Cleanup Intune profiles and policies

%3CLINGO-SUB%20id%3D%22lingo-sub-2779455%22%20slang%3D%22en-US%22%3ECleanup%20Intune%20profiles%20and%20policies%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2779455%22%20slang%3D%22en-US%22%3E%3CP%3EWe%20have%20come%20across%20an%20issue%20where%20a%20desktop%20support%20person%20was%20logging%20into%20each%20windows%20device%20that%20they%20were%20deploying%20which%20assigned%20them%20as%20the%20primary%20user%20on%20the%20device.%26nbsp%3B%20I%20ran%20a%20script%20to%20switch%20the%20primary%20user%20to%20the%20last%20logged%20on%20user%20which%20cleaned%20up%20the%20devices%20and%20assigned%20them%20corrcetly%20but%20now%20the%20polcies%20and%20profiles%20are%20a%20mess.%26nbsp%3B%20Most%20of%20our%20polcies%20and%20profiles%20are%20user%20based%20and%20when%20I%20changed%20the%20primary%20user%2C%20it%20left%20his%20polcies%20and%20profiles%20on%20the%20device.%3CBR%20%2F%3E%3CBR%20%2F%3EHow%20do%20I%20purge%20their%20policies%20and%20profiles%20on%20these%20devices.%26nbsp%3B%20could%20it%20be%20his%20work%20profile%20is%20also%20still%20assigned%20on%20this%20device%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2779455%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EIntune%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2780711%22%20slang%3D%22en-US%22%3ERe%3A%20Cleanup%20Intune%20profiles%20and%20policies%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2780711%22%20slang%3D%22en-US%22%3EHi%2C%3CBR%20%2F%3EHi%2C%20good%20morning%3CBR%20%2F%3EIntune%20profiles--%26gt%3B%20Windows%20profiles..%20When%20a%20user%20logs%20in%20a%20device...%20and%20even%20when%20the%20user%20is%20removed%20the%20old%20profile%20just%20sits%20and%20stays%20there%20on%20the%20device...%3CBR%20%2F%3EIf%20there%20is%20data%20in%20it%20you%20want%20to%20remove%2C%20create%20a%20powershell%20script%20which%20tries%20to%20find%20the%20specific%20user%20folder%20first...%20if%20it%20exists...%20it%20removes%20it...%20(as%20the%20userprofile%20also%20contains%20the%20policies%2Fregister%20settings..%20they%20are%20also%20removed)%3CBR%20%2F%3EOr%20did%20I%20get%20the%20question%20wrong%20%3A)%3C%2Fimg%3E%20%3F%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2782728%22%20slang%3D%22en-US%22%3ERe%3A%20Cleanup%20Intune%20profiles%20and%20policies%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2782728%22%20slang%3D%22en-US%22%3EI%20didnt%20think%20the%20user%20profile%20on%20the%20machine%20was%20associated%20with%20the%20intune%20Device%20Compliance%2C%20Device%20COnfig%2C%20and%20ES%20Config.%20I%20went%20ahead%20and%20pulled%20the%20previous%20user%20profile%20off%20the%20machine%20and%20performed%20a%20sync%2C%20but%20the%20policies%20and%20configurations%20are%20still%20applying.%3C%2FLINGO-BODY%3E
Occasional Contributor

We have come across an issue where a desktop support person was logging into each windows device that they were deploying which assigned them as the primary user on the device.  I ran a script to switch the primary user to the last logged on user which cleaned up the devices and assigned them corrcetly but now the polcies and profiles are a mess.  Most of our polcies and profiles are user based and when I changed the primary user, it left his polcies and profiles on the device.

How do I purge their policies and profiles on these devices.  could it be his work profile is also still assigned on this device?

6 Replies
Hi,
Hi, good morning
Intune profiles--> Windows profiles.. When a user logs in a device... and even when the user is removed the old profile just sits and stays there on the device...
If there is data in it you want to remove, create a powershell script which tries to find the specific user folder first... if it exists... it removes it... (as the userprofile also contains the policies/register settings.. they are also removed)
Or did I get the question wrong :) ?
I didnt think the user profile on the machine was associated with the intune Device Compliance, Device COnfig, and ES Config. I went ahead and pulled the previous user profile off the machine and performed a sync, but the policies and configurations are still applying.
It depends on what was configured..

Device policies...
User policies

Could you take a look at what registry keys are still present inside the policymanager registry key?
Figured out the best way to handle this. Delete the Windows Device from AAD and MEM and wait for it to re-sync. cleans up the any MEM policies and profiles. Just made it a practice for our desktop team to do this before they deploy new or redeploy any Windows device.
SO you need to add the device manually back to aad? isn't autopilot reset not a better option
https://call4cloud.nl/2021/04/to-retire-or-not-to-wipe/#part5

When we need to reassign a existing device to a new user we are always choosing an autopilot reset.
These are hybrid devices. By deleting them in AAD and MEM, they will be autocreated back into AAD and MEM clean. Bit of a pain to do when we switch or deploy pc's, but it seems to work.