Open Entra ID › Devices › All devices in a tenant that has been around for a few years and you will usually find the same laptop listed twice, hybrid joined objects stuck on Pending, and a long tail of devices nobody has seen since a reimage. These leftovers are not just untidy: they make device-based Conditional Access unpredictable and send your helpdesk chasing the wrong object. In this post I'll explain where each kind of leftover comes from, how to spot it from the device and from the portal, and how to clean up without breaking the devices that are still in use.
Symptoms#
- One device name appears twice in the devices list: once with join type Microsoft Entra hybrid joined and once as Microsoft Entra registered (the second one usually has a user as owner).
- Hybrid joined devices show Pending in the Registered column and never get a timestamp.
- Conditional Access policies that require a compliant or hybrid joined device pass on one day and fail on the next for the same user and PC, or users see You can't get there from here.
- Intune reports the device as compliant, but the sign-in log shows a different device ID than the one Intune manages.
- Users on perfectly healthy PCs are told Your organization has deleted the device and are asked to sign in again.
- On the device,
dsregcmd /statusshowsAzureAdJoined : YESandDomainJoined : YES, and in the User State section alsoWorkplaceJoined : YES.
Why it happens#
Windows can hold three different relationships with Microsoft Entra ID, and the directory records each of them as a separate device object with its own trustType value:
| State | trustType in Entra ID | What dsregcmd shows | How it is created |
|---|---|---|---|
| Microsoft Entra joined | AzureAD | AzureAdJoined : YES, DomainJoined : NO | OOBE or Settings, Autopilot |
| Microsoft Entra hybrid joined | ServerAD | AzureAdJoined : YES, DomainJoined : YES | Domain join plus the SCP and the Automatic-Device-Join scheduled task |
| Microsoft Entra registered | Workplace | WorkplaceJoined : YES in User State (per user profile) | Adding a work account to Windows or an app |
Dual state. The registered state is per user and is created the moment someone signs in to an app on a domain-joined PC and answers Yes to the prompt about adding the account to Windows. If you switch on hybrid join afterwards, the same physical device ends up with two identities. Microsoft says hybrid join normally wins during authentication and Conditional Access evaluation, but also that the dual state can make device evaluation nondeterministic and cause access problems, which is exactly the intermittent behaviour above. Since Windows 10 1803 (with KB4489894) Windows removes the registered state for a domain user automatically after the device becomes hybrid joined and that user signs in; it does nothing for local accounts, it cleans up one user at a time, and the Entra object is not deleted immediately when the device is Intune managed.
Pending. The pending state only exists for hybrid join. Microsoft Entra Connect creates the device object first; the device then completes registration against the Device Registration Service and the Registered column gets a date. It stays on Pending when registration never succeeds (connectivity, SCP, federation), or when the object was deleted in Entra ID and re-synced, typically after the computer was moved out of and back into the sync scope. In the second case the device believes it is already registered and never retries.
Duplicates. Microsoft documents three sources: repeated unjoin and rejoin of the same PC, every Windows user who adds a work account creating their own record with the same device name, and a wiped-and-reinstalled device rejoining under its old name. A stale copy keeps its BitLocker keys and its compliance history, which is why a hasty deletion hurts.
How to fix it#
1. Build an inventory#
In Entra ID › Devices › All devices, filter by Join type and Activity, add the Registered column and use Download devices for a CSV; the export carries trustType, registrationDateTime and approximateLastSignInDateTime. For duplicates, Graph PowerShell is quicker:
# Sign in with an account that holds Cloud Device Administrator or Intune Administrator
Connect-MgGraph
Get-MgDevice -All -Property DisplayName,TrustType,ApproximateLastSignInDateTime,AccountEnabled,DeviceId |
Group-Object DisplayName | Where-Object Count -gt 1 |
ForEach-Object { $_.Group | Select-Object DisplayName,TrustType,ApproximateLastSignInDateTime,DeviceId }
# Hybrid joined objects still waiting for the client (Pending)
Get-MgDevice -All -Filter "TrustType eq 'ServerAd'" |
Where-Object { -not $_.AlternativeSecurityIds } |
Select-Object DisplayName,DeviceId,OperatingSystemVersion2. Confirm the state on the device#
Run dsregcmd /status as the signed-in user, not from an elevated prompt, otherwise the user-state fields are not reliable. A hybrid joined device with WorkplaceJoined : YES is in dual state. Note the DeviceId under Device Details and compare it with the IDs you exported: the object with that ID is the one Conditional Access should be evaluating.
3. Remove the registered state#
On the PC, go to Settings › Accounts › Access work or school, select the work account that shows as connected and choose Disconnect. This is per user profile, so repeat it for every profile that registered. Do not touch the entry that represents the domain or hybrid join. Then delete the matching Microsoft Entra registered object from the devices list. If that registration also carried an Intune enrollment, retire it in Intune first; Microsoft notes that removing the registered state on 1803 and later unenrols an auto-enrolled device anyway.
4. Clear Pending objects#
From an elevated prompt run dsregcmd /leave, restart, and sign in. The Automatic-Device-Join task under Task Scheduler Library › Microsoft › Windows › Workplace Join re-registers the device and the Pending object becomes the real one. If the diagnostics block of dsregcmd /status reports a failing test instead, fix that first: an AD Configuration Test failure points at the SCP, a DRS Connectivity Test failure at the proxy or firewall.
5. Retire the genuinely stale objects#
Follow Microsoft's disable-then-delete pattern and factor in that the activity timestamp is only refreshed when it is more than 14 days old (plus or minus 5 days), so nothing younger than about 21 days should count as stale. Hybrid joined objects should be disabled or deleted in on-premises AD and allowed to sync; deleting them in Entra ID alone just brings them back as Pending. Retire Intune-managed devices in Intune first, never delete Autopilot (system-managed) devices, and copy any BitLocker keys you may still need.
$cutoff = (Get-Date).AddDays(-120)
Get-MgDevice -All | Where-Object {
$_.ApproximateLastSignInDateTime -le $cutoff -and $_.TrustType -eq 'Workplace' -and $_.AccountEnabled -eq $false
} | ForEach-Object { Remove-MgDevice -DeviceId $_.Id }Watch out: Remove-MgDevice does not prompt and deletion is not reversible. Entra device soft delete entered public preview in May 2026 and may give you a recovery window in your tenant, but do not plan on it until you have confirmed it is enabled.
Verify the fix#
dsregcmd /statuson the device:AzureAdJoined : YES,DomainJoined : YES,WorkplaceJoined : NO,AzureAdPrt : YESandDeviceAuthStatus : SUCCESS.- In the devices list the name appears once, with join type Microsoft Entra hybrid joined and a date in Registered.
- In Entra ID › Monitoring & health › Sign-in logs, open a recent sign-in and check the Device info tab: the device ID matches the surviving object and the join type is what your Conditional Access policy expects.
- Intune shows the device compliant and Managed by Intune, and the Conditional Access policy result reads Success.
Prevent it next time#
- Stop domain-joined PCs from getting registered in the first place with the policy registry value
HKLM\SOFTWARE\Policies\Microsoft\Windows\WorkplaceJoin,BlockAADWorkplaceJoin=1(REG_DWORD). It also blocks users from adding extra work accounts on corporate devices. - Keep Windows current so the automatic dual-state clean-up runs, and remember it never touches local accounts.
- Keep the Entra Connect OU filter stable; every move out of scope deletes the object and every move back creates a Pending one.
- Use
device.trustTypein Conditional Access device filters deliberately:ServerAD,AzureADandWorkplaceare evaluated against whichever object authenticates, so clean data matters more than clever rules. - Schedule the stale-device script as a monthly job with a disable grace period rather than running it once a year.