Forum Discussion

davidscharf's avatar
davidscharf
Copper Contributor
Nov 03, 2024

Retiring / Deleting Entra ID Joined device will make it unaccessible

Hi community,

am I alone with this issue? I'm currently testing some Intune functions with a testing device and account. I just found out that deleting or retiring an intune device (AD joined, no local backup account) from the web interface will make it unusable after restart. It will ask for the password of the AD user and won't even accept the correct password.

 

Is this issue known? Is there a workaround to gain access to the data? In a prod environment with bitlocker enabled this is a nightmare.

2 Replies

  • Uhhh... let me get this right, you are deleting the device from enta and you are wondering why you cant login to it anymore? When you delete the object service side, the whole trust is gone that the device had... how could the device authenticate with the service if the object is deleted service side?

    The same way if you deleted a device in your active directory... could you still login in on it with your ad cred?(not talking offline witch cached creds)
    • davidscharf's avatar
      davidscharf
      Copper Contributor
      Hi, sorry didn't describe it correctly. Deleting it from entra won't affect the entra joined device but deleting / retiring it from intune will. I'm just a bit concerned because this way all local data will be lost as soon as someone clicks this button. When you manually want to disconnect from your business account in the Windows settings, you get asked for an alternative local account. This doesn't happen when you trigger the delete / retire in intune.

Resources