Houses of Parliament Restoration & Renewal
Operational Runbook

Complete Device Removal

A definitive, ordered runbook for fully removing a Windows device that was provisioned via Autopilot, managed in Intune, and registered in Entra ID — specific to the R&R corporate environment.

Microsoft Intune · Windows Autopilot · Microsoft Entra ID Windows 10 / 11 Full Wipe — Mandatory Organisation-Owned Internal Use Only Version 1.1 Author: Koz Georgiou Next review: May 2026
Completion
0 / 6
🛑
Order is Critical — Steps Must Be Completed in Sequence
Removing the device from Entra ID before retiring it from Intune can prevent a clean wipe. Removing the Autopilot record before the Intune device record can cause the device to automatically re-enrol on its next boot. All three platforms must be cleaned in the order defined below.
Mandatory Sequence
High-Level Process Summary
1
Pre-Checks & Device ID
Intune + Entra ID
2
Wipe the Device
Intune
3
Delete Intune Record
Intune
4
Remove Autopilot Record
Intune
5
Delete Entra ID Object
Entra ID
6
Verification
All Portals
🔐
Prerequisites & Required Permissions
Intune RoleIntune Administrator or Global Administrator
Entra ID RoleCloud Device Administrator or Global Administrator
Autopilot RoleIntune Administrator (inherited via Intune)
Device InformationSerial number, Intune Device ID, and/or Entra Object ID for the target device
User CommunicationEnd user has been notified; device is available for wipe
Data BackupUser data backed up to OneDrive or equivalent before any wipe action
Change RecordAn approved change request or ticket number is available
Step 1 — Pre-Removal Checks ⏱ 10–15 min
1
Pre-Removal Checks & Device Identification
Intune + Entra ID
💡 Why is this step needed?
Before making any destructive changes, you must positively identify the correct device and record all identifiers. You will need the serial number, Intune Device ID, and Entra Object ID at every subsequent stage. Misidentifying the device could result in wiping the wrong machine — an irreversible action.

1.1 — Locate the device in Intune

#ActionNotes
1Navigate to the Intune Admin Centreintune.microsoft.com
2Select DevicesAll DevicesOr use Windows Devices for a filtered view
3Search by device name, serial number, or usernameUse the search bar at the top
4Click the device name to open the recordConfirm this is the correct device before proceeding
5Record: Device name, Intune Device ID, Serial number, Primary user UPN, Last check-in, Enrolment typeAll values from the Overview pane

1.2 — Locate the device in Entra ID

#ActionNotes
1Navigate to the Entra ID Admin Centreentra.microsoft.com
2Select DevicesAll Devices
3Search by device name or serial number
4Record: Entra Object ID, Device ID, Join type, Registration state, Compliance state
ℹ Cross-Reference Device IDs
The Device ID in Entra ID should match the Azure AD Device ID in the Intune record. If these do not match, stop and raise with your team before proceeding.
Step 2 — Wipe the Device ⏱ 2–5 min + processing
2
Wipe the Device in Microsoft Intune
intune.microsoft.com
🛑 R&R Policy — Full Wipe is Mandatory
Retire is NOT used in the R&R environment. All devices must be fully wiped prior to removal. A Wipe destroys ALL data — confirm user data has been backed up to OneDrive before proceeding. Do NOT delete the Intune record until the Wipe has completed successfully.
💡 Why is this step needed?
A full factory wipe permanently erases all data, applications, and configuration from the device. This is mandatory for all R&R corporate hardware to prevent data leakage when a device is decommissioned, reallocated, or returned. The wipe must complete before the Intune record is deleted, otherwise the device may be left in an inconsistent state with corporate data still intact.
#ActionNotes
1In Intune, navigate to Devices → All Devicesintune.microsoft.com
2Search for and select the target deviceUse the identifiers from Step 1
3From the device Overview pane, click WipeAction bar at the top of the record
4Ensure "Wipe device, but keep enrolment state" is UNCHECKEDLeaving this checked causes auto-re-enrol — must NOT be selected for decommissions
5Click Wipe to submit the actionA second confirmation dialogue will appear
6Confirm the Wipe when promptedStatus changes to Wipe Pending
7Monitor until the wipe has completedDevice must be powered on and connected to process
⚠ Offline Devices
If the device is offline, the Wipe command will be queued and executed on next network connection. If the device will never come back online (lost/stolen/decommissioned), document this in the change record, raise with your line manager, and proceed to Step 3 after a reasonable wait period.
Step 3 — Delete Intune Record ⏱ ~2 min
3
Delete the Device Record from Microsoft Intune
intune.microsoft.com
⚠ Wait for the Wipe to Complete
Only delete the Intune record after the Wipe has fully completed. Deleting the record while a wipe is still pending may leave the device in an inconsistent state with corporate data intact.
💡 Why is this step needed?
Deleting the Intune device record removes the device from Intune management entirely and releases any associated licences. However, this does NOT automatically remove the Autopilot registration — that must be deleted separately in Step 4. Leaving the Intune record would mean the device continues to consume a licence slot and appears as a managed endpoint.
#ActionNotes
1In Intune, navigate to Devices → All Devices
2Search for and select the target deviceStatus should confirm wipe completed
3Click the … menu or Delete button at the top of the record
4Confirm the delete actionThis is irreversible — double-check the correct device
5Search for the device again to confirm it no longer appearsMay take a few minutes to fully disappear
✔ Checkpoint
The device should no longer appear in Intune → Devices → All Devices. Record the completion time in your change ticket before proceeding.
Step 4 — Remove Autopilot Record ⏱ 2–3 min
4
Remove the Windows Autopilot Deployment Record
intune.microsoft.com
🛑 Critical — Always Remove the Autopilot Record
If the Autopilot record is left in place, the device will re-enrol automatically on next OOBE boot. This is a common mistake that results in devices unexpectedly re-appearing in Intune. This step is mandatory for all decommissioned Autopilot-enrolled devices.
💡 Why is this step needed?
Windows Autopilot stores a hardware hash that identifies the physical device to Microsoft's deployment service. Even after the Intune record is deleted, this hash tells Microsoft the device belongs to the R&R tenant. If the device boots into OOBE (out-of-box experience) while the Autopilot record exists, it will automatically re-register and re-enrol — effectively undoing all your removal work.
#ActionNotes
1In Intune, navigate to Devices → Enrolment → Windows → Windows AutopilotAlt path: Devices → Enrol Devices → Windows Autopilot → Devices
2Search by serial numberMost reliable key for Autopilot records
3Select the checkbox next to the target deviceDouble-check the serial number
4Click Delete at the top of the Autopilot list
5Confirm the deletionRemoves hardware hash + profile assignment
6Search again to confirm removal
ℹ Sync After Deletion
After removing the Autopilot record, click Sync at the top of the Autopilot Devices list. This forces a synchronisation with the Microsoft Deployment Service to ensure the record is purged.
✔ Checkpoint
The device serial number should no longer appear in the Autopilot Devices list. Record the completion time in your change ticket.
Step 5 — Delete Entra ID Object ⏱ 2–3 min
5
Delete the Device Object from Microsoft Entra ID
entra.microsoft.com
⚠ Entra ID Deletion is the Last Platform Step
Only delete the Entra ID device object after Steps 2, 3, and 4 are complete. Deleting the Entra ID object before the Intune record is removed can orphan the Intune record and prevent a clean wipe.
💡 Why is this step needed?
The Entra ID device object is the identity anchor for the device across all Microsoft 365 services. It controls Conditional Access compliance states, device-based policies, and authentication trust. Deleting it removes the device identity from the directory, disables any associated Conditional Access evaluations, and ensures the device cannot authenticate to cloud resources as a trusted corporate endpoint.
🔑 BitLocker Recovery Keys — Check Before Deleting
Before deleting, check whether BitLocker recovery keys are stored against the device object. Navigate to Recovery Keys in the device record. If keys are present, export and store them in your ITSM/change record. Keys will be permanently deleted when the device object is removed.
#ActionNotes
1Navigate to the Entra ID Admin Centreentra.microsoft.com
2Select Devices → All Devices
3Search by device name or Device IDUse the Entra Object ID from Step 1
4Click the device name, verify Device ID, serial, and join type
5Click Delete (or via the … menu)This action is irreversible
6Confirm the deleteObject and all attributes permanently removed
7Return to All Devices and confirm removal
ℹ Soft Delete in Entra ID
Deleted device objects remain in the Deleted Devices view for up to 30 days. They cannot re-register during this period but can be restored if needed. After 30 days the object is permanently purged.
✔ Checkpoint
The device should no longer appear in Entra ID → Devices → All Devices. The completed Wipe, deleted Intune record, removed Autopilot registration, and deleted Entra ID object together confirm full removal.
Step 6 — Post-Removal Verification ⏱ 5–10 min
6
Post-Removal Verification Checks
All Portals
💡 Why is this step needed?
Verification is the final assurance that the device has been fully and cleanly removed from all three platforms. Orphaned records in any platform can cause licence waste, compliance reporting inaccuracies, Conditional Access policy conflicts, or unexpected device re-enrolment. All checks must pass before the change record can be closed.
IDVerification CheckWhere to Verify
V1Device not found in Intune → Devices → All DevicesIntune Admin Centre
V2Autopilot record not found by serial numberIntune → Enrolment → Autopilot Devices
V3Device not found in Entra ID → Devices → All DevicesEntra ID Admin Centre
V4Primary user's device list no longer shows this deviceEntra ID → Users → [user] → Devices
V5BitLocker keys exported and stored (if applicable)Change record / ITSM ticket
V6No orphaned Conditional Access policy assignments remainEntra ID → Security → Conditional Access
V7Device licence released (if applicable)Intune → Devices → Monitor → Licences
✔ Removal Complete
All verification checks must show Pass before the change record is closed. Update your ITSM ticket with completion timestamps for all six steps. Retain the completed runbook record for audit purposes.
🔧
Troubleshooting & Escalation
IssueProbable CauseResolution
Delete button greyed out in Intune Device status is still active or a wipe is pending Wait for the Wipe to complete. Contact L2 if status does not update.
Device re-appears in Intune after deletion Autopilot record was not removed; device booted into OOBE Immediately remove the Autopilot record (Step 4) and delete the new Intune record.
Autopilot device not found by serial number Not registered via Autopilot, or record already removed Search by device name or hash. If not found, proceed to Step 5.
Cannot delete Entra ID device — permission denied Account lacks Cloud Device Administrator role Ensure your account has Cloud Device Administrator in Entra ID → Roles.
Device still visible in Entra ID after deletion Replication delay; soft-deleted objects visible for 30 days Check Deleted Devices view. Permanently delete from there if required.
Wipe command stuck on Wipe Pending Device is offline or powered down Confirm if device can be powered on. If permanently offline, document and proceed.
Escalation Path:L2 Endpoint/Intune — Wipe or delete issues  →  L2 Identity/Entra — Entra ID object issues  →  Microsoft Support — Persistent sync, Autopilot hash conflicts, portal errors