Intune Device Management During Employee Termination
When an employee leaves your organization, properly managing their Intune-enrolled devices is critical for security and compliance. This comprehensive guide covers everything IT admins need to know about device offboarding.
Understanding Intune Device Scenarios
Corporate-Owned Devices
Devices purchased and owned by the company:
- Corporate laptops and tablets
- Company-issued smartphones
- Fully managed devices
- Recommended action: Full wipe and reuse/redeploy
BYOD (Bring Your Own Device)
Personal devices enrolled for work access:
- Employee's personal iPhone, Android, laptop
- Limited management scope
- Contains personal and work data
- Recommended action: Selective wipe only
Shared Devices
Devices used by multiple employees:
- Warehouse scanners
- Kiosk devices
- Shared tablets
- Recommended action: Remove user, keep device enrolled
Wipe Types: When to Use Each
Selective Wipe (Retire)
What it removes:
- Company email accounts
- Company data in managed apps
- Work profile (Android)
- VPN and Wi-Fi profiles
- Certificates
- Company apps (if deployed via Intune)
What it keeps:
- Personal photos, contacts, apps
- Personal files and documents
- Device settings
Best for: BYOD devices, any device with personal data
How to perform:
Microsoft Endpoint Manager > Devices > All devices
Select device > Retire
Full Wipe
What it does:
- Factory resets entire device
- Removes all data and settings
- Returns device to out-of-box state
- Removes device from Intune enrollment
Best for: Corporate-owned devices being redeployed or decommissioned
How to perform:
Microsoft Endpoint Manager > Devices > All devices
Select device > Wipe
Check "Wipe device, and continue to wipe even if device loses power"
Warning: Cannot be undone. Device will be unusable until set up again.
Delete (Remove from Intune)
What it does:
- Removes device record from Intune
- Does NOT wipe any data
- Device may still have company apps and data
Best for: Lost devices, devices already wiped manually
Warning: Only use after confirming device is physically secured or data is already removed
Step-by-Step Device Offboarding
Step 1: Identify All User Devices
In Microsoft Endpoint Manager:
- Devices > All devices
- Filter by user: Enter terminated employee's name or email
- Note device types: iOS, Android, Windows, macOS
- Check enrollment type: Corporate, BYOD, Shared
- Document serial numbers for corporate devices
Step 2: Physical Device Collection (Corporate Devices)
Before performing any wipe:
- Collect device from employee on last day
- Verify serial number matches asset inventory
- Check for physical damage
- Remove any SIM cards
- Note any accessories (chargers, cases)
Important: Don't wipe corporate devices until you have them physically. This prevents data loss if employee needs to retrieve personal data.
Step 3: Execute Appropriate Wipe
For BYOD Devices:
- Select device in Intune
- Click "Retire"
- Confirm action
- Wait 10-15 minutes for command to reach device
- Verify completion (device status = Retired)
For Corporate Devices:
- Ensure device is physically secured
- Select device in Intune
- Click "Wipe"
- Check "Continue to wipe even if device loses power"
- Click "Yes" to confirm
- Wait for wipe to complete (can take 30+ minutes)
Step 4: Verify Wipe Completion
Check Intune Status:
- Device status should show "Retired" or "Wiped"
- Last check-in time should be recent
- User assignment should be removed
Test Device (Corporate):
- Power on device
- Should show initial setup screen
- No company apps or data should be present
- Employee account should not be able to sign in
Step 5: Remove Device from Azure AD
After wipe completion:
- Azure AD > Devices > All devices
- Find terminated employee's devices
- Select device(s)
- Click "Delete"
- Confirm deletion
Why this step: Intune wipe doesn't always remove Azure AD registration. Manual cleanup prevents orphaned device records.
Platform-Specific Considerations
iOS/iPadOS Devices
Activation Lock:
- If enabled, device is locked to employee's Apple ID
- Use "Disable Activation Lock" action before wipe
- Requires device to be supervised (corporate)
Personal vs Corporate Apple ID:
- BYOD devices: Employee keeps their Apple ID
- Corporate: Use managed Apple IDs or bypass code
Selective Wipe on iOS:
- Removes work profile and managed apps
- Personal apps and data untouched
- iCloud data remains intact
Android Devices
Work Profile vs Device Admin:
- Work Profile: Selective wipe removes work profile entirely
- Device Admin: Older enrollment, less separation
- Fully Managed: Full wipe recommended
Factory Reset Protection (FRP):
- Google account may be required after factory reset
- Corporate devices: Use Google Zero-Touch or manually remove accounts first
Samsung Knox:
- Additional security layer
- Knox container holds all work data
- Selective wipe removes Knox container cleanly
Windows 10/11 Devices
Azure AD Join vs Hybrid Join:
- Azure AD Joined: Full cloud management, wipe removes everything
- Hybrid Joined: Connected to on-prem AD, may need separate AD account disable
BitLocker Keys:
- Before wiping, verify BitLocker recovery key is escrowed in Azure AD
- After wipe, key is automatically removed
- Save keys for corporate devices before any actions
Windows Autopilot:
- Device registration remains after wipe
- Device can be redeployed automatically
- Convenient for reusing corporate laptops
macOS Devices
User-Enrolled vs Device-Enrolled:
- User-Enrolled (BYOD): Only selective wipe available
- Device-Enrolled (DEP/ADE): Full wipe possible
FileVault Keys:
- Verify recovery key is escrowed before wipe
- Intune stores personal recovery key
- Required to access device if FileVault enabled
Timing Considerations
When to Wipe During Termination
Immediate (Same Day):
- BYOD devices - no physical collection needed
- Termination for cause (security risk)
- Remote employees who won't return devices
After Collection (1-3 Days):
- Corporate devices collected on last day
- Gives time to verify asset inventory
- Allows employee to retrieve personal data (with supervision)
Delayed (7-30 Days):
- Layoffs or friendly terminations
- Allow time for knowledge transfer
- Employee may need temporary access to export data
Wipe Duration
- Selective Wipe: 5-30 minutes (next device check-in)
- Full Wipe (iOS/Android): 10-60 minutes
- Full Wipe (Windows): 30-120 minutes
- Full Wipe (macOS): 30-90 minutes
Note: Device must be online and connected to internet for wipe to execute
BYOD Policy Best Practices
Document BYOD Terms Clearly
In your BYOD policy, specify:
- What data can be accessed on personal devices
- Company's right to perform selective wipe
- What data will be removed upon termination
- Personal data protection guarantees
- No access to personal photos, messages, contacts
Enrollment Agreement
Require employees to acknowledge:
"I understand that upon enrollment, company data will be stored on my personal device. Upon termination or unenrollment, a selective wipe will remove all company data, apps, and accounts. My personal data will not be affected."
Data Separation
- iOS: Managed apps keep work data separate
- Android: Work Profile creates separate container
- Windows: Windows Information Protection (WIP) isolates data
Troubleshooting Common Issues
Issue: Wipe Command Not Reaching Device
Causes:
- Device is powered off
- Device not connected to internet
- Employee blocked command (Android)
- Device enrollment expired
Solutions:
- Wait for device to come online (check-in policy: every 8 hours default)
- If corporate device and employee refuses to power on: Report as stolen, remote lock
- If remote employee: Send return shipping label with instructions to power on
- Use mobile carrier to remotely enable device (if available)
Issue: Personal Data Lost During Wipe
Prevention:
- Always use "Retire" (selective wipe) for BYOD
- Never use "Wipe" on personal devices
- Test wipe process on spare device first
- Document which wipe type was used
If it happens:
- Check if device has cloud backup (iCloud, Google)
- May have legal/HR implications
- Document incident for review
Issue: Corporate Device Won't Re-Enroll
Causes:
- Autopilot profile still assigned
- Device still registered in Azure AD
- Enrollment restrictions
Solutions:
- Delete device from Azure AD
- Remove from Autopilot (if applicable)
- Check enrollment restrictions for device type
- Factory reset again if needed
Compliance and Audit Logging
What to Document
For each device wipe, record:
- Employee name and termination date
- Device serial number and model
- Wipe type (selective vs full)
- Date/time wipe was initiated
- Who initiated the wipe (IT admin name)
- Date/time wipe confirmed complete
- Any issues or delays
Intune Audit Logs
Access audit logs:
- Microsoft Endpoint Manager > Tenant administration > Audit logs
- Filter by Activity: "Wipe" or "Retire"
- Export logs monthly for compliance
- Retain for 7 years (varies by industry)
Compliance Requirements
GDPR:
- Document why employee data is being retained (if any)
- Personal device wipes must be selective only
- Employee has right to verify data was removed
HIPAA:
- All devices with patient data must be wiped within 24 hours
- Document compliance with disposal policies
- Audit logs must be retained
SOX:
- Financial data access must be revoked immediately
- Audit trail of all device management actions
- 7-year retention of logs
Automate Intune Device Management
ADATT automates the entire Intune device offboarding process - identifying devices, executing appropriate wipes, and generating compliance reports.
Continue Reading
Azure AD Device Removal Best Practices for Employee Offboarding
Comprehensive guide to removing Azure AD and Intune devices during employee termination. Learn about device types, removal methods, and security implications.
PowerShell Scripts for AD Offboarding: Free Templates for IT Admins
Ready-to-use PowerShell scripts for automating Active Directory employee terminations. Free templates with step-by-step instructions and best practices.
How to Automate Exchange Mailbox Conversion to Shared Mailbox
Learn how to convert user mailboxes to shared mailboxes in Exchange Online and On-Premises. Includes PowerShell scripts and best practices for email retention.
Automate onboarding & offboarding across Active Directory and Microsoft 365