devices with no recent check in InTune - best practices

crib bar 841 Reputation points
2023-05-30T10:51:10.3333333+00:00

When we run a report of all devices in InTune, there are often numerous with no recent check in activity (often several months or longer). I am trying to determine the best practice to handle these devices, assuming they may actually represent old hardware no longer in active use.

In classic on-prem AD if you had equivalents for say office based workstation, there was often a process to disable the computer objects in AD after a set period of no recent login activity. What could/should be done with equivalents in say Android mobile devices in InTune?

And more specifically, what if any are the risks in just leaving the unused/possibly disposed of devices in InTune?

Microsoft Intune Android
Microsoft Intune Android
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Android: An open-source mobile platform based on the Linux kernel, developed by Google, and maintained by the Open Handset Alliance.
295 questions
Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,904 questions
Microsoft Intune Enrollment
Microsoft Intune Enrollment
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Enrollment: The process of requesting, receiving, and installing a certificate.
1,366 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
5,100 questions
0 comments No comments
{count} votes

Accepted answer
  1. Crystal-MSFT 48,846 Reputation points Microsoft Vendor
    2023-05-31T01:55:21.8966667+00:00

    @crib bar Thanks for posting in Q&A. Based on the information provided, it is important to ensure that devices periodically check in with the Intune service to maintain access to protected corporate resources. If a device has not checked in for several months or longer, it may be inactive or no longer in use. In order to maintain the security of the environment and focus resources on managing active devices, it is recommended to remove stale or unused devices.

    For Android mobile devices in Intune, you can use the Inactive Devices Report to identify inactive or stale devices. The Microsoft Learn article titled "How To: Manage stale devices in Azure AD" provides steps for efficiently managing stale devices in your environment, which can also be applied to Android devices managed in Intune. One option is to retire or delete stale or unresponsive devices that have not checked in for a certain period of time.

    Leaving unused or possibly disposed of devices in Intune poses potential security risks such as the devices being compromised or used to access corporate resources. It is important to ensure that all devices are managed properly to maintain the security of your environment. Therefore, it is recommended to periodically remove any stale or unused devices from Intune.

    References:

    Hope the above information can help.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. crib bar 841 Reputation points
    2023-05-30T10:55:27.41+00:00

    And more specifically, what if any are the risks in just leaving the unused/possibly disposed of devices in InTune?


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.