Forum Discussion
James_Gillies
Apr 27, 2021Brass Contributor
MUST be able to delete duplicate/orphaned devices from M365 Security Center
Good morning, I am about 2-3 weeks into evaluating Microsoft Defender for Endpoint, and so far have about 4 Windows 10 devices onboarded and managed through InTune policies. One of the test m...
- Jun 21, 2021AFAIK, TVM data only includes data from computers that have been active in the last 30 days.
Microsoft doesn't provide the ability to remove devices because it's extremely dangerous. If an attacker would get permissions on your cloud instances, he could remove all his tracks. The devices are retained for forensic purposes.
Best options it to tag an offboarded machine and create an 'Inactive' machine group for it
WTulaba
Feb 14, 2022Copper Contributor
I can't believe in 2022 this still isn't a thing. All the other major EDR vendors allow this function.
To suggest we filter around the absence of a basic function is absurd.
Can we get this basic functionality on the development roadmap?
To suggest we filter around the absence of a basic function is absurd.
Can we get this basic functionality on the development roadmap?
Abdul Farooque
Mar 11, 2022Brass Contributor
This is still a bug and needs a fix.
- pwahlmuellerJul 17, 2023MVP
I found the option to exclude devices option, but can this be done by script? Is there an API for that?
- Dennis_PeabodyApr 30, 2022Copper Contributor
Abdul Farooque There is now an exclude device option that you can use on duplicate devices. Not perfect, but it is something (And duplicate device is a reason code, so MS does know this can be an issue)