Device Offboarding & Reuse
How to handle devices from employees who no longer work at Authentica, and prepare them for reassignment.
Scenario: Device is Offline (Former Employee)
If the device is powered off or not connected to the internet, Intune remote actions (Retire, Wipe) will not work — they require the device to check in to receive the command.
Procedure
-
Delete the device record from Intune
- Go to Intune > Devices > search for the device
- Click Delete — this removes the record from Intune’s console only
- Does NOT touch the actual device
-
Delete the device from Entra ID (if applicable)
- Go to Entra ID > Devices > search for the device
- Delete the stale record
-
When the device is physically available for reassignment:
- Power on and sign in with a local admin account (or cached credentials)
- Factory reset: Settings > System > Recovery > Reset this PC > Remove everything
- During the fresh OOBE (Out of Box Experience), join to Azure AD with the new employee’s credentials
- Intune will auto-enroll and apply compliance policies
Scenario: Device is Online (Employee Leaving)
If the employee is still active and the device is online:
-
Wipe the device from Intune — factory resets it remotely
- Intune > Devices > select device > Wipe
- Removes all data, apps, settings — returns to factory state
- Use when the device will be reassigned and you want a clean slate
-
Or Retire if the device is employee-owned (BYOD)
- Removes only company data (managed apps, email profiles, Wi-Fi/VPN, compliance policies)
- Leaves personal files and apps intact
Quick Reference: Intune Device Actions
| Action | What It Does | Device Must Be Online? | Use When |
|---|---|---|---|
| Retire | Removes company data only | Yes | BYOD, employee leaving but keeps device |
| Wipe | Factory reset, removes everything | Yes | Org-owned device being reassigned |
| Delete | Removes record from Intune console | No | Stale/offline devices, cleanup |
Notes
- Always Delete before re-enrolling a device that was previously managed — avoids duplicate records
- After factory reset + Azure AD Join, verify enrollment with
dsregcmd /status