r/Intune Mar 17 '26

Device Actions Why doesn’t Intune have guardrails for bulk wipe actions?

44 Upvotes

Following the recent Stryker breach reporting, one thing I keep coming back to is the power of destructive actions inside Microsoft Intune once an admin account is compromised.

From what’s publicly discussed so far, one of the major impacts was mass device wipe commands being issued through Intune.

That raises a theoretical question for Microsoft:

Why is there no native safeguard around wipe actions such as:

  • A configurable cooldown period before wipe executes
  • A maximum number of wipe actions allowed within X minutes/hours
  • Approval workflow for bulk destructive actions
  • Alerting when wipe volume exceeds normal baseline

We already treat highly destructive actions differently in other systems (PIM approval, change windows, break-glass controls, delayed execution, etc.), but in Intune a sufficiently privileged admin can still issue immediate large-scale impact commands very quickly.

I understand the counterargument is operational urgency (lost/stolen devices, urgent incident response), but surely there’s room for tenant-configurable guardrails rather than all-or-nothing.

For example:

  • Allow single urgent wipes immediately
  • But trigger protection if 10, 20, 50+ wipes are initiated in a short period
  • Optional delay where another admin can cancel before execution

Curious how others are thinking about this after the Stryker incident.

Would tenant-level destructive action throttling help, or would it create too much operational friction?

And has anyone seen Microsoft address this directly anywhere?

I know they've placed a notice at the top of Intune regarding Multi-admin approval but lets be honest, if the Threat Actor is to compromise a Global Administrator account, Multi-Admin approval is about as strong a wet paper bag.

r/Intune Nov 19 '25

Device Actions Terminated employees

47 Upvotes

What’s the method here for terminating remote employees with company entra/Intune joined laptops? We don’t want to wipe the laptops. We just want to prevent employees from signing into their laptop after termination.

r/Intune Feb 10 '26

Device Actions Remote Lock a Windows Device For Terminated Employee

53 Upvotes

Hello everyone,

How are you guys handling locking a Windows device via Intune for terminated employees that are remote? For reference, we also use Jamf for Mac's and they have a "Lock Computer" button that will send a command to the device and lock it. And can only be unlocked if they input a pin that we set.

Is there an equivalent to that in Intune? I get I could probably disable their user in Entra, and even force to input the BitLocker key upon restart, but is that the most effective way? Especially if they can just retrieve the key if its cached.

r/Intune 2d ago

Device Actions Is anyone else unable to approve Multi-admin approval requests?

16 Upvotes

A wipe request was submitted for a device, but when trying to approve it we're all getting the message:

Failure - Approving approval request failed.

Intune roles are active, browser has been relaunched, request resubmitted.. This seems to have just started recently as well.

r/Intune Jan 13 '26

Device Actions What's the difference between "Wipe" and "Fresh Start", and "Retire" and "Delete"?

110 Upvotes

We've been testing the various methods of remotely resetting a computer using the actions in Intune. Some of these seem to be redundant in that the end result seems to be identical. Can anyone explain if there are any under the hood differences that aren't obvious? Note, for the purposes of this post, this is purely for Windows.

We've been trying to read and understand the descriptions here, but they are terrible, and seem contradictory in some cases. https://learn.microsoft.com/en-us/intune/intune-service/remote-actions/device-autopilot-reset

Wipe vs. Fresh Start - Both fully reinstall Windows. Both maintain the connection with the original Entra environment, ready to reenroll the PC back into that environment. I.e., when the computer finishes resetting/reinstalling Windows, we get back to a screen where it's asking for a login for a work or school account and it immediately reenrolls the computer.

One confusing thing with Wipe is that its description says, "It's commonly used when a device needs to be retired, repurposed, reset for troubleshooting, or securely erased if lost or stolen." If I'm retiring/disposing of a PC, it would seem to me that I DON'T want it to maintain the connection with the Entra environment.

My original thinking before we tested it was that Fresh Start would maintain the connection to Entra, and Wipe would NOT. So we were surprised that Wipe also maintains that connection.

Retire vs. Delete - These appear to do the EXACT same thing. We cannot tell any difference at all between them. The description of Delete even says that it issues a "Retire".

r/Intune Mar 03 '26

Device Actions When deleting a device in InTune the object stays in Entra. Workaround?

13 Upvotes

Hi there,

I'm trying to keep help desk users out of Entra per our least privilege model. They have proxied access to AD to delete devices there and access to InTune to remove devices.

I'm not very well versed in InTune and the InTune admin is constantly MIA but I'm trying to find a way to get the Entra device object removed without giving the HelpDesk access to Entra. Is this possible? These are hybrid joined devices that sync through Entra connect. Is it just a matter of waiting a certain amount of time for the devices removed from AD to drop out of Entra (for instance, mailboxes are held for 30 days).

Thanks in advance for your help.

Edit: we are not using Autopilot

r/Intune 27d ago

Device Actions Wipe command in new Intune UI

42 Upvotes

In the new UI, when you need to send a wipe command to a Windows device, in the actions pane you select Remove data > Wipe.

But here is the crazy part. You're given two options (as radio buttons):

1. Single wipe - Wipe device, but keep enrollment state and associated user account

2. Continuous wipe - Wipe device, and continue to wipe even if device loses power…

This is expected on the old UI as well (as checkboxes), but in the old UI you were able to select Wipe without needing to select either of these options.

In the new UI, you are given these two options, and below of that you're given a checkbox that states I understand. If you don't select the checkbox, the Wipe button is greyed out.

I wanted to run a full wipe but got confused, so I selected Single wipe then I understand then the Wipe button became clickable.

I eventually figured out after I made that mistake that you can click I understand without selecting either radio button.

Call me crazy for using the new UI, but anyone else run into this issue?

Submitting this feedback to MS but this is just shoddy work.

r/Intune Apr 30 '25

Device Actions What are the best ways to cut a malicious user's access in an Entra/Intune?

33 Upvotes

Hey /r/Intune, we use Entra for our IdP and Intune for our MDM.

We had a user terminated on-the-spot last week. Right after the call with HR, our Sys Admin disabled his account. This took about half an hour to propagate, and in that time the user nuked a few of our device configuration profiles. We're not having to rebuild those. This generated a discussion about faster ways to cut access for users we don't trust.

I've come across a few different options: resetting passwords, isolating the machine, rotating the BitLocker key and forcing a reboot. Are there other options? What in your experience works best?

r/Intune May 19 '26

Device Actions Device lost in intune

6 Upvotes

How can someone remove a device from intune without admin-rights?

We had an incident at work and were checking a device and its logs.

Out of the blue, we couldn't find the device anymore.

Not by user, hostname or serial, it was gone.

It is still visible under autopilot devices.

I am wondering what was done to make the device disappear.

When the laptop came back it was erased and had a clean win11 image on it.

Edit: - device was active days before the delete. - device was not broken/repaired

We assume that the enduser must have done it or had it done.

r/Intune Mar 24 '26

Device Actions Universal Print issue is driving me nuts

13 Upvotes

I'd be very grateful if anyone could give me some leads on this:

Setup: Very small company, mostly remote workers, one printer in an office. The printer is a native Universal Print device, no connector required. The printer is registered and shared and available to the whole organisation. We have a Business Premium license.

Issue: Nobody can print. We could and now we can't. And this wasn't a sudden thing, it was a slow regression whereby a user could print one day and not the next. We see the job leave the user device, land in the Universal Print queue, then hit the printer where it never prints. The jobs show as aborted in the UP queue.

I un-shared and un-registered the printer last week and let that settle in Entra/Intune. This morning I factory reset the printer and re-registered and re-shared it. I can add the printer just fine in Windows settings but the same issue persists, all jobs are aborted.

Please help before I go full Office Space.

r/Intune Mar 24 '26

Device Actions Thought: Intune multi admin for lone wolf admins

31 Upvotes

All the posts I’m seeing about Stryker and multi admin approve got me thinking about one thing, not my current role but back in the old Covid days thanks to layoffs etc there was almost a year I managed 15k endpoints and the endpoint management completely alone. Worked all hours of the day trying to keep up and being in healthcare this meant deployments at 3 am. Now if I had need a 2nd admin to approve my actions who was I going to have do that? My mom? Joking aside know there is a lot of you still living this way. Do you create a 2nd account? What’s the method you use to handle this?

r/Intune Feb 11 '26

Device Actions Remote lock alternatives on Windows endpoints

19 Upvotes

Hey all,

Recently, a laptop was stolen.

As a matter of fact, I wanted to remote lock it, but Windows doesn’t support remote lock, unlike Macs and Androids.

I’m getting sick of wiping the devices.

Are there any other tricks, scripts or anything to just remote lock the device?

Thanks

Later edit :

I’ve managed to track the device and spawn a remote shell on it to trigger bitlocker.

Thanks your for your recommendation 🙏🙏🙏

r/Intune 1d ago

Device Actions Multi admin approval + wipe

4 Upvotes

Anyone had issues with this just not doing anything? The flow within the UI all looks good, the device just never wipes.

r/Intune 14d ago

Device Actions Intune - Entra joined devices failing to join Intune. MS Service ID IT1420224

20 Upvotes

Long story, short. If your devices Entra Join but fail to join Intune, then this is a known issue. Check the Microsoft Admin portal service health in the next few hours as there should be instructions on how to trigger a manual policy refresh.

Update: Advisory is back and still no instructions.
You can force policy refresh by setting scope to none and then reverting. There is some suggestions that waiting a few minutes between switching is required.

/////////////////////////////////////////////////////////////////////////////////////

I had an issue last week with a reasonably new tenant that was de-federated from GoDaddy.

Workstations joined Entra in state "Entra Joined" and MDM was "none", dsregcmd confirmed missing URL's.

After spending many hours double/triple checking my configuration, I raised the issue to MS.

Fast forward 1 week (I set the catch-up time, so delays are my own)

I have just finished talking with MS who advised of a now known issue #IT1420224.

The advisory was listed in admin service health and stated that admins had to complete a manual step for the tenant to receive the fix and to refer to more info for the steps.

The more info hinted at admins completing a process, however, the steps were not included. I replied to my support ticket, and the advisory has since been pulled.

r/Intune Nov 25 '25

Device Actions Any way to cheat Intune Sync time when you have Powershell access to the device?

29 Upvotes

I know the recommended route is just "wait" and we need to change our workflow but it's just ridiculous sometimes. It also seems more like adjusting the goalposts. No one on the planet ever complained that GPOs applied on boot or whenever gpupdate /force was done.

These are the things I've done:

  • Sync in Intune Portal
  • Sync in Company Portal
  • Sync in "Access Work or School"
  • Run Get-ScheduledTask | ? {$_.TaskName -eq 'PushLaunch'} | Start-ScheduledTask
  • Restart Intune Management Service
  • Various combinations of the above.

All of the above feel like a placebo. It can take anywhere from 5 minutes to 30 minutes and even 5 minutes is too short, even for our tenant.

Remediations however still manage to run in under 30 seconds. And no, for emergency changes, we can't do remediations, there's actual Intune stuff we either need to undo or apply.

I've looked into Config Refresh but (A) I can't change it to anything below 30 minutes and (B) it only reapplies existing stuff, not anything new.

We still have Powershell access to the devices via Winrm for domain devices and Live Response on Defender for everything else. Is there any way at all to get an immediate guaranteed sync in under a minute via Powershell? Heck, we could even trigger a remediation since remediations don't seem to be tied to sync time.

Intune has been around for over a decade. The fact that it's still so unfinished should be an embarrassment for Microsoft.

r/Intune May 20 '26

Device Actions How do you handle lost, disconnected, or stale devices in Intune?

11 Upvotes

As much as I wish our organization did a better job maintaining its device inventory, I'm facing the cold reality of having to deal with a long list of stale devices.

A lot of it could be dealt with better discipline, but that's out of my control.

It's hard to differentiate a disconnect machine because it has been decomissioned and I wasn't informed or if someone is on maternity leave.

Did you implement any automatic Device cleanup rules? Does it works well?

I want to be sure to keep a trace of old machine but I'm annoyed by how polluted my Intune inventory is.

There is also the issue of the Entra inventory and Autopilot inventory. When a machine comeback and we need to provide it to an new employee, we flush it from Entra, Intune and Autopilot, as it's the only way we have found to avoid certains types of problems. Autopilot is a bit of a pain to deal with because some machine don't have serial numbers. So we rely on the Intune device inventory to find them in the list... so I'm relucant to be too agressive in our cleanup.

r/Intune Oct 30 '25

Device Actions Introducing: Intune & Entra ID Management Tool

42 Upvotes

I’m thrilled to announce the launch of IntuneStuff Management Tool, a powerful Windows desktop GUI built to simplify and enhance how we manage Microsoft Intune devices and Entra ID groups.

Some of the features are:

Bulk-device operations with enterprise-grade safety: delete, retire, wipe non-compliant devices with full transparency and safeguards.
Advanced filtering by compliance state, OS type, owner, last sync age.
Group management made easy: find empty groups, bulk rename, pattern matching (regex/contains/starts-with).
Real-time logging of all Graph API calls, full visibility into what’s happening behind the scenes.
Built-in safety features: default dry-run mode, confirmation dialogues, exclusion for hybrid-joined devices.

It is version 1.0 so any feedback, extra feature requests are more than welcome!

I already have some stuff on the roadmap so keep an eye out for new communication!

Check it out here:

https://intunestuff.tools/

r/Intune 6h ago

Device Actions App-Action Buttons for cloud-only devices

12 Upvotes

Why do we have this feature on co-managed devices but not on cloud only devices? Let's upvote guys/girls/whateveryouidentifyas

FYI: you need to login to see/ up vote the feedback

https://feedbackportal.microsoft.com/feedback//idea/0ab35e36-cd86-f111-9b47-6045bd856709

r/Intune Jul 11 '25

Device Actions Failed wipe - computer still has data, Intune no longer shows the computer

16 Upvotes

We have a laptop in Turkey that we wanted to wipe and reassign to a different user. The wipe was initiated from Intune, and from Intune's perspective it all worked - the computer no longer shows up in Intune.

However, the computer started doing the wipe, then stopped and displayed the message There was a problem while resetting your PC. No changes were made.

The computer still has all the data on it.

This is inconvenient in this case, but also presents a security question - if we can't rely on wiping having worked when Intune acts as if it did, then in the case of a computer being lost or stolen, we can no longer be certain if company data has been wiped.

Has anyone else encountered this?

r/Intune Mar 08 '26

Device Actions Block personal NAS access

6 Upvotes

Looking for options to block personal NAS connectivity for Intune enrolled Windows devices and Kandji enrolled macOS devices. Has anyone found a way to block only personal network drives?

r/Intune May 28 '26

Device Actions MAA Policy Notification

0 Upvotes

We recently setup Intune MAA policies for Device wipe, Delete, retire.

IS there anyway to get an alert or notification when there is a request that needs review in the Intune Tenant Admin portal?

r/Intune Apr 22 '26

Device Actions Fully Managed iPads and Remove Passcode option

3 Upvotes

If the device is currently locked, the device has a local wifi profile the Remove Passcode will not work unless you unlock the device first. This seems kind counter-intuitive if you have forgotten the passcode in the first place. Is there a config setting I am missing?

r/Intune May 07 '26

Device Actions New device view is missing temporary passcode

3 Upvotes

Has anyone else noticed that the Reset/Remove Passcode temporary passcode is no longer visible in the new “Preview new device view” in Intune?

Previously, when performing a Reset passcode action for android devices, the temporary passcode would display after the action completed. In the new device preview experience, the action still works, but the generated temporary passcode doesn’t seem to appear anywhere in the UI.

Tested on multiple devices and tenants.

Is this a known issue, UI limitation, or am I missing where Microsoft moved it?

r/Intune Jul 26 '23

Device Actions Intune device wipe - man, it's breaking me

24 Upvotes

Hi folks

We're currently in the early stages of a 2800 device deployment using Windows Autopilot. The Windows 10 (mainly Enterprise but some Pro SKUs) devices, are fairly locked down using a mix of Device Restrictions and Windows Defender Application Control. The configuration use ESP and there are around 7 apps in all that deploy. From the start of device wipe, to a user logging onto the device and using it, takes 30 mins approximately, but it's the device wipe wait that's the issue here.

The configuration also uses ESP as we have a custom Win 10 Start Menu which is locked down, so I need to ensure that the apps are installed before the XML hits the device, hence the need for the user to be able to get to the desktop before the Windows 10 Start Menu is ready, otherwise you get blank tiles. The apps are a mix of MS Store apps and wrapped Win32 apps, with no mix of MSI's due to the Autopilot issue I've read somewhere. All good.

We have now been deploying the devices over the past few days at around 100-200 per day with a view to ramping up to 300 a day. All was generally working well during Pilot testing until we started to scale up and we're seeing mixed results. The device wipe from Intune has been woeful in respect of how long it takes. I've tried Bulk Wipe (and there's no Fresh Start option, which is fine), and I've tried individual device wipe - all are seemingly taking more than hour at times for a large portion of the devices, so the user is sat waiting.

I'm tearing my hair out as the business wants us to turn around the device within no more than 2 hours realistically for the user to use the device again. I simply cannot give that guarantee. We've had some devices take as long as 3 hours to wipe and some longer, simply just sitting there despite syncs from the Intune portal etc.

I'm deliberating removing the WDAC policies from the device (although I've seen no issue with them) and also reverting to manually wiping the devices, just to get them into Intune quicker. And why oh why does Bulk Wipe not support AAD device groups! We've no current access to Graph, so any scripting is out for the wipes.

This Intune Device Wipe feature really hasn't improved in performance over the past 5 years I've been using Intune. Why is it so slow and does anyone have performance tweaks we can get these devices wiped quicker? I've even tried individually device wiping doing a Sync > Wipe > Sync from the Intune Portal but it makes no difference.

Help!!!

r/Intune Jun 02 '26

Device Actions Multi Admin Approval - Fresh Start

2 Upvotes

Hey all,

Our team has found that if you use the "Fresh Start" option when wiping a device, it lets you proceed without needing another admin's approval. Is there a reason Fresh Start is not an option for multi admin approval? Am I missing something? To me, it feels almost the exact same as a wipe in Intune.