for organisations managing fully managed devices, as recovery from an unexpected reset without EFRP configured becomes considerably harder.
From the May 2026 AMAPI release, FRP handling on COPE devices was improved. AMAPI now explicitly disables FRP and clears the account list when no administrator email addresses are configured in the EFRP policy. This prevents unexpected lockouts after device resets on COPE devices where EFRP was never intentionally configured - previously, COPE devices could enter FRP with no recoverable account if the personal-side Google account was removed during the work profile wipe.
For more detail, see Feature spotlight: Factory Reset Protection.