Offboarding Devices
When offboarding corporate devices, the recommendation is to wipe the device before deleting the device from Intune and Azure AD. This will ensure that all company data is removed. Proper hardware sanitation is still required.
When offboarding personally owned devices, the recommendation is to retire the device. This will ensure that company data is properly removed from the device before automatically deleting the device after the next check in.
Remove the device from Autopilot (GCC Only)
- Sign into Intune Admin Center (GCC)
- Click “Devices” -> “Enroll devices” -> “Devices” under “Windows Autopilot Deployment Program”.
- Search for device by serial number.
- Once the device has been located, click the three elipses, then “Unassign user”.
- Check the box next to the device, then click “Delete”.
It can take up to 24 hours for deleteion to fully propagate. If the device is reset prior to the deletion fully propagating, the device may rejoin the domain.
Wiping a device
Wiping a device through Intune will wipe all user accounts, data, MDM policies, and settings. Resets the operating system to its default state and settings.
- Sign into Intune Admin Center (GCC) or Intune Admin Center (GCCH)
- Click “Devices” -> “All Devices”.
- Search for device needing to be wiped.
- Click “Wipe”
- Leave box for “Retain enrollment state and user account” unchecked.
- Status of the “Wipe” command can be seen in the device overview page.
Retiring a device
Retiring a device in Intune will remove managed app data (where applicable), settings, and email profiles that were assigned by using Intune. Removal happens the next time the device checks in and receives the remote Retire action.
- Sign into Intune Admin Center (GCC) or Intune Admin Center (GCCH)
- Click “Devices” -> “All Devices”.
- Search for device needing to be retired.
- Click “Retire”
Delete a device from Intune
Deleting a device out of Intune before you wipe the device will remove users access to company resources, however devices may still retain installed applications and associated data.
- Sign into Intune Admin Center (GCC) or Intune Admin Center (GCCH)
- Search for device needing to be delete.
- Click Delete.
Delete a device from Azure AD
Deleteing a device out of Entra ID will remove the users access to company resources, however this will not remove the device from Intune management.The device will still need to be deleted out of Intune.
- Sign into Entra ID (GCC) or Entra ID (GCCH)
- In the search bar at the top of the Azure portal, enter “Microsoft Entra ID.”
- Click “Devices” -> “All Devices”.
- Search for device needing to be deleted.
- Click Delete.