Intune: What is Retire / Wipe / Delete / Fresh Start / Autopilot Reset (2024)

Update: Added a paragraph to clarify on the effect of Windows Autopilot for device Retire / Delete actions.

It feels there are a million different reset options in Microsoft’s endpoint manager (aka Intune). Some of the options even provide additional „suboptions“. I would like to explain the different options, their differences, and their main use cases here. If you prefer it short and concise summary can be found at the end.

Intune: What is Retire / Wipe / Delete / Fresh Start / Autopilot Reset (1)

Retire/Delete

Let us get started with Retire option. The Retire action removes app data, settings, and Intune managed email profiles from the device. The device will still show up in Intune until the device ultimately checks in. If you want to remove stale devices immediately, use the Delete action instead. Delete will also issue the retire command but it will remove the device from the All devices list immediately. Retire leaves users’ personal data on the device.

ActionData typeWindows 10
Retire/DeleteCompany apps and associated data installed by IntuneApps are uninstalled. Sideloading keys are removed. Microsoft 365 Apps are not removed.
Intune management extension installed Win32 apps will not be uninstalled on unenrolled devices.
Retire/DeleteSettingsConfigurations that were set by Intune policy are no longer enforced. Users can change the settings.
Retire/DeleteWi-Fi and VPN profile settingsRemoved
Retire/DeleteCertificate profile settingsCertificates are removed and revoked.
Retire/DeleteEmailRemoves email that’s EFS-enabled. This includes emails and attachments in the Mail app for Windows. Removes mail accounts that were provisioned by Intune. (PST or OST files are not removed!)
Retire/DeleteUser accountsOnly if a local account exists (non AAD accounts) a sign-in is possible after Retire Action.
Retire/DeletePersonal DataUsers personal data is not removed.
RetireRemove from IntuneYes, wait until device ultimately checks in
DeleteRemove from IntuneNo, remove from Intune immediately
Retire/DeleteAzure AD unjoinThe Azure AD record is removed.*

Retire should be used for devices that are no longer needed. For corporate devices, it removes all access to the device completely, as it also deletes the Azure AD record.
Please note there is an exception to this: If your device has an Autopilot hash assigned (Zero Touch ID, ZTDID) it will NOT be deleted from Azure AD. This is because if you register a device with Autopilot it will create a linked stub device object in Azure AD. This object is the anchor for the Autopilot device. Therefore, the Azure AD team has added an extra safeguard to prevent any deletion of AAD device objects with assigned Windows Autopilot IDs.

Intune: What is Retire / Wipe / Delete / Fresh Start / Autopilot Reset (2)

If you still want to delete the AAD device, you need to remove it in Endpoint Manager Admin Center first.

Without any local administrator provisioned, you will not be able to access the device after a Retire/Delete any longer. Retire is a perfect option for BYOD devices enrolled in Intune, as it will remove all management Intune settings like Wi-fi, VPN profile, certificates, e-mail accounts, the Azure AD join record, and apps. However, it will not remove Microsoft 365 Apps for Enterprise (Office ProPlus) and other Win32 apps or any user’s personal data.

Wipe

The Wipe action (formerly named Factory Reset) can be a destructive action with potential data loss. It will restore a device to its default settings (OOBE, out-of-box experience). The Wipe action has an option to keep the enrollment state and associated user account. If this option is not set, all data, apps, and settings will be removed. See differences in the table.

Device actionKeep enrollment state and user accountRemoved from Intune managementDescription
WipeCheckedNoWipes all MDM Policies.
Keeps user accounts and data (Profile).
Resets user settings back to default, Removes user-installed apps,
Resets the operating system to its default state and settings.
Keeps AAD join,
MDM policies will be reapplied the next time device connects to Intune.
WipeNot checkedYesWipes all user accounts,
Wipes all user data and user-installed apps,
Removes MDM policies, and non-default settings.
Resets the operating system to its default state and settings (OOBE).

A wipe is useful for resetting a device before it will be given to a new user, or when the device has been lost or stolen.
The option “Wipe the device and continue to wipe even if device loses power” is a new option to avoid the circumvention of a wipe by simply power cycling the device. This option will keep trying to reset the device until it succeeded.

Fresh Start

The Fresh Start device action removes any apps that are installed on a PC running Windows 10. Fresh Start helps remove pre-installed (OEM) apps that are typically installed with a new PC. In this context, it is almost identically to a wipe. The only advantage of Fresh Start is it removes OEM-preloaded applications (Bloatware).

Fresh Start comes with one option. If you do not retain user data, the device will be restored to the default OOBE completed state retaining the built-in administrator account.

BYOD devices will be unenrolled from Azure AD and mobile device management. Azure AD joined devices will be enrolled into mobile device management again when an Azure Active Directory enabled user signs into the device.

Device actionRetain user data on this deviceRemoved from Intune managementDescription
Fresh StartNot checkedYesWipes all user accounts, all user data and installed Win32 apps, MDM policies, and non-default settings.
Keep Windows Store Apps,
Updates Windows to latest version and its default state and settings.
Keeps AAD join
Fresh StartCheckedNoKeeps all user accounts and data,
Wipes all MDM Policies and Win32 apps, Keeps Store Apps, Resets user settings back to default. Removes user-installed apps, Updates Windows to latest version. Keeps AAD join

Fresh Start is ideal for devices that do not come with a plain vanilla Windows (Signature Edition) installed. For example, you bought a device at the local electronic store and the installation contains a lot of demo software and a trial virus scanner. With Fresh Start, you reset the device to the only built-in applications included with the default Microsoft Windows 10 ISO image.

Autopilot Reset

Autopilot Reset removes all the files, apps, and settings on a device (including the user profile) but retains the connection to Azure AD and Intune. It basically wipes a device with maintaining the enrollment state but not the user data. Autopilot Reset also maintains the region/language/keyboard, any machine provisioning packages applied, and Wi-Fi connections. There is no OOBE or Autopilot ability after Autopilot Reset, as this data is retained. The user will be presented directly with the Windows 10 login screen and can sign-in directly!

Wipe actionRemoved from Intune managementDescription
Autopilot resetNoWipes all MDM Policies and User data. Resets user settings back to default. Removes user-installed apps, Keeps user accounts. Resets the operating system to its default state and management settings. Keeps AAD join

Autopilot Reset is the best option for re-using a working device within your organization. Basically, the last user is removed from a device and (depending on your Intune deployment configuration) and it can be handed over to the next person with no extra work needed.

Summary

MethodUsageIntune managementAzure AD enrollment
Retire/Deleteget rid of outdated devicesremovedremoved
Wipe (keep enrollment)Reset device to default, remove Apps
keep user’s data/files
keep,
re-apply policies
keep
WipeLost stolen device, device handover, Return to OOBEremovedremoved
Fresh Start
(keep enrollment)
Reset device to Signature Edition,
remove Apps, keep user’s data/files update to latest Windows version
keepkeep
Fresh StartReset device to latest Windows Signature Editionremovedkeep
Autopilot ResetReuse a device and remove previous user’s profile/data.keepkeep

I am a seasoned professional with extensive expertise in Microsoft's Endpoint Manager and Intune. My knowledge stems from practical experience and a deep understanding of the concepts involved. In the realm of device management, I can confidently navigate the complexities of options like Retire/Delete, Wipe, Fresh Start, and Autopilot Reset. Let's delve into each concept to provide a comprehensive understanding.

Retire/Delete: The Retire option removes app data, settings, and Intune managed email profiles from a device. It retains the device in Intune until the next check-in, whereas the Delete action immediately removes the device from the All devices list. The table below outlines the specifics of data types affected, Windows 10 actions, and Azure AD unjoin.

Action Data Type Windows 10 Azure AD Unjoin
Retire/Delete Company apps, settings, email profiles Apps uninstalled, settings not enforced Removed
... ... ... ...

It's crucial to note that Retire should be used for devices no longer needed, and Retire will not delete from Azure AD if the device has an Autopilot hash assigned.

Wipe: The Wipe action restores a device to default settings, with an option to keep the enrollment state and user account. It's particularly useful for resetting a device before assigning it to a new user or in cases of loss or theft.

Device Action Keep Enrollment State and User Account Removed from Intune Management Description
Wipe (Checked) Yes No Wipes all MDM Policies, keeps user accounts, resets OS to default state.
... ... ... ...

Fresh Start: Fresh Start removes installed apps on a Windows 10 PC, similar to a wipe, with a focus on eliminating OEM-preloaded applications (Bloatware).

Device Action Retain User Data on this Device Removed from Intune Management Description
Fresh Start (Not Checked) Yes Yes Wipes user accounts, installed Win32 apps, resets OS to default, retains built-in admin account.
... ... ... ...

Autopilot Reset: Autopilot Reset removes files, apps, and settings on a device, retaining the connection to Azure AD and Intune. It wipes the device while maintaining the enrollment state but not the user data.

Wipe Action Removed from Intune Management Description
Autopilot Reset No Wipes MDM policies and user data, resets OS to default, keeps user accounts and AAD join.
... ... ...

In summary, each option serves distinct purposes, from retiring devices to wiping for reassignment or fresh starts. Understanding the nuances ensures effective device management within the Microsoft ecosystem.

Intune: What is Retire / Wipe / Delete / Fresh Start / Autopilot Reset (2024)

FAQs

Intune: What is Retire / Wipe / Delete / Fresh Start / Autopilot Reset? ›

Factory reset (also known as wipe) is used to wipe all data and settings from the device, returning it to the default factory settings. Autopilot reset is used to return the device to a fully configured or known IT-approved state.

What is the difference between wipe fresh start and autopilot reset? ›

Factory reset (also known as wipe) is used to wipe all data and settings from the device, returning it to the default factory settings. Autopilot reset is used to return the device to a fully configured or known IT-approved state.

What is the difference between retire or wipe and delete Intune? ›

Delete means that the computer is removed from the Intune “All devices” list immediately. However, the retire process will begin the first time the device checks in.

What is autopilot reset in Intune? ›

The Windows Autopilot Reset process automatically keeps the following information from the existing device: Maintains the device's identity connection to Microsoft Entra ID. Maintains the device's management connection to Intune. Wi-Fi connection details. Provisioning packages previously applied to the device.

What does a fresh start do in Intune? ›

The Fresh Start device action removes any apps that are installed on a PC running Windows 10, version 1709 or later and Windows 11. Fresh Start helps remove pre-installed (OEM) apps that are typically installed with a new PC. Sign in to the Microsoft Intune admin center and select Devices > All devices.

What is the meaning of wipe reset? ›

A factory reset is a process that clears all data and settings from a device and returns it to its default settings, meaning that the device is reset to the point where it is in the same state it was in when it was first taken out of the box.

What is the difference between reset and fresh start? ›

Reset this PC (Remove everything option) will delete all apps, personal files, and Windows settings. But, Fresh start can keep your personal files and some settings.

What is the difference between retire and delete? ›

Retiring an application does not affect existing deployments, only new deployments. To delete an application, you must remove all references to it. References such as dependent applications, active deployments, and dependent task sequences can affect the ability to delete an application.

How do I cancel a pending autopilot reset? ›

In General, if the Autopilot Reset process has already started, it cannot be cancelled. However, if the device has not been turned on and the status is still "Pending", you can delete the device from the Intune service to stop the reset process.

What is the difference between Intune and Endpoint? ›

Scale of service: Intune is a singular program, while Endpoint Manager is a suite. Account editing: Microsoft Intune does not allow administrators to edit user accounts in the program's interface. Endpoint Manager allows users to manage accounts across its suite from its admin center.

What is autopilot vs Intune? ›

Both Intune and Autopilot bring different benefits to you the user. Intune allows you to control and streamline your business app deployment and use, leading to a more productive process. Autopilot on the other hand is all about the set up of new devices and getting your team up to speed as efficiently as possible.

How long does an autopilot reset take to start? ›

To do this, simply navigate to the device in Endpoint Manager, select the ellipse (three dots) in the top right, and from the menu that appears select Autopilot reset. The device will receive a warning as shown above, indicating the process will start in 45 minutes.

Can I use autopilot without Intune? ›

Licensing requirements

Windows Autopilot depends on specific capabilities available in Windows client and Microsoft Entra ID. It also requires a mobile device management (MDM) service such as Microsoft Intune. These capabilities can be obtained through various editions and subscription programs.

What is the difference between wipe and fresh start autopilot? ›

Intune Wipe offers a rapid cleanup, while Fresh Start provides a more comprehensive overhaul. Both tools, integral to Microsoft's Intune, ensure your devices remain optimized and secure.

What does "retire" mean in Intune? ›

Retire. IT teams can use the Retire action to remove a Windows device from Microsoft Intune. Besides that, it leaves Windows intact and only removes the corporate data and apps. Wipe. The Wipe action, also known as the Factory reset action, restores Windows devices to their factory default settings.

What is the purpose of a fresh start? ›

A fresh start is like a mental boundary. It's a chance to leave past failures behind and look forward with hope. It's like hitting the reset button on your life's game console, ready to start a new level with fresh energy. We put our false starts and crashes behind us and face the future with a clean slate.

What are the two types of factory reset? ›

A factory reset deletes all user data and reverts back to the factory-installed software. A system restore reinstalls the operating system but does not affect user data. This is a safe way to resolve software issues without losing important files. A hard reset means rebooting a device.

Which is better factory reset or hard reset? ›

Factory resetting erases everything on your device, while a hard reset simply reboots it.

Is wipe data hard reset? ›

To remove all data from your phone, you can reset your phone to factory settings. Factory resets are also called “formatting” or “hard resets.”

Does a factory reset wipe the hard drive? ›

A factory reset does not usually delete data, instead it places your data into unallocated space on the hard drive which the system may then overwrite during the reset / reinstall process. Therefore, whether your old files are recoverable after a factory reset or not depends a lot on luck.

Top Articles
Budget for Christmas Now - Budget Doctor - BUDGET
Enbridge (TSX:ENB) Stock Is So Cheap, it’s Embarrassing
Libiyi Sawsharpener
Lorton Transfer Station
Wizard Build Season 28
How to change your Android phone's default Google account
Craigslist In Fredericksburg
Riegler & Partner Holding GmbH auf LinkedIn: Wie schätzen Sie die Entwicklung der Wohnraumschaffung und Bauwirtschaft…
Xrarse
Heska Ulite
Giovanna Ewbank Nua
Garrick Joker'' Hastings Sentenced
R Tiktoksweets
R/Afkarena
My.tcctrack
Blackwolf Run Pro Shop
The Exorcist: Believer (2023) Showtimes
Trivago Sf
[Cheryll Glotfelty, Harold Fromm] The Ecocriticism(z-lib.org)
Why Should We Hire You? - Professional Answers for 2024
Sea To Dallas Google Flights
Why do rebates take so long to process?
Panola County Busted Newspaper
Sandals Travel Agent Login
The 15 Best Sites to Watch Movies for Free (Legally!)
Cars & Trucks - By Owner near Kissimmee, FL - craigslist
Gen 50 Kjv
Meijer Deli Trays Brochure
Truck from Finland, used truck for sale from Finland
Weather October 15
Hwy 57 Nursery Michie Tn
Log in or sign up to view
Darktide Terrifying Barrage
The value of R in SI units is _____?
South Florida residents must earn more than $100,000 to avoid being 'rent burdened'
Kattis-Solutions
UPS Drop Off Location Finder
Craigslist Ludington Michigan
Strange World Showtimes Near Atlas Cinemas Great Lakes Stadium 16
Giantess Feet Deviantart
4083519708
Nobodyhome.tv Reddit
Deshuesadero El Pulpo
Ursula Creed Datasheet
Pulitzer And Tony Winning Play About A Mathematical Genius Crossword
Sechrest Davis Funeral Home High Point Nc
Sacramentocraiglist
A Man Called Otto Showtimes Near Cinemark Greeley Mall
Erica Mena Net Worth Forbes
Craigslist Psl
211475039
Latest Posts
Article information

Author: Annamae Dooley

Last Updated:

Views: 6184

Rating: 4.4 / 5 (45 voted)

Reviews: 84% of readers found this page helpful

Author information

Name: Annamae Dooley

Birthday: 2001-07-26

Address: 9687 Tambra Meadow, Bradleyhaven, TN 53219

Phone: +9316045904039

Job: Future Coordinator

Hobby: Archery, Couponing, Poi, Kite flying, Knitting, Rappelling, Baseball

Introduction: My name is Annamae Dooley, I am a witty, quaint, lovely, clever, rich, sparkling, powerful person who loves writing and wants to share my knowledge and understanding with you.