azureblog.co.uk
← cd ~/posts

Soft delete for Entra device objects: a safety net for device clean-ups

Deleted device objects can now go into a recoverable state instead of disappearing instantly. A small preview feature that takes the fear out of stale device clean-ups.

2 min read✓ checked 10 Jun 2026Entra ID · Windows · What's new
On this page
  1. A safer stale-device process
  2. Before you delete anything
  3. Disable in bulk

Every tenant collects stale device objects: machines rebuilt, replaced or lost years ago. Cleaning them up is good hygiene, but deleting the wrong device is painful. Its identity, the BitLocker recovery keys stored against it and other security data go with it.

  1. Signing in, managed, compliant
  2. No sign-in for 90 days or more
  3. Can't sign in. Wait and watch for complaints
  4. Recoverable, with keys and identity intact
  5. Gone after the retention period
A device's journey from active to gone.

A new preview adds soft delete for device objects. Deleted devices move into a recoverable state and can be restored within a retention period, with their identity and associated security artifacts intact. It covers , and devices.

A safer stale-device process

  1. Find devices with no sign-in activity for a long period, such as 90 days or more, using the approximateLastSignInDateTime property.
  2. Disable them first and wait. If nobody complains, move on.
  3. Check Intune and your other tools so you're not deleting a device that's still managed.
  4. Delete in batches. With soft delete, a mistake can be restored rather than rebuilt.
powershell
Connect-MgGraph -Scopes "Device.Read.All"

$cutoff = (Get-Date).AddDays(-90)
Get-MgDevice -All -Property DisplayName,OperatingSystem,ApproximateLastSignInDateTime,AccountEnabled |
  Where-Object { $_.ApproximateLastSignInDateTime -lt $cutoff } |
  Sort-Object ApproximateLastSignInDateTime |
  Select-Object DisplayName, OperatingSystem, ApproximateLastSignInDateTime, AccountEnabled
Preview caveat: while it's in preview, check the documentation for the current retention period before relying on it.

Before you delete anything

CheckWhy
Is it still in Intune?A device that checks in with Intune but shows an old sign-in date may just be a device nobody signs in to interactively, such as a kiosk.
Are BitLocker keys stored against it?If the disk might still be needed, export the recovery key first.
Is it a hybrid joined device?Deleting it in Entra while it still exists in AD and syncs brings it back. Clean up in AD first.
Is it an device?Autopilot registrations are separate. Remove them only when the hardware is really leaving.

Disable in bulk

powershell
Connect-MgGraph -Scopes "Device.ReadWrite.All"
$cutoff = (Get-Date).AddDays(-90)
$stale = Get-MgDevice -All -Property Id,DisplayName,ApproximateLastSignInDateTime,AccountEnabled |
  Where-Object { $_.AccountEnabled -and $_.ApproximateLastSignInDateTime -lt $cutoff }
$stale | Export-Csv stale-devices.csv -NoTypeInformation   # keep a record
$stale | ForEach-Object { Update-MgDevice -DeviceId $_.Id -AccountEnabled:$false }
Does disabling a device wipe it?

No. It stops the device authenticating to Entra, which blocks device-based access. Wiping is an Intune action.

What's the benefit over just disabling?

Disabled devices still clutter the directory and count against limits. Soft delete lets you finish the clean-up while keeping a way back.