How can i lock device access from a terminated employee using Intune or AD?

Chris Siefert 0 Reputation points
2023-08-31T14:47:26.5333333+00:00

I am able to block the user or reset there password to kick them out of 365, however in all test cases we are still able to log in to the local device with a pin. I'm scratching my head on this one, any ideas? Wipeing the device seems like our best option at at this time.

Microsoft Security | Microsoft Entra | Microsoft Entra ID
Microsoft Security | Intune | Other
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Pavel yannara Mirochnitchenko 13,336 Reputation points MVP
    2023-08-31T15:21:52.1633333+00:00

    Wipe will reset OS to factory setup, OOBE. Delete device account would prevent user to login to device and let Windows stay to login screen. I suggest to use Delete option, in that case user needs to figure out by his own how to boot to install media re-install Windows by his own to keep continue to use the computer.

    Test out the Delete scenario carefully in your infrastructure, but it should behave as I discribed.

    0 comments No comments

  2. Crystal-MSFT 53,981 Reputation points Microsoft External Staff
    2023-09-01T05:19:06.33+00:00

    @Chris Sieferty, Thanks for posting in Q&A. To block one user to access all devices, you can consider disable the user account.

    If you want to block the user to access one or some device, you can try the policy in the following link:

    https://www.inthecloud247.com/restrict-which-users-can-logon-into-a-windows-10-device-with-microsoft-intune/

    Note: None-Microsoft link, just for the reference.

    Thanks for your understanding.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.