I cannot remotely inspect a personal phone, identify who may be accessing it, remove an unknown administrator, recover deleted data, or provide individual forensic support. Follow the steps below. Do not send me screenshots, logs, IMEIs, telephone numbers, passwords, or account recovery codes.
The presence of Android Enterprise, Android Device Policy, Google Workspace, Knox, a work profile, certificates, system applications, developer terminology, “viewer”, “beta”, “heartbeat”, system/priv-app, or a large number of installed apps does not prove someone has taken over a device.
A telephone number, IP address, IMEI or serial number alone does not give someone remote control of an Android device.
If you remain concerned unauthorised access has happened or is happening, the following are some suggested steps to take. Nothing here replaces any need for contacting the appropriate authorities.
If a partner, ex-partner or someone with physical access may be monitoring you, use a different trusted device to seek help. Removing access or changing settings can alert an abuser. In the UK, Refuge's Tech Safety service provides specialist guidance; call 999 if anyone is in immediate danger.
Before resetting or deleting anything:
If the phone is lost, stolen or no longer under your physical control, use Google's Find Hub from a trusted device to locate it, mark it as lost or erase it. Erasing is permanent and prevents further location through Find Hub, so preserve what you need first where possible.
Do not factory-reset the phone until the data and evidence you need are safely copied.
Most apparent “phone takeovers” are account-access related rather than Android Enterprise management.
Repeat this process for email, social media, cloud storage, banking, mobile-carrier and manufacturer accounts such as a Samsung account. In messaging and social apps, review linked devices, logged-in sessions or similarly named menus and remove anything unfamiliar. Work from the email account outward: control of email is commonly used to reset everything else.
Open Settings and use its search box for each item below. Android manufacturers use different menu layouts, so searching is more reliable than following one fixed path.
A work profile is identified by a briefcase badge on work apps and normally a Work tab in the app drawer and under Settings → Passwords and accounts.
On a personally owned phone, the organisation manages the work profile, not personal photos, personal messages or personal app data. Remove it with:
Settings → Passwords and accounts → Work → Remove work profile
Confirm the deletion, then uninstall the associated policy app if it remains. This deletes work-profile data only. A factory reset is not required. See Introduction to work profile for the privacy boundaries.
Google Family Link supervision can let a parent see a phone's location, approve or block apps, set time limits and remotely lock the device. Those controls can feel like a takeover, but Family Link cannot remotely read the screen, emails or messages, listen to calls, or choose a new screen-lock password.
Search Settings for Parental controls and check Settings → Digital Wellbeing and parental controls or Settings → Google → All services → Kids and family → Parental controls. Also look for a notice that the Google Account is supervised.
Use Google's Family Link supervision guide to stop supervision. A person under 18 needs a parent's approval, and both people are notified when supervision stops. Removing a supervised account removes its supervision settings from that phone; adding the same account again restores them. A factory reset does not turn a supervised account into an unsupervised account.
Search Settings for and review:
An app's long list of declared permissions, whether shown in a manifest, system-app database or diagnostic report, does not mean every permission is currently granted or being used. The current Settings screens, Privacy dashboard and observable account or device activity are what matter.
Also open Google Maps → profile picture → Location sharing and stop any sharing you do not want.
Open Play Store → profile picture → Play Protect → Scan. Uninstall apps Play Protect identifies as harmful. Also install all Android, Google Play system and app updates.
Open Settings → Apps → See all apps and review the complete list, not only the app drawer or Home screen. Some installed apps have no launcher icon. Uninstall an unfamiliar app only after recording its name and checking that it is not a system, carrier, accessibility, work, school or safety app you intentionally use.
For a strange-looking system app or package name, search the BAYTON Android system app database. Use the exact package name from the app-information screen where available, then check the observed manufacturer, device and Android versions. The database shows which packages have been seen preloaded across real device profiles and what they are for. A match can explain a normal system component; a missing result does not prove an app is malicious because coverage is not universal.
Use the phone manufacturer's official instructions to restart in Safe Mode. On many phones, open the power menu, touch and hold Power off, then confirm Safe Mode. Downloaded apps are temporarily disabled until the next normal restart.
If unexplained on-screen behaviour stops in Safe Mode, a downloaded app is likely responsible. Restart normally, then uninstall recently added or unfamiliar apps one at a time. Safe Mode does not sign other people out of online accounts or stop account forwarding and location-sharing settings, so it is a diagnostic step rather than proof that the phone is secure.
A personal work profile and a fully managed device are different.
Reset the device only after completing sections 1 to 3. During setup, watch what happens before adding any Google Account:
Personally owned devices cannot be silently added to Android zero-touch by an ordinary individual who merely knows the IMEI or serial number. Devices are registered through authorised reseller and enterprise systems. See Are employee-owned devices eligible for zero-touch? for how this works.
Loss of service, missing verification texts, unexpected SIM-change messages or calls being redirected are carrier-account problems, not proof that Android itself is managed.
Contact the mobile carrier using a number from its official website. Ask it to:
Do not rely on SMS for account recovery until the carrier confirms the number is secure.
A reset is appropriate after confirmed account compromise, an unknown high-privilege app that cannot be removed, or persistent unexplained behaviour after the checks above.
If enterprise setup returns before any account is added, follow section 4. Repeated resets will not remove reseller-based enterprise registration.
If Settings is blocked, or unexplained behaviour continues after a clean setup without enterprise enrolment, contact the manufacturer or an authorised repair provider and ask it to reinstall the device's official signed firmware. This can destroy data and evidence. Do not follow an unknown person's flashing instructions, unlock the bootloader, or run ADB commands copied from a forum unless you understand exactly what they will remove. Replacing the phone is the final option, after the accounts and mobile number have been secured; otherwise the same account problem can simply follow to the replacement.
Treat these as evidence worth acting on:
These are not evidence on their own:
Do not pay strangers who claim they can identify an attacker from screenshots, an IP address, an IMEI or a list of Android system apps. Do not install remote-support software for them and never share passwords or verification codes.