What you need to know
Intune device cleanup rules hide stale records from the admin center and reports. They do not wipe, retire, or remove the corresponding Microsoft Entra device object.
Potentially affected
Microsoft Intune tenants with stale, duplicate, seasonal, long-offline, replaced, or unenrolled device records across supported platforms.
DSE recommendation
Preview affected devices, reconcile owners and exceptions, select a conservative platform-wide inactivity threshold, monitor audit events, and manage Intune and Entra lifecycle records separately.
Source fact: what Microsoft documents
Microsoft Intune device cleanup rules run on a schedule and automatically hide records for devices that have not checked in during a configured period. Microsoft explicitly states that a cleanup rule does not wipe, retire, or otherwise send an action to the physical device. A hidden record can reappear if the device checks in again before its management certificate expires; after expiry, reenrollment is required.
The inactivity setting accepts 30 through 270 days. Administrators can create a rule for all platforms and one rule per individual platform. If both an all-platform rule and a platform-specific rule apply, Microsoft uses the rule with fewer days. A rule applies to all Intune records for that platform rather than to a selected device group. Jamf-managed devices are not supported.
Cleanup does not remove the related Microsoft Entra device object. Microsoft documents separate Entra stale-device management. Intune audit logs record devices hidden by a cleanup rule, and the admin center can preview currently affected devices before rule creation.
Licensing and applicability
Users or devices benefiting from Intune generally require applicable Intune licensing. Configuring cleanup requires an Intune Administrator or a custom role with cleanup-setting permissions and visibility into the devices. Platform-wide behavior means seasonal equipment, spares, kiosks, disaster-recovery devices, long-term leave, ships, remote sites, and devices awaiting repair can be hidden even when they still have an owner and purpose.
DSE recommendation: production-safe operational steps
- Export current device records with platform, serial number, ownership, enrollment type, last check-in, compliance, management certificate, primary user, and corresponding Entra object.
- Ask service owners to identify legitimate long-offline populations and decide how they will be tracked outside the normal active-device view.
- Choose a conservative threshold based on real check-in patterns, certificate life, remote operations, replacement cycles, and support requirements.
- Use Preview affected devices and investigate unexpected critical, shared, or recently issued assets before creating the rule.
- Start with one platform. Review Intune audit events, hidden-device behavior, reporting impact, reenrollment cases, and device reappearance.
- Maintain a separate process for wipe, retire, corporate-data removal, Entra object cleanup, inventory disposal, license recovery, and evidence retention.
- Review the threshold and exceptions after organizational, enrollment, or certificate changes.
DSE recommends treating cleanup as an administrative-view control, not a security containment or asset-disposal control. Do not cite a disappeared Intune record as proof that access was removed or company data was erased. During an investigation, preserve the record and relevant exports before a cleanup rule hides it.
Official reference
Device cleanup rules — hiding behavior, thresholds, platform scope, preview, Entra separation, and audit logging.
Review the official source
Microsoft Learn: Device cleanup rules · Published May 5, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE