Azure AD Device Removal Best Practices for Employee Offboarding
When an employee leaves your organization, removing their devices from Azure AD (Microsoft Entra ID) and Intune is critical for maintaining security. Orphaned devices can provide unauthorized access points and consume Intune licenses.
Understanding Azure AD Device Types
Azure AD Registered Devices
Personal devices (BYOD) registered to access company resources. These devices:
- Remain owned by the employee
- Have limited company control
- Should be selectively wiped (company data only)
- Examples: Personal iPhone, home laptop
Azure AD Joined Devices
Company-owned devices fully managed by your organization. These devices:
- Are domain-joined to Azure AD
- Can be fully controlled and wiped
- Require physical collection from employee
- Examples: Corporate laptops, tablets
Hybrid Azure AD Joined Devices
Devices joined to both on-premises AD and Azure AD. These devices:
- Require coordination between on-prem and cloud management
- Must be removed from both environments
- Often include desktop workstations
Device Removal Methods
Method 1: Azure Portal
Best for: Single device removal, manual processes
Steps:
- Sign in to Azure Portal
- Navigate to Azure AD > Users > Select User > Devices
- Select device and click Delete
- Confirm the deletion
Method 2: PowerShell with Azure AD Module
Best for: Bulk operations, automation scripts
Advantages: Can process multiple devices, scriptable, auditable
Method 3: Microsoft Graph API
Best for: Integration with other systems, modern automation
Advantages: REST API, works with any programming language, detailed control
Intune Device Management
Selective Wipe vs Full Wipe
Selective Wipe (Recommended for BYOD)
- Removes company data only
- Preserves personal photos, contacts, apps
- Removes email, calendar, company apps
- Faster and less disruptive
Full Wipe (For Corporate Devices)
- Factory resets the entire device
- Removes all data and settings
- Prepares device for reuse or disposal
- More thorough but takes longer
Wipe Process in Intune
- Microsoft Endpoint Manager admin center
- Devices > All devices
- Select device
- Choose Wipe or Retire
- Confirm and monitor status
Token Revocation and Session Management
Why Revoke Tokens?
Even after removing devices, existing authentication tokens may remain valid for hours. Revoking tokens ensures immediate access termination.
What Gets Revoked
- OAuth refresh tokens
- Azure AD authentication sessions
- Application-specific tokens
- Persistent browser sessions
Token Revocation Methods
Tokens can be revoked through Azure Portal or PowerShell, affecting all active sessions across all devices.
Multi-Factor Authentication Reset
When to Reset MFA
- Employee used personal phone for MFA
- Company-issued phone not returned
- Security authenticator app on personal device
- Preventing future authentication attempts
MFA Reset Process
- Azure AD > Users > Select user
- Authentication methods
- Require re-register MFA (or delete methods)
- Remove all registered authentication methods
Complete Device Removal Automation
Automated Workflow Steps
- Identify all user devices in Azure AD
- Categorize by device type (Registered/Joined/Hybrid)
- Execute appropriate wipe (Selective/Full)
- Remove from Azure AD
- Remove from Intune
- Revoke all refresh tokens
- Reset MFA registration
- Log all actions for audit
Best Practices and Recommendations
Timing
- Immediate: Revoke tokens and reset MFA (within minutes of termination)
- Same day: Wipe and remove registered BYOD devices
- After collection: Wipe corporate devices once physically returned
- 30 days: Final cleanup of any orphaned device records
Device Collection
- Maintain checklist of assigned devices in HR system
- Collect laptops, phones, tablets, security tokens on last day
- Verify serial numbers match asset records
- Don't wipe until device is physically secured
BYOD Policies
- Require enrollment before accessing company data
- Use Intune App Protection Policies for selective control
- Clearly communicate wipe policies during onboarding
- Only perform selective wipes on personal devices
Audit and Compliance
- Log all device removal actions with timestamps
- Maintain device inventory with owner information
- Document wipe completion and verification
- Retain logs for compliance requirements (7 years for SOX)
Common Issues and Troubleshooting
Device Stuck in Pending Wipe
Cause: Device offline or unable to connect to Intune
Solution: Wait for device to come online, or delete device record if permanently offline
Unable to Remove Hybrid Joined Device
Cause: Device still exists in on-premises AD
Solution: Remove from on-prem AD first, wait for AAD Connect sync
User Still Signing In After Device Removal
Cause: Valid tokens not revoked
Solution: Explicitly revoke refresh tokens in addition to device removal
Intune License Still Assigned
Cause: Device record remains in Intune
Solution: Delete device from Intune portal, not just Azure AD
Automate with ADATT
Manual device management during offboarding is complex and error-prone. ADATT provides complete automation:
- ✓ Automatic device discovery across Azure AD and Intune
- ✓ Intelligent wipe selection (Selective for BYOD, Full for corporate)
- ✓ Token revocation and MFA reset in one click
- ✓ Complete audit logs for compliance
- ✓ Bulk device removal for mass terminations
- ✓ Integration with Microsoft Graph API for modern management
Simplify Azure AD Device Management
Don't leave security gaps with orphaned devices. ADATT automates complete device removal across Azure AD, Entra ID, and Intune.
Continue Reading
Intune Device Management During Employee Termination
Complete guide to managing Intune devices when employees leave. Learn about selective wipe vs full wipe, BYOD policies, and compliance requirements.
PowerShell Scripts for AD Offboarding: Free Templates for IT Admins
Ready-to-use PowerShell scripts for automating Active Directory employee terminations. Free templates with step-by-step instructions and best practices.
How to Automate Exchange Mailbox Conversion to Shared Mailbox
Learn how to convert user mailboxes to shared mailboxes in Exchange Online and On-Premises. Includes PowerShell scripts and best practices for email retention.
Automate onboarding & offboarding across Active Directory and Microsoft 365