Intune Device Management During Employee Termination

When an employee leaves your organization, properly managing their Intune-enrolled devices is critical for security and compliance. This comprehensive guide covers everything IT admins need to know about device offboarding.

Understanding Intune Device Scenarios

Corporate-Owned Devices

Devices purchased and owned by the company:

  • Corporate laptops and tablets
  • Company-issued smartphones
  • Fully managed devices
  • Recommended action: Full wipe and reuse/redeploy

BYOD (Bring Your Own Device)

Personal devices enrolled for work access:

  • Employee's personal iPhone, Android, laptop
  • Limited management scope
  • Contains personal and work data
  • Recommended action: Selective wipe only

Shared Devices

Devices used by multiple employees:

  • Warehouse scanners
  • Kiosk devices
  • Shared tablets
  • Recommended action: Remove user, keep device enrolled

Wipe Types: When to Use Each

Selective Wipe (Retire)

What it removes:

  • Company email accounts
  • Company data in managed apps
  • Work profile (Android)
  • VPN and Wi-Fi profiles
  • Certificates
  • Company apps (if deployed via Intune)

What it keeps:

  • Personal photos, contacts, apps
  • Personal files and documents
  • Device settings

Best for: BYOD devices, any device with personal data

How to perform:

Microsoft Endpoint Manager > Devices > All devices
Select device > Retire

Full Wipe

What it does:

  • Factory resets entire device
  • Removes all data and settings
  • Returns device to out-of-box state
  • Removes device from Intune enrollment

Best for: Corporate-owned devices being redeployed or decommissioned

How to perform:

Microsoft Endpoint Manager > Devices > All devices
Select device > Wipe
Check "Wipe device, and continue to wipe even if device loses power"

Warning: Cannot be undone. Device will be unusable until set up again.

Delete (Remove from Intune)

What it does:

  • Removes device record from Intune
  • Does NOT wipe any data
  • Device may still have company apps and data

Best for: Lost devices, devices already wiped manually

Warning: Only use after confirming device is physically secured or data is already removed

Step-by-Step Device Offboarding

Step 1: Identify All User Devices

In Microsoft Endpoint Manager:

  1. Devices > All devices
  2. Filter by user: Enter terminated employee's name or email
  3. Note device types: iOS, Android, Windows, macOS
  4. Check enrollment type: Corporate, BYOD, Shared
  5. Document serial numbers for corporate devices

Step 2: Physical Device Collection (Corporate Devices)

Before performing any wipe:

  • Collect device from employee on last day
  • Verify serial number matches asset inventory
  • Check for physical damage
  • Remove any SIM cards
  • Note any accessories (chargers, cases)

Important: Don't wipe corporate devices until you have them physically. This prevents data loss if employee needs to retrieve personal data.

Step 3: Execute Appropriate Wipe

For BYOD Devices:

  1. Select device in Intune
  2. Click "Retire"
  3. Confirm action
  4. Wait 10-15 minutes for command to reach device
  5. Verify completion (device status = Retired)

For Corporate Devices:

  1. Ensure device is physically secured
  2. Select device in Intune
  3. Click "Wipe"
  4. Check "Continue to wipe even if device loses power"
  5. Click "Yes" to confirm
  6. Wait for wipe to complete (can take 30+ minutes)

Step 4: Verify Wipe Completion

Check Intune Status:

  • Device status should show "Retired" or "Wiped"
  • Last check-in time should be recent
  • User assignment should be removed

Test Device (Corporate):

  • Power on device
  • Should show initial setup screen
  • No company apps or data should be present
  • Employee account should not be able to sign in

Step 5: Remove Device from Azure AD

After wipe completion:

  1. Azure AD > Devices > All devices
  2. Find terminated employee's devices
  3. Select device(s)
  4. Click "Delete"
  5. Confirm deletion

Why this step: Intune wipe doesn't always remove Azure AD registration. Manual cleanup prevents orphaned device records.

Platform-Specific Considerations

iOS/iPadOS Devices

Activation Lock:

  • If enabled, device is locked to employee's Apple ID
  • Use "Disable Activation Lock" action before wipe
  • Requires device to be supervised (corporate)

Personal vs Corporate Apple ID:

  • BYOD devices: Employee keeps their Apple ID
  • Corporate: Use managed Apple IDs or bypass code

Selective Wipe on iOS:

  • Removes work profile and managed apps
  • Personal apps and data untouched
  • iCloud data remains intact

Android Devices

Work Profile vs Device Admin:

  • Work Profile: Selective wipe removes work profile entirely
  • Device Admin: Older enrollment, less separation
  • Fully Managed: Full wipe recommended

Factory Reset Protection (FRP):

  • Google account may be required after factory reset
  • Corporate devices: Use Google Zero-Touch or manually remove accounts first

Samsung Knox:

  • Additional security layer
  • Knox container holds all work data
  • Selective wipe removes Knox container cleanly

Windows 10/11 Devices

Azure AD Join vs Hybrid Join:

  • Azure AD Joined: Full cloud management, wipe removes everything
  • Hybrid Joined: Connected to on-prem AD, may need separate AD account disable

BitLocker Keys:

  • Before wiping, verify BitLocker recovery key is escrowed in Azure AD
  • After wipe, key is automatically removed
  • Save keys for corporate devices before any actions

Windows Autopilot:

  • Device registration remains after wipe
  • Device can be redeployed automatically
  • Convenient for reusing corporate laptops

macOS Devices

User-Enrolled vs Device-Enrolled:

  • User-Enrolled (BYOD): Only selective wipe available
  • Device-Enrolled (DEP/ADE): Full wipe possible

FileVault Keys:

  • Verify recovery key is escrowed before wipe
  • Intune stores personal recovery key
  • Required to access device if FileVault enabled

Timing Considerations

When to Wipe During Termination

Immediate (Same Day):

  • BYOD devices - no physical collection needed
  • Termination for cause (security risk)
  • Remote employees who won't return devices

After Collection (1-3 Days):

  • Corporate devices collected on last day
  • Gives time to verify asset inventory
  • Allows employee to retrieve personal data (with supervision)

Delayed (7-30 Days):

  • Layoffs or friendly terminations
  • Allow time for knowledge transfer
  • Employee may need temporary access to export data

Wipe Duration

  • Selective Wipe: 5-30 minutes (next device check-in)
  • Full Wipe (iOS/Android): 10-60 minutes
  • Full Wipe (Windows): 30-120 minutes
  • Full Wipe (macOS): 30-90 minutes

Note: Device must be online and connected to internet for wipe to execute

BYOD Policy Best Practices

Document BYOD Terms Clearly

In your BYOD policy, specify:

  • What data can be accessed on personal devices
  • Company's right to perform selective wipe
  • What data will be removed upon termination
  • Personal data protection guarantees
  • No access to personal photos, messages, contacts

Enrollment Agreement

Require employees to acknowledge:

"I understand that upon enrollment, company data will be stored on my personal device. Upon termination or unenrollment, a selective wipe will remove all company data, apps, and accounts. My personal data will not be affected."

Data Separation

  • iOS: Managed apps keep work data separate
  • Android: Work Profile creates separate container
  • Windows: Windows Information Protection (WIP) isolates data

Troubleshooting Common Issues

Issue: Wipe Command Not Reaching Device

Causes:

  • Device is powered off
  • Device not connected to internet
  • Employee blocked command (Android)
  • Device enrollment expired

Solutions:

  • Wait for device to come online (check-in policy: every 8 hours default)
  • If corporate device and employee refuses to power on: Report as stolen, remote lock
  • If remote employee: Send return shipping label with instructions to power on
  • Use mobile carrier to remotely enable device (if available)

Issue: Personal Data Lost During Wipe

Prevention:

  • Always use "Retire" (selective wipe) for BYOD
  • Never use "Wipe" on personal devices
  • Test wipe process on spare device first
  • Document which wipe type was used

If it happens:

  • Check if device has cloud backup (iCloud, Google)
  • May have legal/HR implications
  • Document incident for review

Issue: Corporate Device Won't Re-Enroll

Causes:

  • Autopilot profile still assigned
  • Device still registered in Azure AD
  • Enrollment restrictions

Solutions:

  • Delete device from Azure AD
  • Remove from Autopilot (if applicable)
  • Check enrollment restrictions for device type
  • Factory reset again if needed

Compliance and Audit Logging

What to Document

For each device wipe, record:

  • Employee name and termination date
  • Device serial number and model
  • Wipe type (selective vs full)
  • Date/time wipe was initiated
  • Who initiated the wipe (IT admin name)
  • Date/time wipe confirmed complete
  • Any issues or delays

Intune Audit Logs

Access audit logs:

  1. Microsoft Endpoint Manager > Tenant administration > Audit logs
  2. Filter by Activity: "Wipe" or "Retire"
  3. Export logs monthly for compliance
  4. Retain for 7 years (varies by industry)

Compliance Requirements

GDPR:

  • Document why employee data is being retained (if any)
  • Personal device wipes must be selective only
  • Employee has right to verify data was removed

HIPAA:

  • All devices with patient data must be wiped within 24 hours
  • Document compliance with disposal policies
  • Audit logs must be retained

SOX:

  • Financial data access must be revoked immediately
  • Audit trail of all device management actions
  • 7-year retention of logs

Automate Intune Device Management

ADATT automates the entire Intune device offboarding process - identifying devices, executing appropriate wipes, and generating compliance reports.

Continue Reading

Automate onboarding & offboarding across Active Directory and Microsoft 365