Skip to content

Device Offboarding & Reuse

How to handle devices from employees who no longer work at Authentica, and prepare them for reassignment.

Scenario: Device is Offline (Former Employee)

If the device is powered off or not connected to the internet, Intune remote actions (Retire, Wipe) will not work — they require the device to check in to receive the command.

Procedure

  1. Delete the device record from Intune

    • Go to Intune > Devices > search for the device
    • Click Delete — this removes the record from Intune’s console only
    • Does NOT touch the actual device
  2. Delete the device from Entra ID (if applicable)

    • Go to Entra ID > Devices > search for the device
    • Delete the stale record
  3. When the device is physically available for reassignment:

    • Power on and sign in with a local admin account (or cached credentials)
    • Factory reset: Settings > System > Recovery > Reset this PC > Remove everything
    • During the fresh OOBE (Out of Box Experience), join to Azure AD with the new employee’s credentials
    • Intune will auto-enroll and apply compliance policies

Scenario: Device is Online (Employee Leaving)

If the employee is still active and the device is online:

  1. Wipe the device from Intune — factory resets it remotely

    • Intune > Devices > select device > Wipe
    • Removes all data, apps, settings — returns to factory state
    • Use when the device will be reassigned and you want a clean slate
  2. Or Retire if the device is employee-owned (BYOD)

    • Removes only company data (managed apps, email profiles, Wi-Fi/VPN, compliance policies)
    • Leaves personal files and apps intact

Quick Reference: Intune Device Actions

ActionWhat It DoesDevice Must Be Online?Use When
RetireRemoves company data onlyYesBYOD, employee leaving but keeps device
WipeFactory reset, removes everythingYesOrg-owned device being reassigned
DeleteRemoves record from Intune consoleNoStale/offline devices, cleanup

Notes

  • Always Delete before re-enrolling a device that was previously managed — avoids duplicate records
  • After factory reset + Azure AD Join, verify enrollment with dsregcmd /status