Offboarding
Offboarding Device - Windows
In case, Windows corporate owned device has been sold, donated or recycled as e-waste.
Windows Autopilot devices and Active Directory Computers:
- Intune Admin Center > Devices > Windows > Find device in search and select it> Select Retire/Wipe
- Disable Computer object in Active Directory and move to Disabled OU if exists
- Remove from Windows Autopilot Devices > Intune Admin Center, Devices > Enrollment > Windows Autopilot > Devices > Select Device> Delete
- Reinstall Windows OS or use Reset this PC option in System > Recovery in Windows to be ready for future use of the new owner, select to remove all existing files.
Offboarding Device - Android Corporate-owned, Fully managed user devices
In case, Android corporate owned device has been sold, or recycled.
- Go to Intune > Devices > Android > Device > Wipe > Yes
- Check if device has been removed from Intune
Offboarding Device - Android Personally-owned devices with work profile
In case, Android personal owned device has been stolen or removed, and user did not initiate retire itself using Intune Company Portal Web App.
- Go to Intune > Apps > Android > App selective Wipe > Create Wipe Request > Select User > Select Device > Create Request
- Go to Intune > Device > Retire > Yes
- Check if device has been removed from Intune
Offboarding Device - iOS web based enrollment
In case, iOS device has been stolen or removed, and user did not initiate retire itself using Intune Company Portal Web App.
- Go to Intune > Apps > iOS> App selective Wipe > Create Wipe Request > Select User > Select Device > Create Request
- Go to Intune > Device > Retire> Yes
Offboarding Device - macOS
In case, Windows corporate owned device has been sold, or recycled.
- Intune Admin Center > Devices > Windows > Find device in search and select it> Select Retire/Wipe
Pre-Offboarding user
In case a user is leaving the organization and is on a notice period, still working. Apply as needed.
- Enable Exchange mailbox Litigation Hold for 60 days
Offboarding user
-
If having Exchange Online mailbox
- Remove future calendar events inside mailbox
- Set mailbox type to shared
- If cloud only, hide in HAL
- If needed, set Message forwarding to another user
- Otherwise, if no forwarding, configure message delivery restrictions to self only
-
If have Windows Server Active Directory
- Disable user account login
- Remove Manager
- Remove user from all AD groups
- Clear all proxyAddresses (if no email forwarding previously set)
- Hide in GAL
- Start Domain Controller sync/replication
- Start Microsoft Entra Connect sync
-
If Microsoft Entra cloud only user
- Disable user account login
- Remove Manager
- Hide in GAL
- Rename user to initial .onmicrosoft domain
- Remove old email address from other domains in Mailbox proxyAddress (if no email forwarding previously set)
-
Revoke sign in sessions
-
Microsoft Intune Retire Android and iOS devices of the user
-
Remove from Microsoft Entra roles
-
Remove from Microsoft Entra Groups and Exchange distribution and mail-enabled security groups
-
Remove direct assigned User licenses
-
Microsoft Intune - Remote wipe and reinstall device:
- Personally-owned phone - Retire (The Retire action removes managed app data (where applicable), settings, and email profiles that were assigned by using Intune. The device is removed from Intune management.)
- Corporate owned phone - Wipe (The Wipe action restores a device to its factory default settings. The user data is kept if you choose the Retain enrollment state and user account checkbox. Otherwise, all data, apps, and settings will be removed.)
- Corporate owned laptop/PC - Retire/Wipe