Managing Windows devices with Microsoft Intune  means having the right tool for every situation. Whether an employee is leaving the organization, a device needs to be repurposed for a new user, or a laptop has persistent performance issues that require a fresh start - knowing which remote action to use can save time and prevent data loss.

Consider these common scenarios:

  • An employee resigns, and their corporate laptop needs to be prepared for the next hire.
  • A contractor’s project ends, and you need to remove company data from their personal device.
  • A user reports their device is slow and cluttered with software accumulated over years.
  • A laptop is reported lost or stolen, and corporate data must be protected immediately.
  • A power user wants to reset their own device without waiting for IT support.

Each of these situations calls for a different approach. Using the wrong action could leave sensitive data exposed, require unnecessary manual intervention, or result in a device that cannot automatically re-enroll.

A split-screen of a Windows laptop transitioning from a cluttered desktop to a clean, fresh one.

In this post, we’ll explore the remote actions available to IT administrators. We’ll explain what each action does, when you should use it, and highlight the differences in how they handle company data, personal data, and overall device management.

Device reset and recovery options

Microsoft Intune offers several device actions for managing Windows devices:

  1. Wipe - Factory reset the device
  2. Retire - Remove corporate management
  3. Fresh Start - Reinstall Windows
  4. Autopilot Reset - Quick device refresh
  5. Delete - Remove the device record
  6. Company Portal Reset - User-initiated reset

To access Device reset and recovery options, sign in to the Microsoft Intune admin center , navigate to Devices > All devices, select a device, and choose the desired action from the device’s toolbar or the ellipsis menu.

Read on to understand when to use each action and what to expect.


Wipe - Factory reset the device

The Wipe action performs a factory reset of the device, restoring it to its default settings. This is the most comprehensive reset option available, removing all personal and organizational data, apps, and configurations. It’s commonly used when a device needs to be retired, repurposed, reset for troubleshooting, or securely erased if lost or stolen.

What happens during a Wipe

  • All user data is removed from the device.
  • All applications (including Microsoft Intune management) are removed.
  • The device is restored to factory default settings.
  • If the device is registered with Windows Autopilot, or the user is targeted with a Windows Autopilot device preparation policy, it will automatically re-enroll upon next setup.

Wipe options

When initiating a Wipe, you have additional options:

OptionDescription
No options selectedPerforms a standard factory reset. The device is wiped and restored to default settings. If registered with Windows Autopilot, or the user is targeted with device preparation, it will automatically re-enroll.
Wipe device, but keep enrollment state and associated user accountResets the device but preserves the Microsoft Entra ID join and Microsoft Intune enrollment. User data is removed, but the device remains managed.
Wipe device and continue to wipe even if device loses powerEnsures the wipe completes even if the device loses power during the process. This writes zeros to the drive.
Wipe options in Microsoft Intune

When to use Wipe

  • Device is being repurposed for a new user.
  • Device contains sensitive data that must be removed.
  • Device is being decommissioned and will be disposed of or sold.
  • Troubleshooting persistent issues that cannot be resolved otherwise.

Risks and considerations

  • All data on the device will be permanently deleted.
  • The process cannot be undone once initiated.
  • If the device is not registered with Windows Autopilot, and the user is not targeted with a Windows Autopilot device preparation policy, it will require manual re-enrollment.
  • The wipe process can take 20-60 minutes depending on device specifications and whether secure wipe is enabled.

Expected timeline

PhaseDuration
Command received by deviceVaries (depends on device check-in)
Wipe process20-60 minutes
Windows Out-of-Box Experience (OOBE)10-20 minutes
Windows Autopilot enrollment15-45 minutes
Total estimated time45-125 minutes
Estimated timeline for Wipe action

Summary: Wipe performs a complete factory reset, removing all data and apps. Requires Windows Autopilot for automatic re-enrollment. Best for device repurposing or decommissioning.


Retire - Remove corporate management

The Retire action removes company data from a device without performing a full wipe or factory reset. This action is ideal for personally owned devices or when transitioning a device out of organizational control. It unenrolls the device from Microsoft Intune and removes managed apps, settings, and profiles deployed through mobile device management (MDM), while preserving personal data.

Unlike the Wipe action, which resets the device to factory settings, Retire keeps user content intact.

What happens during a Retire

  • The device is unenrolled from Microsoft Intune.
  • Company apps deployed through Microsoft Intune are removed.
  • Microsoft Intune management profiles and MDM policies are removed.
  • Company data protected by app protection policies is removed.
  • Personal data, apps, and settings remain on the device.
  • The device remains joined to Microsoft Entra ID (if applicable).
  • The action is triggered the next time the device checks in with Microsoft Intune.

When to use Retire

  • Employee leaves the organization but keeps their personal device (BYOD scenarios).
  • Device transitions from corporate-managed to personal use.
  • Removing management without affecting user data.

Risks and considerations

  • Personal data remains on the device - ensure this aligns with your data protection policies.
  • Company apps are removed, but data created by the user outside managed apps may remain.
  • The device may still be joined to Microsoft Entra ID and may need to be manually removed.
  • The action executes when the device next checks in - until then, the device may still appear in the admin center.
  • If you need to remove a device record immediately, consider using the Delete action instead.
  • For corporate-owned devices, consider using Wipe instead.

Summary: Retire removes company apps, policies, and data while preserving personal content. Best for BYOD scenarios when employees leave.


Fresh Start - Reinstall Windows

The Fresh Start action removes pre-installed (OEM) applications and reinstalls Windows cleanly while preserving user data and Microsoft Entra ID enrollment.

What happens during Fresh Start

  • Windows is reinstalled cleanly.
  • Pre-installed OEM applications (bloatware) are removed.
  • User data and settings can optionally be retained.
  • Microsoft Entra ID join is preserved.
  • Device re-enrolls in Microsoft Intune automatically.

When to use Fresh Start

  • Device performance has degraded due to accumulated software.
  • OEM bloatware is causing issues or security concerns.

Risks and considerations

  • All installed applications (except built-in Windows apps) are removed.
  • The process requires a stable internet connection.
  • Can take significant time depending on Windows update size.
  • User data retention is optional - verify settings before initiating.

Expected timeline

PhaseDuration
Command received by deviceVaries (depends on device check-in)
Windows reinstallation30-90 minutes
Microsoft Intune re-enrollment15-30 minutes
Total estimated time45-120 minutes
Estimated timeline for Fresh Start action

Summary: Fresh Start reinstalls Windows and removes OEM bloatware while preserving enrollment. User data retention is optional. Best for performance issues.


Autopilot Reset - Quick device refresh

The Autopilot Reset action prepares a Windows device for reuse while maintaining its Microsoft Entra ID and Microsoft Intune enrollment. It removes user data, settings, and apps, then reapplies the original device configuration. This action is designed for scenarios where a device needs to be repurposed or reassigned, returning it to a fully configured, IT-approved state without requiring a full reimage.

What happens during Autopilot Reset

  • User data and apps are removed.
  • Device settings are removed.
  • The device remains joined to Microsoft Entra ID.
  • The device remains enrolled in Microsoft Intune.
  • The device remains registered with Windows Autopilot.
  • Wi-Fi profiles and credentials are preserved, allowing automatic reconnection after reset.
  • Region, language, and keyboard settings are retained.
  • Upon restart, the device goes through a streamlined setup experience.

When to use Autopilot Reset

  • Quickly preparing a device for a new user.
  • Device is in a shared device or kiosk scenario.
  • Classroom or lab environments where devices need regular reset.
  • Faster alternative to full Wipe for Autopilot-registered devices.

Risks and considerations

  • Only available for devices registered with Windows Autopilot.
  • All user data will be removed.
  • Applications will need to be reinstalled.
  • Faster than Wipe but with the same data removal outcome.

Expected timeline

PhaseDuration
Command received by deviceVaries (depends on device check-in)
Reset process10-20 minutes
Autopilot setup experience15-30 minutes
Total estimated time25-50 minutes
Estimated timeline for Autopilot Reset action

Summary: Autopilot Reset removes user data while maintaining enrollment, Wi-Fi profiles, and regional settings. Returns the device to an IT-approved state without reimaging. Ideal for shared devices or reassignment scenarios.


Delete - Remove the device record

The Delete action removes the device record from Microsoft Intune but does not affect the physical device itself.

What happens during Delete

  • The device record is removed from Microsoft Intune admin center.
  • No action is taken on the physical device.
  • Policies and apps remain on the device until the next sync attempt fails.
  • The device may become non-compliant if conditional access policies are in place.

When to use Delete

  • Device has been lost or stolen and cannot be wiped remotely.
  • Device record needs to be cleaned up after a successful Wipe.
  • Removing stale or orphaned device records.
  • Device was already factory reset outside of Microsoft Intune.

Risks and considerations

  • Does not remove data or management from the physical device.
  • If the device is still active, it will remain in its current state until re-enrolled.
  • Use Wipe or Retire before Delete if the device is accessible.
  • For Windows Autopilot devices, the device will re-enroll if connected to the internet.

Summary: Delete only removes the device record from Microsoft Intune - nothing happens on the physical device. Use for cleaning up stale records or after a device has been wiped.


Company Portal Reset - User-initiated reset

Use the Company Portal app for Windows to reset a used, lost, or stolen device back to factory settings. After a reset, all apps, settings, and personal data on the device are deleted, and the device no longer appears in Company Portal.

The reset option may not be available for every device that appears in Company Portal. Your organization can choose to hide the option.

Requirements for user-initiated reset

For a user to reset their own device via Company Portal, the following must be in place:

  1. Device must be registered with Windows Autopilot, or the user must be targeted with a Windows Autopilot device preparation policy. This ensures the device can automatically re-enroll after reset.
  2. User must be the primary user of the device. The reset option is only available to the assigned primary user.

Comparison: Admin Wipe vs. Company Portal Reset

The Company Portal Reset performs essentially the same operation as an admin-initiated Wipe action. Here’s how they compare:

FeatureAdmin Wipe (Microsoft Intune)Company Portal Reset
Initiated byIT administratorEnd user (primary user only)
Requires admin accessYesNo
Data removedAll user and company dataAll user and company data
Apps removedAll applicationsAll applications
Enrollment removedYesYes
Auto re-enrollmentYes (if Autopilot registered or user targeted with device prep)Yes (requires Autopilot or device prep)
Wipe options availableYes (keep enrollment, secure wipe)No
Can target any deviceYesNo (own device only)
Autopilot requiredFor auto re-enroll onlyYes (mandatory)
Policy controlN/AMust be enabled by admin
Typical use caseIT-managed device lifecycleSelf-service device refresh
Estimated time45-125 minutes45-125 minutes
Comparison of Admin Wipe vs. Company Portal Reset

When users might use Company Portal Reset

  • Device is experiencing persistent performance issues.
  • User wants to start fresh before transitioning to a new role.
  • Device has been compromised and user wants immediate action.
  • Self-service device refresh in organizations that empower users.

Summary: Company Portal Reset enables users to reset their own devices. Requires Windows Autopilot, primary user assignment, and admin-enabled policy. Equivalent to an admin-initiated Wipe.


What happens after reset: Re-enrollment

After a device is reset (via Wipe, Autopilot Reset, or Company Portal Reset), the device will go through the enrollment process again if registered with Windows Autopilot, or if the user is targeted with a Windows Autopilot device preparation policy.

Automatic re-application after enrollment

When the device re-enrolls in Microsoft Intune, the following are automatically applied:

ItemRe-applied automatically
Device configuration policiesYes
Compliance policiesYes
Security baselinesYes
Required applicationsYes
Available applicationsNo - User must request via Company Portal
Windows updates policiesYes
Endpoint security policiesYes
Scripts and remediationsYes
Post-reset re-application of policies and apps

Enrollment timeline expectations

The time for a device to become fully operational after reset depends on several factors:

FactorImpact on time
Number of required applicationsMore apps = longer enrollment
Size of applicationsLarge apps take longer to download and install
Network speedSlower connections extend download times
Windows updates pendingMay require additional restarts
Policy complexityMore policies = more processing time
Factors affecting re-enrollment time

Typical re-enrollment time: 30-90 minutes for a device to receive all policies and required applications.


Reset limitations

There are important limitations to be aware of when using reset functionality:

General limitations

  • Internet connectivity required - Device must be able to reach Microsoft Intune and Microsoft Entra ID services
  • Device must be powered on - Reset commands cannot be executed on powered-off devices
  • Check-in dependency - Commands are executed when the device next checks in with Microsoft Intune
  • BitLocker recovery keys - Ensure recovery keys are backed up before initiating reset; they may be required during recovery

Windows Autopilot limitations

  • Autopilot registration required - For seamless re-enrollment, devices must be registered with Windows Autopilot, or users must be targeted with a Windows Autopilot device preparation policy
  • Hardware hash - If the device is not registered, the hardware hash must be imported for automatic enrollment
  • Profile assignment - Devices must have a Windows Autopilot profile assigned for the enrollment experience to be customized

Company Portal Reset limitations

  • Primary user only - Only the primary user can initiate a reset through Company Portal
  • Policy dependency - Administrator must enable user-initiated reset in device configuration
  • Autopilot required - Without Windows Autopilot registration, or without the user being targeted with a device preparation policy, the device cannot automatically re-enroll
  • No granular options - Users cannot choose between different reset types; it performs a full reset

Offline devices

If a device is offline when a reset command is issued:

  • The command queues in Microsoft Intune.
  • The command executes when the device next connects.
  • Commands may expire after an extended period (typically 30 days).
  • Consider physically accessing the device if remote reset is not possible.

Scenarios and examples

The following scenarios demonstrate how to choose the right device action for common situations you may encounter. Each scenario includes a recommended action, step-by-step guidance, and expected timeframe.

Scenario 1: Employee leaving the organization (corporate device)

Situation: An employee is leaving, and their corporate-owned laptop needs to be prepared for a new user.

Recommended action: Wipe

Steps:

  1. Ensure any important data is backed up (if applicable)
  2. Verify the device is registered with Windows Autopilot, or the new user is targeted with a device preparation policy
  3. Initiate Wipe from Microsoft Intune admin center
  4. Once complete, the device will be ready for the next user via Autopilot or device preparation

Expected time: 45-90 minutes

Scenario 2: BYOD device leaving management

Situation: An employee with a personal device enrolled in Microsoft Intune is leaving the company.

Recommended action: Retire

Steps:

  1. Initiate Retire from Microsoft Intune admin center
  2. Company apps and data are removed
  3. Personal data remains intact
  4. Consider removing the device from Microsoft Entra ID if appropriate

Expected time: 5-15 minutes

Scenario 3: Device performance issues

Situation: A user reports their device is slow due to accumulated software and OEM bloatware.

Recommended action: Fresh Start

Steps:

  1. Backup any critical user data
  2. Initiate Fresh Start from Microsoft Intune admin center
  3. Choose whether to retain user data
  4. Device reinstalls Windows and removes OEM apps
  5. Required apps are reinstalled automatically

Expected time: 60-120 minutes

Scenario 4: Shared device in classroom

Situation: A school needs to reset shared devices between terms.

Recommended action: Autopilot Reset

Steps:

  1. Initiate Autopilot Reset from Microsoft Intune admin center
  2. Devices quickly reset and return to sign-in screen
  3. Next user signs in and receives their assigned apps and policies

Expected time: 25-50 minutes per device

Scenario 5: Lost or stolen device

Situation: An employee reports their laptop was stolen.

Recommended action: Wipe, then Delete (if wipe cannot complete)

Steps:

  1. Immediately initiate Wipe to protect corporate data
  2. If the device never connects to complete the wipe, consider Delete after a reasonable period
  3. Ensure BitLocker is enabled - data remains encrypted even if wipe doesn’t complete
  4. Report the incident according to your security policies

Expected time: Wipe may never complete if device remains offline

Scenario 6: User self-service refresh

Situation: A power user wants to reset their device to resolve persistent issues.

Recommended action: Company Portal Reset (user-initiated)

Steps:

  1. User opens Company Portal on their device
  2. User navigates to their device and selects Reset
  3. User confirms the reset action
  4. Device resets and re-enrolls via Windows Autopilot
  5. Required apps install automatically; user requests available apps as needed

Expected time: 45-90 minutes


Quick reference: Comparison table

Use this table for a quick comparison of all device actions and their key characteristics.

ActionData removedApps removedEnrollment removedAutopilot requiredUser can initiate
WipeAllAllYes (unless option selected)For auto re-enrollNo
RetireCompany onlyCompany onlyYesNoNo
Fresh StartOptionalAll (except built-in)NoNoNo
Autopilot ResetAllAllNoYesNo
DeleteNoneNoneRecord onlyNoNo
Company Portal ResetAllAllYesYesYes (primary user)
Summary comparison of reset and wipe actions in Microsoft Intune

Final Thoughts

Understanding the different reset and wipe options in Microsoft Intune is essential for effective device lifecycle management. Each action has specific use cases, outcomes, and limitations that IT administrators should consider before initiating.

Key takeaways:

  • Wipe is the most comprehensive option for returning a device to factory state
  • Retire is ideal for BYOD scenarios where personal data should remain
  • Fresh Start helps with performance issues while preserving enrollment
  • Autopilot Reset provides fast turnaround for shared or reassigned devices
  • Delete only affects the Microsoft Intune record, not the physical device
  • Company Portal Reset empowers users with self-service capabilities

For seamless re-enrollment after reset actions, ensure devices are registered with Windows Autopilot, or target users with a Windows Autopilot device preparation policy for dynamic enrollment.

–Jesper


Header image attribution: Image created with help from Microsoft Copilot