Azure AD Device Removal Best Practices for Employee Offboarding

When an employee leaves your organization, removing their devices from Azure AD (Microsoft Entra ID) and Intune is critical for maintaining security. Orphaned devices can provide unauthorized access points and consume Intune licenses.

Understanding Azure AD Device Types

Azure AD Registered Devices

Personal devices (BYOD) registered to access company resources. These devices:

  • Remain owned by the employee
  • Have limited company control
  • Should be selectively wiped (company data only)
  • Examples: Personal iPhone, home laptop

Azure AD Joined Devices

Company-owned devices fully managed by your organization. These devices:

  • Are domain-joined to Azure AD
  • Can be fully controlled and wiped
  • Require physical collection from employee
  • Examples: Corporate laptops, tablets

Hybrid Azure AD Joined Devices

Devices joined to both on-premises AD and Azure AD. These devices:

  • Require coordination between on-prem and cloud management
  • Must be removed from both environments
  • Often include desktop workstations

Device Removal Methods

Method 1: Azure Portal

Best for: Single device removal, manual processes

Steps:

  1. Sign in to Azure Portal
  2. Navigate to Azure AD > Users > Select User > Devices
  3. Select device and click Delete
  4. Confirm the deletion

Method 2: PowerShell with Azure AD Module

Best for: Bulk operations, automation scripts

Advantages: Can process multiple devices, scriptable, auditable

Method 3: Microsoft Graph API

Best for: Integration with other systems, modern automation

Advantages: REST API, works with any programming language, detailed control

Intune Device Management

Selective Wipe vs Full Wipe

Selective Wipe (Recommended for BYOD)

  • Removes company data only
  • Preserves personal photos, contacts, apps
  • Removes email, calendar, company apps
  • Faster and less disruptive

Full Wipe (For Corporate Devices)

  • Factory resets the entire device
  • Removes all data and settings
  • Prepares device for reuse or disposal
  • More thorough but takes longer

Wipe Process in Intune

  1. Microsoft Endpoint Manager admin center
  2. Devices > All devices
  3. Select device
  4. Choose Wipe or Retire
  5. Confirm and monitor status

Token Revocation and Session Management

Why Revoke Tokens?

Even after removing devices, existing authentication tokens may remain valid for hours. Revoking tokens ensures immediate access termination.

What Gets Revoked

  • OAuth refresh tokens
  • Azure AD authentication sessions
  • Application-specific tokens
  • Persistent browser sessions

Token Revocation Methods

Tokens can be revoked through Azure Portal or PowerShell, affecting all active sessions across all devices.

Multi-Factor Authentication Reset

When to Reset MFA

  • Employee used personal phone for MFA
  • Company-issued phone not returned
  • Security authenticator app on personal device
  • Preventing future authentication attempts

MFA Reset Process

  1. Azure AD > Users > Select user
  2. Authentication methods
  3. Require re-register MFA (or delete methods)
  4. Remove all registered authentication methods

Complete Device Removal Automation

Automated Workflow Steps

  1. Identify all user devices in Azure AD
  2. Categorize by device type (Registered/Joined/Hybrid)
  3. Execute appropriate wipe (Selective/Full)
  4. Remove from Azure AD
  5. Remove from Intune
  6. Revoke all refresh tokens
  7. Reset MFA registration
  8. Log all actions for audit

Best Practices and Recommendations

Timing

  • Immediate: Revoke tokens and reset MFA (within minutes of termination)
  • Same day: Wipe and remove registered BYOD devices
  • After collection: Wipe corporate devices once physically returned
  • 30 days: Final cleanup of any orphaned device records

Device Collection

  • Maintain checklist of assigned devices in HR system
  • Collect laptops, phones, tablets, security tokens on last day
  • Verify serial numbers match asset records
  • Don't wipe until device is physically secured

BYOD Policies

  • Require enrollment before accessing company data
  • Use Intune App Protection Policies for selective control
  • Clearly communicate wipe policies during onboarding
  • Only perform selective wipes on personal devices

Audit and Compliance

  • Log all device removal actions with timestamps
  • Maintain device inventory with owner information
  • Document wipe completion and verification
  • Retain logs for compliance requirements (7 years for SOX)

Common Issues and Troubleshooting

Device Stuck in Pending Wipe

Cause: Device offline or unable to connect to Intune
Solution: Wait for device to come online, or delete device record if permanently offline

Unable to Remove Hybrid Joined Device

Cause: Device still exists in on-premises AD
Solution: Remove from on-prem AD first, wait for AAD Connect sync

User Still Signing In After Device Removal

Cause: Valid tokens not revoked
Solution: Explicitly revoke refresh tokens in addition to device removal

Intune License Still Assigned

Cause: Device record remains in Intune
Solution: Delete device from Intune portal, not just Azure AD

Automate with ADATT

Manual device management during offboarding is complex and error-prone. ADATT provides complete automation:

  • ✓ Automatic device discovery across Azure AD and Intune
  • ✓ Intelligent wipe selection (Selective for BYOD, Full for corporate)
  • ✓ Token revocation and MFA reset in one click
  • ✓ Complete audit logs for compliance
  • ✓ Bulk device removal for mass terminations
  • ✓ Integration with Microsoft Graph API for modern management

Simplify Azure AD Device Management

Don't leave security gaps with orphaned devices. ADATT automates complete device removal across Azure AD, Entra ID, and Intune.

Continue Reading

Automate onboarding & offboarding across Active Directory and Microsoft 365