IntuneHow-to

Keeping Intune tidy: device cleanup rules and stale device hygiene

How Intune device cleanup rules work per platform, what they hide and what they leave behind, and how to pair them with a safe Entra ID stale-device routine that spares Autopilot.

Old laptops, replaced phones and abandoned enrollments pile up in Intune and quietly skew every report. Device cleanup rules handle the Intune side automatically, but they don't touch Microsoft Entra ID or Windows Autopilot. In this post I'll set up per-platform rules, then add an Entra ID routine that disables before it deletes and leaves Autopilot devices alone.

How this guide is organised: How it works → Prerequisites → Step-by-step → Verify → Tips & gotchasFlow diagram of the article's sections in reading order: 1. How it works. 2. Prerequisites. 3. Step-by-step (5 steps: Decide your thresholds; Create the cleanup rules; Check what the rule did; Clean up Microsoft Entra ID separately; Treat Autopilot devices differently). 4. Verify. 5. Tips & gotchas. Toolbox: Remove-MgDevice, Devices › All devices, Device.Read.All, Directory.AccessAsUser.All, ApproximateLastSignInDateTime.1How it works2Prerequisites3Step-by-step4Verify5Tips & gotchas1Decide yourthresholds2Create the cleanuprules3Check what therule did4Clean up MicrosoftEntra ID separately5Treat Autopilotdevices differentlyTOOLBOXRemove-MgDeviceDevices › All devicesDevice.Read.AllDirectory.AccessAsUser.AllApproximateLastSignInDateTimeHow this guide is organised: How it works → Prerequisites → Step-by-step → Verify → Tips & gotchasFlow diagram of the article's sections in reading order: 1. How it works. 2. Prerequisites. 3. Step-by-step (5 steps: Decide your thresholds; Create the cleanup rules; Check what the rule did; Clean up Microsoft Entra ID separately; Treat Autopilot devices differently). 4. Verify. 5. Tips & gotchas. Toolbox: Remove-MgDevice, Devices › All devices, Device.Read.All, Directory.AccessAsUser.All, ApproximateLastSignInDateTime.1How it works2Prerequisites3Step-by-step1Decide your thresholds2Create the cleanup rules3Check what the rule did4Clean up Microsoft Entra ID separately5Treat Autopilot devices differently4Verify5Tips & gotchasTOOLBOXRemove-MgDeviceDevices › All devicesDevice.Read.AllDirectory.AccessAsUser.AllApproximateLastSignInDateTime
At a glance: how this guide is organised · 5 steps · 5 key settings and tools

How it works#

A cleanup rule runs on a schedule and hides devices that haven't checked in with Intune for a set number of days, anywhere from 30 to 270. You can create one rule per platform (Windows, Windows Holographic, macOS, iOS/iPadOS, tvOS, visionOS, ChromeOS and four Android management types) plus an All platforms rule. Where both apply, the rule with fewer days wins.

ObjectWhat a cleanup rule does to it
Intune device recordHides it from the admin center and reports
The device itselfNothing: no wipe, no retire
Microsoft Entra ID device objectNothing, so BitLocker keys stored on it stay too
Windows Autopilot registrationNothing

A hidden device reappears if it checks in before its device certificate expires; after that, it has to enroll again. Cleanup rules aren't available for Jamf-managed devices.

Prerequisites#

  • Intune Administrator, or a custom role with Managed Device Cleanup Rules/Update, Managed Device Cleanup Settings/Update and read access to managed devices.
  • For the Entra ID part: the Cloud Device Administrator or Intune Administrator role and the Microsoft Graph PowerShell SDK (the Microsoft.Graph.Identity.DirectoryManagement and Microsoft.Graph.DeviceManagement.Enrollment modules). Reading needs Device.Read.All and, for the Autopilot list, DeviceManagementServiceConfig.Read.All. Disabling and deleting with a signed-in admin uses Directory.AccessAsUser.All.

Step-by-step#

1. Decide your thresholds#

These are my starting points, not Microsoft defaults:

LayerSuggested thresholdWhy
Cleanup rule: Windows and macOS90 daysCovers long leave and travel
Cleanup rule: iOS/iPadOS and Android60 to 90 daysPhones that go quiet for that long have usually been replaced
Entra ID: disable90 days without activityLines up with the Intune rule
Entra ID: deleteAt least 30 days after disablingGives owners time to notice

Devices that stop checking in turn noncompliant long before this anyway, after the compliance status validity period (30 days by default).

2. Create the cleanup rules#

  1. In the Microsoft Intune admin center, go to Devices › Organize devices › Device cleanup rules and select Create.
  2. On Basics, name the rule and choose the platform.
  3. On Rule settings, enter the number of days, then select Preview affected devices to see exactly what will be hidden.
  4. Review and create, then repeat for each platform that needs its own threshold.

3. Check what the rule did#

In Tenant administration › Audit logs, filter on activities named Device set to be hidden from admin by Device Cleanup Rule followed by your rule name.

4. Clean up Microsoft Entra ID separately#

Entra ID tracks activity in ApproximateLastSignInDateTime, which only refreshes when the change is more than about 14 days (give or take 5), so never treat anything younger than 21 days as stale. Retire Intune-managed devices in Intune before touching their Entra object, and handle hybrid joined devices in on-premises Active Directory, letting Microsoft Entra Connect sync the change.

This script lists stale cloud devices, skipping blank timestamps (some active devices have one), hybrid joined devices and Autopilot devices, then disables the unmanaged ones:

PowerShell
$scopes = 'Device.Read.All','DeviceManagementServiceConfig.Read.All','Directory.AccessAsUser.All'
Connect-MgGraph -Scopes $scopes -NoWelcome

$cutoff = (Get-Date).AddDays(-90)
$autopilotIds = (Get-MgDeviceManagementWindowsAutopilotDeviceIdentity -All).AzureActiveDirectoryDeviceId

$stale = Get-MgDevice -All | Where-Object {
    $_.ApproximateLastSignInDateTime -and
    $_.ApproximateLastSignInDateTime -le $cutoff -and
    $_.TrustType -ne 'ServerAd' -and
    $_.DeviceId -notin $autopilotIds
}

$stale | Select-Object DisplayName, DeviceId, OperatingSystem, TrustType, IsManaged,
        ApproximateLastSignInDateTime |
    Export-Csv -Path .\EntraStaleDevices.csv -NoTypeInformation

# Managed devices stay enabled here: retire them in Intune first
$toDisable = $stale | Where-Object { -not $_.IsManaged }
Read-Host "Review the CSV, then press Enter to disable $($toDisable.Count) devices (Ctrl+C to stop)"
foreach ($d in $toDisable) {
    Update-MgDevice -DeviceId $d.Id -BodyParameter @{ accountEnabled = $false }
}

Devices the CSV marks as IsManaged are skipped on purpose: retire those in Intune first, then disable them deliberately. After the grace period, delete only devices that are still disabled, using Remove-MgDevice -DeviceId with the object ID.

Watch out: Remove-MgDevice doesn't prompt and can't be undone. It also deletes any BitLocker recovery keys stored on the device object, so back up keys you might still need first.

5. Treat Autopilot devices differently#

Autopilot devices are system-managed and shouldn't be deleted from Entra ID. If their Entra object disappears, self-deploying and pre-provisioning deployments fail with a ZTDID mismatch, and user-driven deployments create a new object without the ZTDID tag. Entra ID won't let you delete them until they're deleted from Intune anyway. When the hardware is genuinely gone, remove it from the Windows Autopilot devices list in Intune first, then deal with the Entra object.

Verify#

  • Preview affected devices matched what you expected before you created each rule.
  • The audit log shows entries for hidden devices, each naming the rule.
  • In the Microsoft Entra admin center, Entra ID › Devices › All devices shows the disabled devices as not enabled, and the CSV gives you a record of what changed.

Tips & gotchas#

  • Disabled isn't harmless. A disabled device can't authenticate to Microsoft Entra ID, so a misfire locks someone out of Microsoft 365. Review the CSV.
  • App-only limits. With application permissions, Graph only lets you update extension attributes on non-Windows devices, so run the disable step with a signed-in admin.
  • Deleting doesn't unregister the client. Removing an Entra object only stops the device using that identity; the device itself still thinks it's registered.
  • Start high, then tighten. Moving a threshold down later is easier than explaining why a returning user's laptop vanished.

References#

Written and checked against current Microsoft Learn documentation. Test changes with a pilot group before rolling them out to everyone, and if an admin center path has moved since, search for the setting name instead.

Spotted a mistake, or did this fix work differently for you? Email me or message me on LinkedIn — corrections are credited in the article.

OE
Written by

Omer Eltayeb

Independent Microsoft Intune consultant in Cairo, Egypt, former Microsoft Cloud Solutions Architect, Microsoft Certified Trainer and Microsoft Innovative Educator Expert (2024–26) and Microsoft Elevate Educator Expert (2026–27). I share practical, step-by-step guides, study plans, scripts and toolkits for Microsoft Intune, Microsoft Entra ID, Microsoft Defender and Exchange Online with the community.

Microsoft Certified Trainer (MCT) 2026Microsoft Innovative Educator Expert 2025–2026Microsoft Elevate Educator Expert 2026–2027ISC2 Certified Information Systems Security Professional (CISSP)Microsoft 365 Certified: Enterprise Administrator Expert (MS-102)