Soft delete for Entra device objects: a safety net for device clean-ups
Deleted device objects can now go into a recoverable state instead of disappearing instantly. A small preview feature that takes the fear out of stale device clean-ups.
Every tenant collects stale device objects: machines rebuilt, replaced or lost years ago. Cleaning them up is good hygiene, but deleting the wrong device is painful. Its identity, the BitLocker recovery keys stored against it and other security data go with it.
- Signing in, managed, compliant
- No sign-in for 90 days or more
- Can't sign in. Wait and watch for complaints
- Recoverable, with keys and identity intact
- Gone after the retention period
A new preview adds soft delete for device objects. Deleted devices move into a recoverable state and can be restored within a retention period, with their identity and associated security artifacts intact. It covers Entra joined, Entra registered and hybrid joined devices.
A safer stale-device process
- Find devices with no sign-in activity for a long period, such as 90 days or more, using the
approximateLastSignInDateTimeproperty. - Disable them first and wait. If nobody complains, move on.
- Check Intune and your other tools so you're not deleting a device that's still managed.
- Delete in batches. With soft delete, a mistake can be restored rather than rebuilt.
Connect-MgGraph -Scopes "Device.Read.All"
$cutoff = (Get-Date).AddDays(-90)
Get-MgDevice -All -Property DisplayName,OperatingSystem,ApproximateLastSignInDateTime,AccountEnabled |
Where-Object { $_.ApproximateLastSignInDateTime -lt $cutoff } |
Sort-Object ApproximateLastSignInDateTime |
Select-Object DisplayName, OperatingSystem, ApproximateLastSignInDateTime, AccountEnabledBefore you delete anything
| Check | Why |
|---|---|
| Is it still in Intune? | A device that checks in with Intune but shows an old sign-in date may just be a device nobody signs in to interactively, such as a kiosk. |
| Are BitLocker keys stored against it? | If the disk might still be needed, export the recovery key first. |
| Is it a hybrid joined device? | Deleting it in Entra while it still exists in AD and syncs brings it back. Clean up in AD first. |
| Is it an Autopilot device? | Autopilot registrations are separate. Remove them only when the hardware is really leaving. |
Disable in bulk
Connect-MgGraph -Scopes "Device.ReadWrite.All"
$cutoff = (Get-Date).AddDays(-90)
$stale = Get-MgDevice -All -Property Id,DisplayName,ApproximateLastSignInDateTime,AccountEnabled |
Where-Object { $_.AccountEnabled -and $_.ApproximateLastSignInDateTime -lt $cutoff }
$stale | Export-Csv stale-devices.csv -NoTypeInformation # keep a record
$stale | ForEach-Object { Update-MgDevice -DeviceId $_.Id -AccountEnabled:$false }Does disabling a device wipe it?
No. It stops the device authenticating to Entra, which blocks device-based access. Wiping is an Intune action.
What's the benefit over just disabling?
Disabled devices still clutter the directory and count against limits. Soft delete lets you finish the clean-up while keeping a way back.