devices with no recent check in InTune - best practices

crib bar 846 Reputation points
2023-05-30T10:51:10.3333333+00:00

When we run a report of all devices in InTune, there are often numerous with no recent check in activity (often several months or longer). I am trying to determine the best practice to handle these devices, assuming they may actually represent old hardware no longer in active use.

In classic on-prem AD if you had equivalents for say office based workstation, there was often a process to disable the computer objects in AD after a set period of no recent login activity. What could/should be done with equivalents in say Android mobile devices in InTune?

And more specifically, what if any are the risks in just leaving the unused/possibly disposed of devices in InTune?

Microsoft Security | Intune | Microsoft Intune Android
Microsoft Security | Intune | Configuration
Microsoft Security | Intune | Enrollment
Microsoft Security | Intune | Other
0 comments No comments
{count} votes

Accepted answer
  1. Crystal-MSFT 53,986 Reputation points Microsoft External Staff
    2023-05-31T01:55:21.8966667+00:00

    @crib bar Thanks for posting in Q&A. Based on the information provided, it is important to ensure that devices periodically check in with the Intune service to maintain access to protected corporate resources. If a device has not checked in for several months or longer, it may be inactive or no longer in use. In order to maintain the security of the environment and focus resources on managing active devices, it is recommended to remove stale or unused devices.

    For Android mobile devices in Intune, you can use the Inactive Devices Report to identify inactive or stale devices. The Microsoft Learn article titled "How To: Manage stale devices in Azure AD" provides steps for efficiently managing stale devices in your environment, which can also be applied to Android devices managed in Intune. One option is to retire or delete stale or unresponsive devices that have not checked in for a certain period of time.

    Leaving unused or possibly disposed of devices in Intune poses potential security risks such as the devices being compromised or used to access corporate resources. It is important to ensure that all devices are managed properly to maintain the security of your environment. Therefore, it is recommended to periodically remove any stale or unused devices from Intune.

    References:

    Hope the above information can help.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. crib bar 846 Reputation points
    2023-05-30T10:55:27.41+00:00

    And more specifically, what if any are the risks in just leaving the unused/possibly disposed of devices in InTune?


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.