Need to restore a device record recently deleted from intune

Jeremy Hildeen 0 Reputation points
2024-05-09T21:45:32.9633333+00:00

Greetings Internet Hive Mind.

iI have quite a conundrum on my hands. I recently had a user leave my company who took it upon himself to wipe his hard drive on the way out. Attempts to recover the data have all failed. Following the IT protocol I have deleted the device from AD, AAD and Intune. Now I am told they want to go after this former employee legally and want every record they can find on him. Is there a way to recover this recently deleted intune record? I have found bits and peices across the interwebs but nothing solid.

Any help you can provide would be greatly appreciated.

Microsoft Intune Security
Microsoft Intune Security
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
419 questions
Microsoft Intune Enrollment
Microsoft Intune Enrollment
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Enrollment: The process of requesting, receiving, and installing a certificate.
1,366 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
5,096 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. ZhoumingDuan-MSFT 13,160 Reputation points Microsoft Vendor
    2024-05-10T02:08:35.2333333+00:00

    @Jeremy Hildeen, Thanks for posting in Q&A.

    From your description, I know you want to restore a device record recently deleted from Intune.

    Based on my searches, there is no way to recover a device that has been deleted from Intune, you will need to re-join the device to Intune, but you can check the Audit logs to find out which user deleted a device as well as make sure that the device was actually indeed enrolled to Intune.

    Here is the location of the Audit log.

    Intune portal > Tenant administration > Audit logs

    User's image

    Moreover, you can check the logs in the Event Viewer and look for the Intune cert issued by Sc_Online_Issuing on the device side to confirm that the device was enrolled to Intune.

    Location of Log: Event Viewer > Applications and Services Logs > Microsoft > Windows > DeviceManagement-Enterprise-Diagnostics-Provider > Admin

    Location of certificate: From the Start menu, type Run > MMC > Choose File > Add/Remove Snap-ins > Double-click Certificates, choose Computer account > Next, and select Local Computer > Double-click Certificates (Local computer) and choose Personal > Certificates.

    Hope it will help.

    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.