Read about “LoTL” attacks (living off the land” and LoTO “Living off the Orchard. Also DEP, search on MDM attacks and lateral movement. Do you see an MDM under VPN, or log into Business or School? This is very complex! Look at “allowed apps” under restrictions are they all there? Some legit apps may be replaced with fake ones. Search on Eset for Gookit and read about LoTl attacks at this site. If it’s and auto enrollment (such as DEP) it will reinstall with reformat. “They” can see everything! There is a lot of info, except how to remove it. It could also be another attack such as just LoTL in which case, tools can remove the compromises, but email and passwords and other accounts will have to be changed. I’d much rather have LoTL, but mine appears to be MDM, search on symptoms of MDM compromise. List your symptoms, as you have to work backwards. Eset has a tool to remove LoTl and steps. But you will have to determine symptoms then figure out the cause! 60% of recent attacks are fileless (LoTl). Lots of reading required! Also read about “lateral attacks”. I
hope this helps.