Offboard a device from Microsoft Defender for Business
Article
As devices are replaced or retired, or your business needs change, you can offboard devices from Defender for Business. Offboarding a device causes the device to stop sending data to Defender for Business. However, data received prior to offboarding is retained for up to six (6) months.
In the navigation pane, choose Settings, and then choose Endpoints.
Under Device management, choose Offboarding.
Select an operating system, such as Windows 10 and 11, and then, under Offboard a device, in the Deployment method section, choose Local script.
In the confirmation screen, review the information, and then choose Download to proceed.
Select Download offboarding package. We recommend saving the offboarding package to a removable drive.
Run the script on each device that you want to offboard.
Mac
Go to Finder > Applications.
Right click on Microsoft Defender for Business, and then choose Move to Trash. --- or --- Use the following command: sudo '/Library/Application Support/Microsoft/Defender/uninstall/uninstall'.
In the navigation pane, choose Settings > Endpoints, and then under Device management, choose Offboarding.
Select an operating system, such as Windows Server 1803, 2019, and 2022, and then in the Deployment method section, choose Local script.
Select Download package. We recommend that you save the offboarding package to a removable drive. The zipped folder will be called WindowsDefenderATPOffboardingPackage_valid_until_YYYY-MM-DD.zip (where YYYY-MM-DD is the expiry date of the package).
On your Windows Server device, extract the contents of the zipped folder to a location such as the Desktop folder.
Open a command prompt as an administrator.
Type the location of the script file. For example, if you copied the file to the Desktop folder, you would type %userprofile%\Desktop\WindowsDefenderATPOffboardingScript_valid_until_2022-11-11.cmd (where YYYY-MM-DD is the expiry date of the package), and then press Enter (or select OK).
In the navigation pane, choose Settings > Endpoints, and then under Device management, choose Offboarding.
Select Linux Server for the operating system, and then in the Deployment method section, choose Local script.
Select Download package. We recommend that you save the offboarding package to a removable drive. The zipped folder will be called WindowsDefenderATPOffboardingPackage_valid_until_YYYY-MM-DD.zip (where YYYY-MM-DD is the expiry date of the package).
On your Linux Server device, extract the contents of the zipped folder to a location such as the Desktop folder.
Open a terminal, and navigate to the directory where the MicrosoftDefenderATPOffboardingLinuxServer_valid_until_YYYY-MM-DD file (where YYYY-MM-DD is the expiry date of the file) is located.
Type python MicrosoftDefenderATPOffboardingLinuxServer_valid_until_YYYY-MM-DD.py in the terminal.
Tip
For more information, see Uninstall in the Microsoft Defender for Endpoint on Linux guidance.
Mobile devices
You can use Microsoft Intune to manage mobile devices, such as iOS, iPadOS, and Android devices.