{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/intune-device-cleanup-rules-stale-records/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/intune-device-cleanup-rules-stale-records/",
        "slug": "intune-device-cleanup-rules-stale-records",
        "url": "https://update.dsesecurity.com/updates/intune-device-cleanup-rules-stale-records/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/intune-device-cleanup-rules-stale-records.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/intune-device-cleanup-rules-stale-records/"
        },
        "title": "Clean up stale Intune records without mistaking hiding for retirement",
        "summary": "Intune device cleanup rules hide stale records from the admin center and reports. They do not wipe, retire, or remove the corresponding Microsoft Entra device object.",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "topics": [
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            },
            {
                "slug": "microsoft-365-identity",
                "name": "Microsoft 365 & Identity",
                "url": "https://update.dsesecurity.com/topic/microsoft-365-identity/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-07-19T21:27:53+00:00",
        "modified_at": "2026-07-19T21:27:53+00:00",
        "reviewed_on": "2026-07-19",
        "reading_minutes": 2,
        "word_count": 422,
        "potentially_affected": "Microsoft Intune tenants with stale, duplicate, seasonal, long-offline, replaced, or unenrolled device records across supported platforms.",
        "dse_recommendation": "Preview affected devices, reconcile owners and exceptions, select a conservative platform-wide inactivity threshold, monitor audit events, and manage Intune and Entra lifecycle records separately.",
        "primary_source": {
            "name": "Microsoft Learn: Device cleanup rules",
            "url": "https://learn.microsoft.com/en-us/intune/governance/configure-cleanup-rules",
            "published_on": "2026-05-05",
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source fact: what Microsoft documents</h2>\n<p>Microsoft Intune device cleanup rules run on a schedule and automatically hide records for devices that have not checked in during a configured period. Microsoft explicitly states that a cleanup rule does not wipe, retire, or otherwise send an action to the physical device. A hidden record can reappear if the device checks in again before its management certificate expires; after expiry, reenrollment is required.</p>\n<p>The inactivity setting accepts 30 through 270 days. Administrators can create a rule for all platforms and one rule per individual platform. If both an all-platform rule and a platform-specific rule apply, Microsoft uses the rule with fewer days. A rule applies to all Intune records for that platform rather than to a selected device group. Jamf-managed devices are not supported.</p>\n<p>Cleanup does not remove the related Microsoft Entra device object. Microsoft documents separate Entra stale-device management. Intune audit logs record devices hidden by a cleanup rule, and the admin center can preview currently affected devices before rule creation.</p>\n<h2>Licensing and applicability</h2>\n<p>Users or devices benefiting from Intune generally require applicable Intune licensing. Configuring cleanup requires an Intune Administrator or a custom role with cleanup-setting permissions and visibility into the devices. Platform-wide behavior means seasonal equipment, spares, kiosks, disaster-recovery devices, long-term leave, ships, remote sites, and devices awaiting repair can be hidden even when they still have an owner and purpose.</p>\n<h2>DSE recommendation: production-safe operational steps</h2>\n<ol>\n<li>Export current device records with platform, serial number, ownership, enrollment type, last check-in, compliance, management certificate, primary user, and corresponding Entra object.</li>\n<li>Ask service owners to identify legitimate long-offline populations and decide how they will be tracked outside the normal active-device view.</li>\n<li>Choose a conservative threshold based on real check-in patterns, certificate life, remote operations, replacement cycles, and support requirements.</li>\n<li>Use Preview affected devices and investigate unexpected critical, shared, or recently issued assets before creating the rule.</li>\n<li>Start with one platform. Review Intune audit events, hidden-device behavior, reporting impact, reenrollment cases, and device reappearance.</li>\n<li>Maintain a separate process for wipe, retire, corporate-data removal, Entra object cleanup, inventory disposal, license recovery, and evidence retention.</li>\n<li>Review the threshold and exceptions after organizational, enrollment, or certificate changes.</li>\n</ol>\n<p>DSE recommends treating cleanup as an administrative-view control, not a security containment or asset-disposal control. Do not cite a disappeared Intune record as proof that access was removed or company data was erased. During an investigation, preserve the record and relevant exports before a cleanup rule hides it.</p>\n<h2>Official reference</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/intune/governance/configure-cleanup-rules\" target=\"_blank\" rel=\"noopener noreferrer\">Device cleanup rules</a> — hiding behavior, thresholds, platform scope, preview, Entra separation, and audit logging.</p>",
        "content_text": "Source fact: what Microsoft documents\nMicrosoft Intune device cleanup rules run on a schedule and automatically hide records for devices that have not checked in during a configured period. Microsoft explicitly states that a cleanup rule does not wipe, retire, or otherwise send an action to the physical device. A hidden record can reappear if the device checks in again before its management certificate expires; after expiry, reenrollment is required.\nThe inactivity setting accepts 30 through 270 days. Administrators can create a rule for all platforms and one rule per individual platform. If both an all-platform rule and a platform-specific rule apply, Microsoft uses the rule with fewer days. A rule applies to all Intune records for that platform rather than to a selected device group. Jamf-managed devices are not supported.\nCleanup does not remove the related Microsoft Entra device object. Microsoft documents separate Entra stale-device management. Intune audit logs record devices hidden by a cleanup rule, and the admin center can preview currently affected devices before rule creation.\nLicensing and applicability\nUsers or devices benefiting from Intune generally require applicable Intune licensing. Configuring cleanup requires an Intune Administrator or a custom role with cleanup-setting permissions and visibility into the devices. Platform-wide behavior means seasonal equipment, spares, kiosks, disaster-recovery devices, long-term leave, ships, remote sites, and devices awaiting repair can be hidden even when they still have an owner and purpose.\nDSE recommendation: production-safe operational steps\n\nExport current device records with platform, serial number, ownership, enrollment type, last check-in, compliance, management certificate, primary user, and corresponding Entra object.\nAsk service owners to identify legitimate long-offline populations and decide how they will be tracked outside the normal active-device view.\nChoose a conservative threshold based on real check-in patterns, certificate life, remote operations, replacement cycles, and support requirements.\nUse Preview affected devices and investigate unexpected critical, shared, or recently issued assets before creating the rule.\nStart with one platform. Review Intune audit events, hidden-device behavior, reporting impact, reenrollment cases, and device reappearance.\nMaintain a separate process for wipe, retire, corporate-data removal, Entra object cleanup, inventory disposal, license recovery, and evidence retention.\nReview the threshold and exceptions after organizational, enrollment, or certificate changes.\n\nDSE recommends treating cleanup as an administrative-view control, not a security containment or asset-disposal control. Do not cite a disappeared Intune record as proof that access was removed or company data was erased. During an investigation, preserve the record and relevant exports before a cleanup rule hides it.\nOfficial reference\nDevice cleanup rules — hiding behavior, thresholds, platform scope, preview, Entra separation, and audit logging.",
        "content_markdown": "## Source fact: what Microsoft documents\n\nMicrosoft Intune device cleanup rules run on a schedule and automatically hide records for devices that have not checked in during a configured period. Microsoft explicitly states that a cleanup rule does not wipe, retire, or otherwise send an action to the physical device. A hidden record can reappear if the device checks in again before its management certificate expires; after expiry, reenrollment is required.\n\nThe inactivity setting accepts 30 through 270 days. Administrators can create a rule for all platforms and one rule per individual platform. If both an all-platform rule and a platform-specific rule apply, Microsoft uses the rule with fewer days. A rule applies to all Intune records for that platform rather than to a selected device group. Jamf-managed devices are not supported.\n\nCleanup does not remove the related Microsoft Entra device object. Microsoft documents separate Entra stale-device management. Intune audit logs record devices hidden by a cleanup rule, and the admin center can preview currently affected devices before rule creation.\n\n## Licensing and applicability\n\nUsers or devices benefiting from Intune generally require applicable Intune licensing. Configuring cleanup requires an Intune Administrator or a custom role with cleanup-setting permissions and visibility into the devices. Platform-wide behavior means seasonal equipment, spares, kiosks, disaster-recovery devices, long-term leave, ships, remote sites, and devices awaiting repair can be hidden even when they still have an owner and purpose.\n\n## DSE recommendation: production-safe operational steps\n\n- Export current device records with platform, serial number, ownership, enrollment type, last check-in, compliance, management certificate, primary user, and corresponding Entra object.\n\n- Ask service owners to identify legitimate long-offline populations and decide how they will be tracked outside the normal active-device view.\n\n- Choose a conservative threshold based on real check-in patterns, certificate life, remote operations, replacement cycles, and support requirements.\n\n- Use Preview affected devices and investigate unexpected critical, shared, or recently issued assets before creating the rule.\n\n- Start with one platform. Review Intune audit events, hidden-device behavior, reporting impact, reenrollment cases, and device reappearance.\n\n- Maintain a separate process for wipe, retire, corporate-data removal, Entra object cleanup, inventory disposal, license recovery, and evidence retention.\n\n- Review the threshold and exceptions after organizational, enrollment, or certificate changes.\n\nDSE recommends treating cleanup as an administrative-view control, not a security containment or asset-disposal control. Do not cite a disappeared Intune record as proof that access was removed or company data was erased. During an investigation, preserve the record and relevant exports before a cleanup rule hides it.\n\n## Official reference\n\n[Device cleanup rules](https://learn.microsoft.com/en-us/intune/governance/configure-cleanup-rules) — hiding behavior, thresholds, platform scope, preview, Entra separation, and audit logging."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo.png"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/intune-device-cleanup-rules-stale-records/",
                "url": "https://update.dsesecurity.com/updates/intune-device-cleanup-rules-stale-records/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-07-19"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/intune-device-cleanup-rules-stale-records/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Clean up stale Intune records without mistaking hiding for retirement",
                        "item": "https://update.dsesecurity.com/updates/intune-device-cleanup-rules-stale-records/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/intune-device-cleanup-rules-stale-records/#article",
                "identifier": "https://update.dsesecurity.com/updates/intune-device-cleanup-rules-stale-records/",
                "url": "https://update.dsesecurity.com/updates/intune-device-cleanup-rules-stale-records/",
                "headline": "Clean up stale Intune records without mistaking hiding for retirement",
                "description": "Intune device cleanup rules hide stale records from the admin center and reports. They do not wipe, retire, or remove the corresponding Microsoft Entra…",
                "abstract": "Intune device cleanup rules hide stale records from the admin center and reports. They do not wipe, retire, or remove the corresponding Microsoft Entra device object.",
                "articleBody": "Source fact: what Microsoft documents\nMicrosoft Intune device cleanup rules run on a schedule and automatically hide records for devices that have not checked in during a configured period. Microsoft explicitly states that a cleanup rule does not wipe, retire, or otherwise send an action to the physical device. A hidden record can reappear if the device checks in again before its management certificate expires; after expiry, reenrollment is required.\nThe inactivity setting accepts 30 through 270 days. Administrators can create a rule for all platforms and one rule per individual platform. If both an all-platform rule and a platform-specific rule apply, Microsoft uses the rule with fewer days. A rule applies to all Intune records for that platform rather than to a selected device group. Jamf-managed devices are not supported.\nCleanup does not remove the related Microsoft Entra device object. Microsoft documents separate Entra stale-device management. Intune audit logs record devices hidden by a cleanup rule, and the admin center can preview currently affected devices before rule creation.\nLicensing and applicability\nUsers or devices benefiting from Intune generally require applicable Intune licensing. Configuring cleanup requires an Intune Administrator or a custom role with cleanup-setting permissions and visibility into the devices. Platform-wide behavior means seasonal equipment, spares, kiosks, disaster-recovery devices, long-term leave, ships, remote sites, and devices awaiting repair can be hidden even when they still have an owner and purpose.\nDSE recommendation: production-safe operational steps\n\nExport current device records with platform, serial number, ownership, enrollment type, last check-in, compliance, management certificate, primary user, and corresponding Entra object.\nAsk service owners to identify legitimate long-offline populations and decide how they will be tracked outside the normal active-device view.\nChoose a conservative threshold based on real check-in patterns, certificate life, remote operations, replacement cycles, and support requirements.\nUse Preview affected devices and investigate unexpected critical, shared, or recently issued assets before creating the rule.\nStart with one platform. Review Intune audit events, hidden-device behavior, reporting impact, reenrollment cases, and device reappearance.\nMaintain a separate process for wipe, retire, corporate-data removal, Entra object cleanup, inventory disposal, license recovery, and evidence retention.\nReview the threshold and exceptions after organizational, enrollment, or certificate changes.\n\nDSE recommends treating cleanup as an administrative-view control, not a security containment or asset-disposal control. Do not cite a disappeared Intune record as proof that access was removed or company data was erased. During an investigation, preserve the record and relevant exports before a cleanup rule hides it.\nOfficial reference\nDevice cleanup rules — hiding behavior, thresholds, platform scope, preview, Entra separation, and audit logging.",
                "datePublished": "2026-07-19T21:27:53+00:00",
                "dateModified": "2026-07-19T21:27:53+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/intune-device-cleanup-rules-stale-records/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@id": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": "https://update.dsesecurity.com/assets/dse-updates-share.png",
                "articleSection": [
                    "IT",
                    "Microsoft 365 & Identity"
                ],
                "keywords": [
                    "IT",
                    "Microsoft 365 & Identity",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Microsoft 365 & Identity",
                        "url": "https://update.dsesecurity.com/topic/microsoft-365-identity/"
                    }
                ],
                "wordCount": 422,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Microsoft Learn: Device cleanup rules",
                    "url": "https://learn.microsoft.com/en-us/intune/governance/configure-cleanup-rules",
                    "datePublished": "2026-05-05"
                }
            }
        ]
    }
}