Endpoint Services, Intune, Device Cleanup Rules

Overview

Microsoft Intune's device cleanup rules apply to all enrolled devices. Intune removes inactive devices after 270 days.

Systems

Microsoft Intune

Affected Customers

  • Personally owned Windows devices that have signed in to ‘Access work or school’ with university credentials.
  • Personally owned Windows devices that have accepted ‘Allow my organization to manage my device’ when signing into M365 apps with university credentials.
  • Android devices that have installed the Company Portal app and signed in with university credentials (primarily Teams devices).

The settings described are being tested. Feedback is requested while a larger personal policy is established. Settings are subject to change without notice as we develop management of the platform. The focus is on university-owned devices. Personal devices are not supported by the university.

You can remove Intune from your personal device by following the steps here:
Microsoft 365, How do I undo the "Allow my organization to manage my device" setting?

General Information

Microsoft Intune will automatically remove devices that have not communicated with the service in 270 days. Communication with Intune is a passive process that requires an internet connection and a valid Intune device certificate, which is automatically issued during device enrollment and is valid for one year.

A removed device is considered unenrolled from Intune and will:

  • No longer receive policy or settings from Intune.
  • Automatically re-enroll in Intune only if it still has a valid Intune device certificate the next time it has an active internet connection.

Depending on the settings managed by Intune at the time of last check-in, a Windows device that comes online after removal may have some settings persist. Others may revert to Windows' default behavior. In either case, management of all settings will be returned to the device’s administrator.

Users who sign in to a removed Windows device may receive a notification that their organization no longer manages specific settings. They may also experience behavior that differs from the last time they were online, depending on the settings that are no longer managed.

Any changes in a device's Intune enrollment state or the settings managed on a device will not result in the removal of any personal files from the device.

Removal will neither wipe nor retire a device, and it will not disable or remove the device from Microsoft Entra ID.



Keywords:
eps Intune techs-eps-intune byod eps aad "Azure Active Directory" "Entra ID" azure m365 "Microsoft 365" device personal "personal device" settings cleanup "clean up" 
Doc ID:
148288
Owned by:
EPS Distribution List G. in University of Illinois Technology Services
Created:
2025-02-12
Updated:
2025-03-10
Sites:
University of Illinois Technology Services