Devices shall be deleted that haven’t checked in for over 30 days
Description
By default, no devices are removed from Intune no matter the level of inactivity. In order to ensure an inventory of active authorized devices, device clean-up rules should be configured to automatically delete devices that have not checked in for over 30 days.
Policy
Devices are deleted from Intune if they have not checked in for over 30 days
Licensing Considerations
Any tenant with Intune licensing can access this setting.
Set-Up Instructions
Overview of enrollment restrictions - Microsoft Intune | Microsoft Learn
Create device platform restrictions - Microsoft Intune | Microsoft Learn
To set the device clean-up rule:
Go to the Intune Admin Center
Click on Devices
Scroll down to Other and select Device Clean-up rules
Select Yes for the first option
Set the time period to 30 days
Click Save
End-User Impact
Level: Low
If users have a device that does no check in for over 30 days it would be removed from Intune. Devices can be recovered if someone were to take an extended leave for up to 180 days.
Tips
• If you are leveraging Intune as a source of truth for your asset inventory, you may want to change this setting to 60 or 90 days so that devices are not removed as quickly. This would give you more time to identify stale devices and take the proper action to reissue or retire the device.
PowerShell Scripts
Videos
Last updated