Wiping a device

%3CLINGO-SUB%20id%3D%22lingo-sub-2234599%22%20slang%3D%22en-US%22%3EWiping%20a%20device%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2234599%22%20slang%3D%22en-US%22%3E%3CP%20class%3D%22_1qeIAgB0cPwnLhDF9XSiJM%22%3EHello%2C%3C%2FP%3E%3CP%20class%3D%22_1qeIAgB0cPwnLhDF9XSiJM%22%3EIs%20there%20any%20option%20in%20Intune%2C%20where%20conditions%20can%20be%20set%20to%20perform%20wiping%20of%20devices.%3C%2FP%3E%3CP%20class%3D%22_1qeIAgB0cPwnLhDF9XSiJM%22%3EExample%3A%20if%20a%20machine%20is%20inactive%20for%20a%20period%20of%2060%20days%20and%20doesn't%20come%20online%2C%20then%20perform%20complete%20wipe%20of%20the%20device.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2234599%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EIntune%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2235841%22%20slang%3D%22en-US%22%3ERe%3A%20Wiping%20a%20device%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2235841%22%20slang%3D%22en-US%22%3ECheck%20out%20Devices%20%26gt%3B%20Device%20Cleanup%20rules%3CBR%20%2F%3E%22Set%20your%20Intune%20device%20cleanup%20rules%20to%20delete%20Intune%20MDM%20enrolled%20devices%20that%20appear%20inactive%2C%20stale%2C%20or%20unresponsive.%20Intune%20applies%20cleanup%20rules%20immediately%20and%20continuously%20so%20that%20your%20device%20records%20remain%20current.%22%3CBR%20%2F%3E%3C%2FLINGO-BODY%3E
Frequent Contributor

Hello,

Is there any option in Intune, where conditions can be set to perform wiping of devices.

Example: if a machine is inactive for a period of 60 days and doesn't come online, then perform complete wipe of the device.

5 Replies
Check out Devices > Device Cleanup rules
"Set your Intune device cleanup rules to delete Intune MDM enrolled devices that appear inactive, stale, or unresponsive. Intune applies cleanup rules immediately and continuously so that your device records remain current."
Another possibility would be implementing app protection policies. When implementing app protection policies you could configure the conditional launch settings:

https://call4cloud.nl/2021/03/app-protection-and-a-disabled-account/
I have seen this setting is available just for Android/iOS app protection policy and not for Windows 10 devices.
This would just remove the device from the portal and will not perform the wiping of the device.

https://techcommunity.microsoft.com/t5/device-management-in-microsoft/using-intune-device-cleanup-ru....
Perhaps (little bit of rethinking) but you can make use of Windows information Protection... and combine it with a powershell script like Nicola build some time ago: https://tech.nicolonsky.ch/clean-up-azure-ad-devices/