## TL;DR
Issue the remote wipe via MDM immediately, revoke the user's sessions and rotate credentials that were on the device (VPN, Wi-Fi, SSO), then file the report with asset details. Speed matters more than completeness in the first 30 minutes; inventory and paperwork follow.

## The error
```text
(Urgent: device lost or stolen.)
```

## Steps
1. In the MDM (Jamf/Intune), locate the device and issue a remote wipe/lock now. Expected: command queued. A lock is instant deterrence; a full wipe follows when the device comes online.
2. Revoke the user's active sessions in the IdP and rotate the VPN and Wi-Fi credentials if they were device-stored. Expected: sessions killed. A wiped device with live tokens is still a risk until revocation.
3. Change passwords for any shared or service credentials the user had access to. Expected: rotated. Assume the thief will try them.
4. File the incident: asset tag, serial, user, last known location, police report number if stolen. Expected: ticket with all identifiers. Update inventory state to lost/stolen.
5. If the device comes online, confirm the wipe completed in the MDM. Expected: confirmed. If it never comes online, keep the wipe queued and monitor.

## When to use
- Laptop reported lost or stolen
- Device missing beyond a reasonable search

## When not to use
- Device found quickly (cancel the wipe if not yet executed)
- Phone or tablet (similar flow, different MDM section)

## Compatibility
- Jamf Pro, Intune; IdP session revocation

## Variants
### Device contains regulated data
Trigger the breach-assessment process; a lost encrypted device is usually not a breach, but document the analysis.
### Thief is using the device
Do not attempt remote confrontation; work with law enforcement and security.

## Why it happens
A lost laptop is a bag of credentials: cached logins, VPN profiles, tokens, and files. The response is about shrinking the window between loss and neutralization.

## Edge cases
- Encryption status determines breach severity; confirm FileVault/BitLocker was on.
- If the wipe was issued in error and the device is found, cancel it in the MDM before it executes if possible.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_vJo3CnPEKC23ZqIaaahpqA
