Skip to content
Automatically Delete Old User Profiles after 40 Days in Windows using Intune

Automatically Delete Old User Profiles after 40 Days in Windows using Intune

Written By Anoop C Nair
Last Updated August 22, 2024
Posted In Intune
SHARE

Let’s talk about how to automatically delete Old User Profiles after 40 Days in Windows using Intune. To do this, you can set up an Intune policy that targets devices and removes profiles that haven’t been used for a specified number of days.

This helps eliminate unnecessary profiles that take up space and could cause security issues. By setting specific rules, like how many days of inactivity before a profile is deleted, you can keep your devices clean and secure without needing to do it manually.

There is an easy way to solve this problem for customers using Microsoft Intune. If you are not using Intune yet to manage your devices or are co-managing (ensuring the device configuration is moved to Intune), you can use Group Policy (GPO) to achieve the same result.

In this post, you will find all the details on automatically deleting old user profiles in Windows using Intune. We will guide you through setting up a policy that removes inactive profiles, helping you keep your devices clean and secure.

Patch My PC

Why is it Important to Manage User Profiles in Windows?


Managing user profiles is important because it helps keep the system organized and running smoothly. Old or inactive profiles can mess the system, leading to performance issues and potential security risks.

Windows CSP Details CleanupProfiles

We will review the Windows CSP details for the CleanupProfiles policy setting. This setting enables administrators to automatically remove user profiles that haven’t been used for a specified number of days when the system restarts.

CSP URI – ./Device/Vendor/MSFT/Policy/Config/ADMX_UserProfiles/CleanupProfiles

Automatically Delete Old User Profiles after 40 Days in Windows using Intune - Fig.1
Automatically Delete Old User Profiles after 40 Days in Windows using Intune – Fig.1

Automatically Delete Old User Profiles after 40 Days in Windows using Intune

Intune provides a few ways to manage user profiles, such as Remediation Scripts, Scheduled Tasks and Configuration Profiles. Out of these, using Configuration Profiles through the Settings Catalog is the easiest and most effective method. It simplifies the process and helps you manage user profiles with less effort.

  • Sign in to the Intune portal.
  • Navigate to Device > Windows > Configurations.
  • Click Create and then select New Policy.
  • Choose “Settings Catalog” for the profile type and “Windows 10 and later” as the platform.
Automatically Delete Old User Profiles after 40 Days in Windows using Intune - Fig.2
Automatically Delete Old User Profiles after 40 Days in Windows using Intune – Fig.2

Give the policy a name, such as “User Profile Cleanup in Windows,” and optionally provide a description to explain its purpose. This helps keep your policies organized and ensures clarity about their function.

Automatically Delete Old User Profiles after 40 Days in Windows using Intune - Fig.3
Automatically Delete Old User Profiles after 40 Days in Windows using Intune- Fig.3

Under the Configuration tab, click the “Add Settings” hyperlink. In the “Settings picker”, search for “Delete user profiles older than.” You can browse by category to find it under Administrative Templates > System > User Profiles. There will be 2 options under the User Profiles subcategory; they are as follows.

  • Delete user profiles older than a specified number of days on system restart
  • Delete user profiles older than (days) (Device)
Automatically Delete Old User Profiles after 40 Days in Windows using Intune - Fig.4
Automatically Delete Old User Profiles after 40 Days in Windows using Intune – Fig.4

This policy setting allows an administrator to automatically delete user profiles not used within a specified number of days on system restart. If you enable this policy setting, the User Profile Service will automatically delete the following system and restart all user profiles on the computer that have not been used within the specified number of days.

  • If you disable or do not configure this policy setting, the User Profile Service will not automatically delete any profiles on the next system restart.

Note: One day is interpreted as 24 hours after a specific user profile was accessed.

Settings NameEnable
Delete user profiles older than a specified number of days on system restartToggle the pane to the Right side.
Automatically Delete Old User Profiles after 40 Days in Windows using Intune – Table 1
Automatically Delete Old User Profiles in Windows using Intune - Fig.5
Automatically Delete Old User Profiles after 40 Days in Windows using Intune – Fig.5

Scope tags are not very critical in this context. The Assignments category is where you assign the policy to specific groups. You will see 2 categories in the Assignments section: Included and Excluded groups. This allows you to define which groups will receive the policy and which will not.

  • You can easily add groups using the Add Groups option under the Included group.
Automatically Delete Old User Profiles after 40 Days in Windows using Intune - Fig.6
Automatically Delete Old User Profiles after 40 Days in Windows using Intune – Fig.6

Check your settings in the Review + Create tab to ensure everything is correct. Once you click Create, your changes will be saved, and the profile will be assigned.

Automatically Delete Old User Profiles after 40 Days in Windows using Intune - Fig.7
Automatically Delete Old User Profiles after 40 Days in Windows using Intune – Fig.7

End-results

Old user profiles will be automatically deleted according to the device settings where the policy has been applied successfully. This helps keep your system clean and removes outdated profiles without manual effort.

  • The Notification shows that the “Policy User profile cleanup in Windows was created successfully”.
  • The Device and the user check-in status show that the number of succeeded is 1.
Automatically Delete Old User Profiles in Windows using Intune - Fig.8
Automatically Delete Old User Profiles after 40 Days in Windows using Intune – Fig.8

We are on WhatsApp now. To get the latest step-by-step guides, news, and updates, Join our Channel. Click here. HTMD WhatsApp.

Author

Anoop C Nair has been Microsoft MVP from 2015 onwards for 10 consecutive years! He is a Workplace Solution Architect with more than 22+ years of experience in Workplace technologies. He is also a Blogger, Speaker, and Local User Group Community leader. His primary focus is on Device Management technologies like SCCM and Intune. He writes about technologies like Intune, SCCM, Windows, Cloud PC, Windows, Entra, Microsoft Security, Career, etc.

Written by

Anoop C Nair is Workplace Technology solution architect with 25+ years of experience in global enterprise organizations such as JP Morgan, Capgemini, etc. Microsoft Certified Trainer. Microsoft MVP from 2015 onwards for consecutive 11+ years! He also conducts Intune and modern workplace tech training for enterprise organizations. He is Blogger, Speaker, and Founder of HTMD Community and HTMD Conference. His main focus is on Device Management technologies like Intune, Windows, Cloud PC. He writes about technologies like Intune, SCCM, Windows, Cloud PC, Windows, Entra, Microsoft Security.

Discussion · 2 comments

  1. this setting doesnt works for me , because NTuser.dat always shows current date even those users havent logged in recently .

  2. This only does half the job, it removed the entry from profilelist registry entry but leaves the folders untouched in c:\users

Join the discussion

Your email address will not be published. Required fields are marked *

Related guides

Intune

Simplify Windows Devices to Run Only the Required Applications using Intune

Key Takeaways Hey, let’s learn about Simplify Windows Devices to Run Only the Required Applications using Intune. This policy lets administrators replace the default windows shell with a custom or lightweight shell. it improves performance by using system resources and is useful for devices that run a dedicated application. If the policy is disabled or […]

AC Anoop C Nair 8 min read
Intune

Enhance macOS Compliance with Custom Security and Compliance Checks to Improve Device Security using Microsoft Intune

Key Takeaways In this post we are discussing about Enhance macOS Compliance with Custom Security and Compliance Checks to Improve Device Security using Microsoft Intune. Microsoft has announced the general availability of Custom Compliance Settings for macOS in Microsoft Intune. The feature helps organizations strengthen security controls while supporting many types of macOS management scenarios. […]

AC Anoop C Nair 4 min read
Intune

Manage Samsung Galaxy Firmware Versions to Improve Security and Compliance using Microsoft Intune

Key Takeaways In this post we are discussing Manage Samsung Galaxy Firmware Versions to Improve Security and Compliance using Microsoft Intune. Microsoft Intune has received a new update that expands firmware management capabilities for Samsung Galaxy devices through Firmware Versionsintegration. This enhancement gives IT administrators more control over firmware and operating system updates, helping them […]

AC Anoop C Nair 4 min read
Intune

MS Intune Adds Windows Registry Data Collection to Device Inventory for Single Values All Key Values and Subkeys

Key Takeaways Microsoft Intune 2607 introduces Windows Registry Data collection in Device Inventory, allowing IT admins to verify actual device configurations without relying on custom discovery or remediation scripts. Using the Properties Catalog, admins can collect registry information through Single Value, All Values Under a Key (Non-Recursive), or Same Value Across Subkeys. MS Intune Adds […]

AC Anoop C Nair 5 min read