Old laptops, replaced phones and abandoned enrollments pile up in Intune and quietly skew every report. Device cleanup rules handle the Intune side automatically, but they don't touch Microsoft Entra ID or Windows Autopilot. In this post I'll set up per-platform rules, then add an Entra ID routine that disables before it deletes and leaves Autopilot devices alone.
How it works#
A cleanup rule runs on a schedule and hides devices that haven't checked in with Intune for a set number of days, anywhere from 30 to 270. You can create one rule per platform (Windows, Windows Holographic, macOS, iOS/iPadOS, tvOS, visionOS, ChromeOS and four Android management types) plus an All platforms rule. Where both apply, the rule with fewer days wins.
| Object | What a cleanup rule does to it |
|---|---|
| Intune device record | Hides it from the admin center and reports |
| The device itself | Nothing: no wipe, no retire |
| Microsoft Entra ID device object | Nothing, so BitLocker keys stored on it stay too |
| Windows Autopilot registration | Nothing |
A hidden device reappears if it checks in before its device certificate expires; after that, it has to enroll again. Cleanup rules aren't available for Jamf-managed devices.
Prerequisites#
- Intune Administrator, or a custom role with Managed Device Cleanup Rules/Update, Managed Device Cleanup Settings/Update and read access to managed devices.
- For the Entra ID part: the Cloud Device Administrator or Intune Administrator role and the Microsoft Graph PowerShell SDK (the
Microsoft.Graph.Identity.DirectoryManagementandMicrosoft.Graph.DeviceManagement.Enrollmentmodules). Reading needsDevice.Read.Alland, for the Autopilot list,DeviceManagementServiceConfig.Read.All. Disabling and deleting with a signed-in admin usesDirectory.AccessAsUser.All.
Step-by-step#
1. Decide your thresholds#
These are my starting points, not Microsoft defaults:
| Layer | Suggested threshold | Why |
|---|---|---|
| Cleanup rule: Windows and macOS | 90 days | Covers long leave and travel |
| Cleanup rule: iOS/iPadOS and Android | 60 to 90 days | Phones that go quiet for that long have usually been replaced |
| Entra ID: disable | 90 days without activity | Lines up with the Intune rule |
| Entra ID: delete | At least 30 days after disabling | Gives owners time to notice |
Devices that stop checking in turn noncompliant long before this anyway, after the compliance status validity period (30 days by default).
2. Create the cleanup rules#
- In the Microsoft Intune admin center, go to Devices › Organize devices › Device cleanup rules and select Create.
- On Basics, name the rule and choose the platform.
- On Rule settings, enter the number of days, then select Preview affected devices to see exactly what will be hidden.
- Review and create, then repeat for each platform that needs its own threshold.
3. Check what the rule did#
In Tenant administration › Audit logs, filter on activities named Device set to be hidden from admin by Device Cleanup Rule followed by your rule name.
4. Clean up Microsoft Entra ID separately#
Entra ID tracks activity in ApproximateLastSignInDateTime, which only refreshes when the change is more than about 14 days (give or take 5), so never treat anything younger than 21 days as stale. Retire Intune-managed devices in Intune before touching their Entra object, and handle hybrid joined devices in on-premises Active Directory, letting Microsoft Entra Connect sync the change.
This script lists stale cloud devices, skipping blank timestamps (some active devices have one), hybrid joined devices and Autopilot devices, then disables the unmanaged ones:
$scopes = 'Device.Read.All','DeviceManagementServiceConfig.Read.All','Directory.AccessAsUser.All'
Connect-MgGraph -Scopes $scopes -NoWelcome
$cutoff = (Get-Date).AddDays(-90)
$autopilotIds = (Get-MgDeviceManagementWindowsAutopilotDeviceIdentity -All).AzureActiveDirectoryDeviceId
$stale = Get-MgDevice -All | Where-Object {
$_.ApproximateLastSignInDateTime -and
$_.ApproximateLastSignInDateTime -le $cutoff -and
$_.TrustType -ne 'ServerAd' -and
$_.DeviceId -notin $autopilotIds
}
$stale | Select-Object DisplayName, DeviceId, OperatingSystem, TrustType, IsManaged,
ApproximateLastSignInDateTime |
Export-Csv -Path .\EntraStaleDevices.csv -NoTypeInformation
# Managed devices stay enabled here: retire them in Intune first
$toDisable = $stale | Where-Object { -not $_.IsManaged }
Read-Host "Review the CSV, then press Enter to disable $($toDisable.Count) devices (Ctrl+C to stop)"
foreach ($d in $toDisable) {
Update-MgDevice -DeviceId $d.Id -BodyParameter @{ accountEnabled = $false }
}Devices the CSV marks as IsManaged are skipped on purpose: retire those in Intune first, then disable them deliberately. After the grace period, delete only devices that are still disabled, using Remove-MgDevice -DeviceId with the object ID.
Watch out: Remove-MgDevice doesn't prompt and can't be undone. It also deletes any BitLocker recovery keys stored on the device object, so back up keys you might still need first.
5. Treat Autopilot devices differently#
Autopilot devices are system-managed and shouldn't be deleted from Entra ID. If their Entra object disappears, self-deploying and pre-provisioning deployments fail with a ZTDID mismatch, and user-driven deployments create a new object without the ZTDID tag. Entra ID won't let you delete them until they're deleted from Intune anyway. When the hardware is genuinely gone, remove it from the Windows Autopilot devices list in Intune first, then deal with the Entra object.
Verify#
- Preview affected devices matched what you expected before you created each rule.
- The audit log shows entries for hidden devices, each naming the rule.
- In the Microsoft Entra admin center, Entra ID › Devices › All devices shows the disabled devices as not enabled, and the CSV gives you a record of what changed.
Tips & gotchas#
- Disabled isn't harmless. A disabled device can't authenticate to Microsoft Entra ID, so a misfire locks someone out of Microsoft 365. Review the CSV.
- App-only limits. With application permissions, Graph only lets you update extension attributes on non-Windows devices, so run the disable step with a signed-in admin.
- Deleting doesn't unregister the client. Removing an Entra object only stops the device using that identity; the device itself still thinks it's registered.
- Start high, then tighten. Moving a threshold down later is easier than explaining why a returning user's laptop vanished.