Skip to content
Microsoft Introduces Platform Level Device Cleanup Rules in Intune with Scoped RBAC Permissions

Microsoft Introduces Platform Level Device Cleanup Rules in Intune with Scoped RBAC Permissions

Written By Anoop C Nair
Last Updated January 17, 2025
Posted In Intune
SHARE

Microsoft Introduces Platform Level Device Cleanup Rules in Intune with Scoped RBAC Permissions! Microsoft has introduced a new Intune feature to make device management easier.

This update shows Microsoft’s commitment to providing IT administrators with powerful tools to manage devices more effectively throughout their lifecycle. This new feature helps admins keep their systems clean and secure by more effectively targeting and removing outdated devices for each platform.

Device Cleanup Rules help IT administrators automatically remove unused, inactive, or outdated devices from their system. These rules are typically used to maintain a clean and secure environment by identifying devices that have not been active for a specified period.

In this post, you will find all the details about Microsoft’s new feature: Platform-Level Device Cleanup Rules in Intune with Scoped RBAC Permissions. We will explain everything you need to know about these rules and how they work in simple terms.

Patch My PC
Microsoft Introduces Platform Level Device Cleanup Rules in Intune with Scoped RBAC Permissions - Fig.1
Microsoft Introduces Platform Level Device Cleanup Rules in Intune with Scoped RBAC Permissions – Fig.1

Platform Level Device Cleanup Rules in Intune with Scoped RBAC Permissions

Intune allows you to set up automatic device removal for inactive, stale, or unresponsive devices. These cleanup rules keep your device list updated by checking device activity regularly. Any device that isn’t active gets removed from Intune management, ensuring only active devices are shown. This applies to all devices managed by Intune, not just selected ones.

OS Platform Level Targeting of Device Cleanup Rule

Platform-level targeting for Device Cleanup rules helps admins remove stale or inactive devices from their system based on the number of inactive days they set. These scoped and targeted rules allow admins to focus on specific platforms or operating systems, making it easier to manage and clean up devices.

FeatureDescription
Device Cleanup Rules per PlatformSet one cleanup rule for each platform (Windows, iOS/macOS, iPadOS, Android, Linux).
Different RBAC PermissionsConfigure and assign different RBAC permissions for device cleanup management.
Active Days RuleAdmins can specify how many days of inactivity should trigger device removal.
Scoped and Targeted CleanupAllows admins to configure and apply cleanup rules at platform or OS level.
Microsoft Introduces Platform Level Device Cleanup Rules in Intune with Scoped RBAC Permissions – Table 1

How Device Cleanup Rules Work

When a device cleanup rule runs, it removes the device from Intune. The device must then go through the re-enrollment process to reappear in the console. The list below shows the steps to configure device cleanup rules.

  • Go to the Microsoft Intune admin center.
  • Select Devices > Device cleanup rules and enable the option by choosing Yes.
  • In the Delete devices that haven’t checked in for this many days field, enter a value between 30 and 270 days.
  • Click Save to apply the rule.
Microsoft Introduces Platform Level Device Cleanup Rules in Intune with Scoped RBAC Permissions - Fig.2
Microsoft Introduces Platform Level Device Cleanup Rules in Intune with Scoped RBAC Permissions – Fig.2

Important Details about Device Cleanup Rules

Let’s go over some key points about Device Cleanup Rules. The table below provides a simple overview of all the important details.

FeatureDetails
Device ReappearanceRemoved devices that check in before certification expires will reappear in the admin centre.
No Wipe or Retire ActionDevice cleanup rules do not trigger a wipe or retire for the device.
BitLocker EncryptionCleanup rules do not suspend BitLocker when Intune manages encryption.
Jamf-Managed DevicesDevice cleanup rules are not available for Jamf-managed devices.
Required PermissionTo update cleanup rules, you need the “Managed Device Cleanup Settings” permission with “Update” set to Yes.
Microsoft Introduces Platform Level Device Cleanup Rules in Intune with Scoped RBAC Permissions - Fig.3
Microsoft Introduces Platform Level Device Cleanup Rules in Intune with Scoped RBAC Permissions – Fig.3

Need Further Assistance or Have Technical Questions?

Join the LinkedIn Page and Telegram group to get the latest step-by-step guides and news updates. Join our Meetup Page to participate in User group meetings. Also, Join the WhatsApp Community to get the latest news on Microsoft Technologies. We are there on Reddit as well.

Resources

In development – Microsoft Intune | Microsoft Learn

Author

Anoop C Nair has been Microsoft MVP from 2015 onwards for 10 consecutive years! He is a Workplace Solution Architect with more than 22+ years of experience in Workplace technologies. He is also a Blogger, Speaker, and Local User Group Community leader. His primary focus is on Device Management technologies like SCCM and Intune. He writes about technologies like Intune, SCCM, Windows, Cloud PC, Windows, Entra, Microsoft Security, Career, etc.

Written by

Anoop C Nair is Workplace Technology solution architect with 25+ years of experience in global enterprise organizations such as JP Morgan, Capgemini, etc. Microsoft Certified Trainer. Microsoft MVP from 2015 onwards for consecutive 11+ years! He also conducts Intune and modern workplace tech training for enterprise organizations. He is Blogger, Speaker, and Founder of HTMD Community and HTMD Conference. His main focus is on Device Management technologies like Intune, Windows, Cloud PC. He writes about technologies like Intune, SCCM, Windows, Cloud PC, Windows, Entra, Microsoft Security.

Discussion

Join the discussion

Your email address will not be published. Required fields are marked *

Related guides

Intune

Simplify Windows Devices to Run Only the Required Applications using Intune

Key Takeaways Hey, let’s learn about Simplify Windows Devices to Run Only the Required Applications using Intune. This policy lets administrators replace the default windows shell with a custom or lightweight shell. it improves performance by using system resources and is useful for devices that run a dedicated application. If the policy is disabled or […]

AC Anoop C Nair 8 min read
Intune

Enhance macOS Compliance with Custom Security and Compliance Checks to Improve Device Security using Microsoft Intune

Key Takeaways In this post we are discussing about Enhance macOS Compliance with Custom Security and Compliance Checks to Improve Device Security using Microsoft Intune. Microsoft has announced the general availability of Custom Compliance Settings for macOS in Microsoft Intune. The feature helps organizations strengthen security controls while supporting many types of macOS management scenarios. […]

AC Anoop C Nair 4 min read
Intune

Manage Samsung Galaxy Firmware Versions to Improve Security and Compliance using Microsoft Intune

Key Takeaways In this post we are discussing Manage Samsung Galaxy Firmware Versions to Improve Security and Compliance using Microsoft Intune. Microsoft Intune has received a new update that expands firmware management capabilities for Samsung Galaxy devices through Firmware Versionsintegration. This enhancement gives IT administrators more control over firmware and operating system updates, helping them […]

AC Anoop C Nair 4 min read
Intune

MS Intune Adds Windows Registry Data Collection to Device Inventory for Single Values All Key Values and Subkeys

Key Takeaways Microsoft Intune 2607 introduces Windows Registry Data collection in Device Inventory, allowing IT admins to verify actual device configurations without relying on custom discovery or remediation scripts. Using the Properties Catalog, admins can collect registry information through Single Value, All Values Under a Key (Non-Recursive), or Same Value Across Subkeys. MS Intune Adds […]

AC Anoop C Nair 5 min read