Step 1 — Pre-Removal Checks
⏱ 10–15 min
1
Pre-Removal Checks & Device Identification
Intune + Entra ID
▼
💡 Why is this step needed?
Before making any destructive changes, you must positively identify the correct device and record all identifiers. You will need the serial number, Intune Device ID, and Entra Object ID at every subsequent stage. Misidentifying the device could result in wiping the wrong machine — an irreversible action.
1.1 — Locate the device in Intune
| # | Action | Notes |
|---|---|---|
| 1 | Navigate to the Intune Admin Centre | intune.microsoft.com |
| 2 | Select Devices → All Devices | Or use Windows Devices for a filtered view |
| 3 | Search by device name, serial number, or username | Use the search bar at the top |
| 4 | Click the device name to open the record | Confirm this is the correct device before proceeding |
| 5 | Record: Device name, Intune Device ID, Serial number, Primary user UPN, Last check-in, Enrolment type | All values from the Overview pane |
1.2 — Locate the device in Entra ID
| # | Action | Notes |
|---|---|---|
| 1 | Navigate to the Entra ID Admin Centre | entra.microsoft.com |
| 2 | Select Devices → All Devices | |
| 3 | Search by device name or serial number | |
| 4 | Record: Entra Object ID, Device ID, Join type, Registration state, Compliance state |
ℹ Cross-Reference Device IDs
The Device ID in Entra ID should match the Azure AD Device ID in the Intune record. If these do not match, stop and raise with your team before proceeding.
Step 2 — Wipe the Device
⏱ 2–5 min + processing
2
Wipe the Device in Microsoft Intune
intune.microsoft.com
▼
🛑 R&R Policy — Full Wipe is Mandatory
Retire is NOT used in the R&R environment. All devices must be fully wiped prior to removal. A Wipe destroys ALL data — confirm user data has been backed up to OneDrive before proceeding. Do NOT delete the Intune record until the Wipe has completed successfully.
💡 Why is this step needed?
A full factory wipe permanently erases all data, applications, and configuration from the device. This is mandatory for all R&R corporate hardware to prevent data leakage when a device is decommissioned, reallocated, or returned. The wipe must complete before the Intune record is deleted, otherwise the device may be left in an inconsistent state with corporate data still intact.
| # | Action | Notes |
|---|---|---|
| 1 | In Intune, navigate to Devices → All Devices | intune.microsoft.com |
| 2 | Search for and select the target device | Use the identifiers from Step 1 |
| 3 | From the device Overview pane, click Wipe | Action bar at the top of the record |
| 4 | Ensure "Wipe device, but keep enrolment state" is UNCHECKED | Leaving this checked causes auto-re-enrol — must NOT be selected for decommissions |
| 5 | Click Wipe to submit the action | A second confirmation dialogue will appear |
| 6 | Confirm the Wipe when prompted | Status changes to Wipe Pending |
| 7 | Monitor until the wipe has completed | Device must be powered on and connected to process |
⚠ Offline Devices
If the device is offline, the Wipe command will be queued and executed on next network connection. If the device will never come back online (lost/stolen/decommissioned), document this in the change record, raise with your line manager, and proceed to Step 3 after a reasonable wait period.
Step 3 — Delete Intune Record
⏱ ~2 min
3
Delete the Device Record from Microsoft Intune
intune.microsoft.com
▼
⚠ Wait for the Wipe to Complete
Only delete the Intune record after the Wipe has fully completed. Deleting the record while a wipe is still pending may leave the device in an inconsistent state with corporate data intact.
💡 Why is this step needed?
Deleting the Intune device record removes the device from Intune management entirely and releases any associated licences. However, this does NOT automatically remove the Autopilot registration — that must be deleted separately in Step 4. Leaving the Intune record would mean the device continues to consume a licence slot and appears as a managed endpoint.
| # | Action | Notes |
|---|---|---|
| 1 | In Intune, navigate to Devices → All Devices | |
| 2 | Search for and select the target device | Status should confirm wipe completed |
| 3 | Click the … menu or Delete button at the top of the record | |
| 4 | Confirm the delete action | This is irreversible — double-check the correct device |
| 5 | Search for the device again to confirm it no longer appears | May take a few minutes to fully disappear |
✔ Checkpoint
The device should no longer appear in Intune → Devices → All Devices. Record the completion time in your change ticket before proceeding.
Step 4 — Remove Autopilot Record
⏱ 2–3 min
4
Remove the Windows Autopilot Deployment Record
intune.microsoft.com
▼
🛑 Critical — Always Remove the Autopilot Record
If the Autopilot record is left in place, the device will re-enrol automatically on next OOBE boot. This is a common mistake that results in devices unexpectedly re-appearing in Intune. This step is mandatory for all decommissioned Autopilot-enrolled devices.
💡 Why is this step needed?
Windows Autopilot stores a hardware hash that identifies the physical device to Microsoft's deployment service. Even after the Intune record is deleted, this hash tells Microsoft the device belongs to the R&R tenant. If the device boots into OOBE (out-of-box experience) while the Autopilot record exists, it will automatically re-register and re-enrol — effectively undoing all your removal work.
| # | Action | Notes |
|---|---|---|
| 1 | In Intune, navigate to Devices → Enrolment → Windows → Windows Autopilot | Alt path: Devices → Enrol Devices → Windows Autopilot → Devices |
| 2 | Search by serial number | Most reliable key for Autopilot records |
| 3 | Select the checkbox next to the target device | Double-check the serial number |
| 4 | Click Delete at the top of the Autopilot list | |
| 5 | Confirm the deletion | Removes hardware hash + profile assignment |
| 6 | Search again to confirm removal |
ℹ Sync After Deletion
After removing the Autopilot record, click Sync at the top of the Autopilot Devices list. This forces a synchronisation with the Microsoft Deployment Service to ensure the record is purged.
✔ Checkpoint
The device serial number should no longer appear in the Autopilot Devices list. Record the completion time in your change ticket.
Step 5 — Delete Entra ID Object
⏱ 2–3 min
5
Delete the Device Object from Microsoft Entra ID
entra.microsoft.com
▼
⚠ Entra ID Deletion is the Last Platform Step
Only delete the Entra ID device object after Steps 2, 3, and 4 are complete. Deleting the Entra ID object before the Intune record is removed can orphan the Intune record and prevent a clean wipe.
💡 Why is this step needed?
The Entra ID device object is the identity anchor for the device across all Microsoft 365 services. It controls Conditional Access compliance states, device-based policies, and authentication trust. Deleting it removes the device identity from the directory, disables any associated Conditional Access evaluations, and ensures the device cannot authenticate to cloud resources as a trusted corporate endpoint.
🔑 BitLocker Recovery Keys — Check Before Deleting
Before deleting, check whether BitLocker recovery keys are stored against the device object. Navigate to Recovery Keys in the device record. If keys are present, export and store them in your ITSM/change record. Keys will be permanently deleted when the device object is removed.
| # | Action | Notes |
|---|---|---|
| 1 | Navigate to the Entra ID Admin Centre | entra.microsoft.com |
| 2 | Select Devices → All Devices | |
| 3 | Search by device name or Device ID | Use the Entra Object ID from Step 1 |
| 4 | Click the device name, verify Device ID, serial, and join type | |
| 5 | Click Delete (or via the … menu) | This action is irreversible |
| 6 | Confirm the delete | Object and all attributes permanently removed |
| 7 | Return to All Devices and confirm removal |
ℹ Soft Delete in Entra ID
Deleted device objects remain in the Deleted Devices view for up to 30 days. They cannot re-register during this period but can be restored if needed. After 30 days the object is permanently purged.
✔ Checkpoint
The device should no longer appear in Entra ID → Devices → All Devices. The completed Wipe, deleted Intune record, removed Autopilot registration, and deleted Entra ID object together confirm full removal.
Step 6 — Post-Removal Verification
⏱ 5–10 min
6
Post-Removal Verification Checks
All Portals
▼
💡 Why is this step needed?
Verification is the final assurance that the device has been fully and cleanly removed from all three platforms. Orphaned records in any platform can cause licence waste, compliance reporting inaccuracies, Conditional Access policy conflicts, or unexpected device re-enrolment. All checks must pass before the change record can be closed.
| ID | Verification Check | Where to Verify |
|---|---|---|
| V1 | Device not found in Intune → Devices → All Devices | Intune Admin Centre |
| V2 | Autopilot record not found by serial number | Intune → Enrolment → Autopilot Devices |
| V3 | Device not found in Entra ID → Devices → All Devices | Entra ID Admin Centre |
| V4 | Primary user's device list no longer shows this device | Entra ID → Users → [user] → Devices |
| V5 | BitLocker keys exported and stored (if applicable) | Change record / ITSM ticket |
| V6 | No orphaned Conditional Access policy assignments remain | Entra ID → Security → Conditional Access |
| V7 | Device licence released (if applicable) | Intune → Devices → Monitor → Licences |
✔ Removal Complete
All verification checks must show Pass before the change record is closed. Update your ITSM ticket with completion timestamps for all six steps. Retain the completed runbook record for audit purposes.