Managing Windows devices with Microsoft Intune means having the right tool for every situation. Whether an employee is leaving the organization, a device needs to be repurposed for a new user, or a laptop has persistent performance issues that require a fresh start - knowing which remote action to use can save time and prevent data loss.
Consider these common scenarios:
- An employee resigns, and their corporate laptop needs to be prepared for the next hire.
- A contractor’s project ends, and you need to remove company data from their personal device.
- A user reports their device is slow and cluttered with software accumulated over years.
- A laptop is reported lost or stolen, and corporate data must be protected immediately.
- A power user wants to reset their own device without waiting for IT support.
Each of these situations calls for a different approach. Using the wrong action could leave sensitive data exposed, require unnecessary manual intervention, or result in a device that cannot automatically re-enroll.
In this post, we’ll explore the remote actions available to IT administrators. We’ll explain what each action does, when you should use it, and highlight the differences in how they handle company data, personal data, and overall device management.
Note
For seamless re-enrollment after reset actions, devices should be registered with Windows Autopilot, or users should be targeted with a Windows Autopilot device preparation policy. Without this, certain reset options may not be available or may result in the device requiring manual re-enrollment.Device reset and recovery options
Microsoft Intune offers several device actions for managing Windows devices:
- Wipe - Factory reset the device
- Retire - Remove corporate management
- Fresh Start - Reinstall Windows
- Autopilot Reset - Quick device refresh
- Delete - Remove the device record
- Company Portal Reset - User-initiated reset
Note
Before using remote actions in Microsoft Intune, ensure the following:
- Devices must be enrolled in Microsoft Intune.
- Devices must be connected to the internet to receive remote commands.
- Administrators must have the appropriate Microsoft Intune roles and permissions to execute device actions.
- Some actions have additional requirements (such as Windows Autopilot registration or device preparation policy assignment) as noted in each section.
To access Device reset and recovery options, sign in to the Microsoft Intune admin center , navigate to Devices > All devices, select a device, and choose the desired action from the device’s toolbar or the ellipsis menu.
Read on to understand when to use each action and what to expect.
Wipe - Factory reset the device
The Wipe action performs a factory reset of the device, restoring it to its default settings. This is the most comprehensive reset option available, removing all personal and organizational data, apps, and configurations. It’s commonly used when a device needs to be retired, repurposed, reset for troubleshooting, or securely erased if lost or stolen.
What happens during a Wipe
- All user data is removed from the device.
- All applications (including Microsoft Intune management) are removed.
- The device is restored to factory default settings.
- If the device is registered with Windows Autopilot, or the user is targeted with a Windows Autopilot device preparation policy, it will automatically re-enroll upon next setup.
Wipe options
When initiating a Wipe, you have additional options:
| Option | Description |
|---|---|
| No options selected | Performs a standard factory reset. The device is wiped and restored to default settings. If registered with Windows Autopilot, or the user is targeted with device preparation, it will automatically re-enroll. |
| Wipe device, but keep enrollment state and associated user account | Resets the device but preserves the Microsoft Entra ID join and Microsoft Intune enrollment. User data is removed, but the device remains managed. |
| Wipe device and continue to wipe even if device loses power | Ensures the wipe completes even if the device loses power during the process. This writes zeros to the drive. |
When to use Wipe
- Device is being repurposed for a new user.
- Device contains sensitive data that must be removed.
- Device is being decommissioned and will be disposed of or sold.
- Troubleshooting persistent issues that cannot be resolved otherwise.
Risks and considerations
- All data on the device will be permanently deleted.
- The process cannot be undone once initiated.
- If the device is not registered with Windows Autopilot, and the user is not targeted with a Windows Autopilot device preparation policy, it will require manual re-enrollment.
- The wipe process can take 20-60 minutes depending on device specifications and whether secure wipe is enabled.
Expected timeline
| Phase | Duration |
|---|---|
| Command received by device | Varies (depends on device check-in) |
| Wipe process | 20-60 minutes |
| Windows Out-of-Box Experience (OOBE) | 10-20 minutes |
| Windows Autopilot enrollment | 15-45 minutes |
| Total estimated time | 45-125 minutes |
Summary: Wipe performs a complete factory reset, removing all data and apps. Requires Windows Autopilot for automatic re-enrollment. Best for device repurposing or decommissioning.
Retire - Remove corporate management
The Retire action removes company data from a device without performing a full wipe or factory reset. This action is ideal for personally owned devices or when transitioning a device out of organizational control. It unenrolls the device from Microsoft Intune and removes managed apps, settings, and profiles deployed through mobile device management (MDM), while preserving personal data.
Unlike the Wipe action, which resets the device to factory settings, Retire keeps user content intact.
What happens during a Retire
- The device is unenrolled from Microsoft Intune.
- Company apps deployed through Microsoft Intune are removed.
- Microsoft Intune management profiles and MDM policies are removed.
- Company data protected by app protection policies is removed.
- Personal data, apps, and settings remain on the device.
- The device remains joined to Microsoft Entra ID (if applicable).
- The action is triggered the next time the device checks in with Microsoft Intune.
When to use Retire
- Employee leaves the organization but keeps their personal device (BYOD scenarios).
- Device transitions from corporate-managed to personal use.
- Removing management without affecting user data.
Risks and considerations
- Personal data remains on the device - ensure this aligns with your data protection policies.
- Company apps are removed, but data created by the user outside managed apps may remain.
- The device may still be joined to Microsoft Entra ID and may need to be manually removed.
- The action executes when the device next checks in - until then, the device may still appear in the admin center.
- If you need to remove a device record immediately, consider using the Delete action instead.
- For corporate-owned devices, consider using Wipe instead.
Summary: Retire removes company apps, policies, and data while preserving personal content. Best for BYOD scenarios when employees leave.
Fresh Start - Reinstall Windows
The Fresh Start action removes pre-installed (OEM) applications and reinstalls Windows cleanly while preserving user data and Microsoft Entra ID enrollment.
What happens during Fresh Start
- Windows is reinstalled cleanly.
- Pre-installed OEM applications (bloatware) are removed.
- User data and settings can optionally be retained.
- Microsoft Entra ID join is preserved.
- Device re-enrolls in Microsoft Intune automatically.
When to use Fresh Start
- Device performance has degraded due to accumulated software.
- OEM bloatware is causing issues or security concerns.
Risks and considerations
- All installed applications (except built-in Windows apps) are removed.
- The process requires a stable internet connection.
- Can take significant time depending on Windows update size.
- User data retention is optional - verify settings before initiating.
Expected timeline
| Phase | Duration |
|---|---|
| Command received by device | Varies (depends on device check-in) |
| Windows reinstallation | 30-90 minutes |
| Microsoft Intune re-enrollment | 15-30 minutes |
| Total estimated time | 45-120 minutes |
Summary: Fresh Start reinstalls Windows and removes OEM bloatware while preserving enrollment. User data retention is optional. Best for performance issues.
Autopilot Reset - Quick device refresh
The Autopilot Reset action prepares a Windows device for reuse while maintaining its Microsoft Entra ID and Microsoft Intune enrollment. It removes user data, settings, and apps, then reapplies the original device configuration. This action is designed for scenarios where a device needs to be repurposed or reassigned, returning it to a fully configured, IT-approved state without requiring a full reimage.
What happens during Autopilot Reset
- User data and apps are removed.
- Device settings are removed.
- The device remains joined to Microsoft Entra ID.
- The device remains enrolled in Microsoft Intune.
- The device remains registered with Windows Autopilot.
- Wi-Fi profiles and credentials are preserved, allowing automatic reconnection after reset.
- Region, language, and keyboard settings are retained.
- Upon restart, the device goes through a streamlined setup experience.
When to use Autopilot Reset
- Quickly preparing a device for a new user.
- Device is in a shared device or kiosk scenario.
- Classroom or lab environments where devices need regular reset.
- Faster alternative to full Wipe for Autopilot-registered devices.
Risks and considerations
- Only available for devices registered with Windows Autopilot.
- All user data will be removed.
- Applications will need to be reinstalled.
- Faster than Wipe but with the same data removal outcome.
Expected timeline
| Phase | Duration |
|---|---|
| Command received by device | Varies (depends on device check-in) |
| Reset process | 10-20 minutes |
| Autopilot setup experience | 15-30 minutes |
| Total estimated time | 25-50 minutes |
Summary: Autopilot Reset removes user data while maintaining enrollment, Wi-Fi profiles, and regional settings. Returns the device to an IT-approved state without reimaging. Ideal for shared devices or reassignment scenarios.
Delete - Remove the device record
The Delete action removes the device record from Microsoft Intune but does not affect the physical device itself.
What happens during Delete
- The device record is removed from Microsoft Intune admin center.
- No action is taken on the physical device.
- Policies and apps remain on the device until the next sync attempt fails.
- The device may become non-compliant if conditional access policies are in place.
When to use Delete
- Device has been lost or stolen and cannot be wiped remotely.
- Device record needs to be cleaned up after a successful Wipe.
- Removing stale or orphaned device records.
- Device was already factory reset outside of Microsoft Intune.
Risks and considerations
- Does not remove data or management from the physical device.
- If the device is still active, it will remain in its current state until re-enrolled.
- Use Wipe or Retire before Delete if the device is accessible.
- For Windows Autopilot devices, the device will re-enroll if connected to the internet.
Summary: Delete only removes the device record from Microsoft Intune - nothing happens on the physical device. Use for cleaning up stale records or after a device has been wiped.
Company Portal Reset - User-initiated reset
Use the Company Portal app for Windows to reset a used, lost, or stolen device back to factory settings. After a reset, all apps, settings, and personal data on the device are deleted, and the device no longer appears in Company Portal.
The reset option may not be available for every device that appears in Company Portal. Your organization can choose to hide the option.
Requirements for user-initiated reset
For a user to reset their own device via Company Portal, the following must be in place:
- Device must be registered with Windows Autopilot, or the user must be targeted with a Windows Autopilot device preparation policy. This ensures the device can automatically re-enroll after reset.
- User must be the primary user of the device. The reset option is only available to the assigned primary user.
Comparison: Admin Wipe vs. Company Portal Reset
The Company Portal Reset performs essentially the same operation as an admin-initiated Wipe action. Here’s how they compare:
| Feature | Admin Wipe (Microsoft Intune) | Company Portal Reset |
|---|---|---|
| Initiated by | IT administrator | End user (primary user only) |
| Requires admin access | Yes | No |
| Data removed | All user and company data | All user and company data |
| Apps removed | All applications | All applications |
| Enrollment removed | Yes | Yes |
| Auto re-enrollment | Yes (if Autopilot registered or user targeted with device prep) | Yes (requires Autopilot or device prep) |
| Wipe options available | Yes (keep enrollment, secure wipe) | No |
| Can target any device | Yes | No (own device only) |
| Autopilot required | For auto re-enroll only | Yes (mandatory) |
| Policy control | N/A | Must be enabled by admin |
| Typical use case | IT-managed device lifecycle | Self-service device refresh |
| Estimated time | 45-125 minutes | 45-125 minutes |
Note
The key difference is who initiates the action and what options are available. When an IT administrator performs a Wipe, they can choose additional options like keeping the enrollment state or ensuring a secure wipe that continues even if power is lost. The Company Portal Reset is a simplified, single-option reset designed for self-service scenarios.When users might use Company Portal Reset
- Device is experiencing persistent performance issues.
- User wants to start fresh before transitioning to a new role.
- Device has been compromised and user wants immediate action.
- Self-service device refresh in organizations that empower users.
Summary: Company Portal Reset enables users to reset their own devices. Requires Windows Autopilot, primary user assignment, and admin-enabled policy. Equivalent to an admin-initiated Wipe.
What happens after reset: Re-enrollment
After a device is reset (via Wipe, Autopilot Reset, or Company Portal Reset), the device will go through the enrollment process again if registered with Windows Autopilot, or if the user is targeted with a Windows Autopilot device preparation policy.
Automatic re-application after enrollment
When the device re-enrolls in Microsoft Intune, the following are automatically applied:
| Item | Re-applied automatically |
|---|---|
| Device configuration policies | Yes |
| Compliance policies | Yes |
| Security baselines | Yes |
| Required applications | Yes |
| Available applications | No - User must request via Company Portal |
| Windows updates policies | Yes |
| Endpoint security policies | Yes |
| Scripts and remediations | Yes |
Note
Required apps assigned to the device or user will be automatically installed during or after enrollment. Available apps are not automatically installed - users must browse the Company Portal and request installation of any available apps they need.Enrollment timeline expectations
The time for a device to become fully operational after reset depends on several factors:
| Factor | Impact on time |
|---|---|
| Number of required applications | More apps = longer enrollment |
| Size of applications | Large apps take longer to download and install |
| Network speed | Slower connections extend download times |
| Windows updates pending | May require additional restarts |
| Policy complexity | More policies = more processing time |
Typical re-enrollment time: 30-90 minutes for a device to receive all policies and required applications.
Reset limitations
There are important limitations to be aware of when using reset functionality:
General limitations
- Internet connectivity required - Device must be able to reach Microsoft Intune and Microsoft Entra ID services
- Device must be powered on - Reset commands cannot be executed on powered-off devices
- Check-in dependency - Commands are executed when the device next checks in with Microsoft Intune
- BitLocker recovery keys - Ensure recovery keys are backed up before initiating reset; they may be required during recovery
Windows Autopilot limitations
- Autopilot registration required - For seamless re-enrollment, devices must be registered with Windows Autopilot, or users must be targeted with a Windows Autopilot device preparation policy
- Hardware hash - If the device is not registered, the hardware hash must be imported for automatic enrollment
- Profile assignment - Devices must have a Windows Autopilot profile assigned for the enrollment experience to be customized
Company Portal Reset limitations
- Primary user only - Only the primary user can initiate a reset through Company Portal
- Policy dependency - Administrator must enable user-initiated reset in device configuration
- Autopilot required - Without Windows Autopilot registration, or without the user being targeted with a device preparation policy, the device cannot automatically re-enroll
- No granular options - Users cannot choose between different reset types; it performs a full reset
Offline devices
If a device is offline when a reset command is issued:
- The command queues in Microsoft Intune.
- The command executes when the device next connects.
- Commands may expire after an extended period (typically 30 days).
- Consider physically accessing the device if remote reset is not possible.
Warning
If a device has been compromised by malware, ransomware, or a sophisticated attack, a remote Wipe may not be sufficient. Depending on the type and severity of the compromise, malicious artifacts may persist in firmware, recovery partitions, or other areas not affected by a standard wipe.
For compromised devices, consider performing a bare metal recovery (BMR) using verified installation media to ensure complete removal of any malicious components. Consult your security team before deciding on the appropriate recovery method.
Scenarios and examples
The following scenarios demonstrate how to choose the right device action for common situations you may encounter. Each scenario includes a recommended action, step-by-step guidance, and expected timeframe.
Scenario 1: Employee leaving the organization (corporate device)
Situation: An employee is leaving, and their corporate-owned laptop needs to be prepared for a new user.
Recommended action: Wipe
Steps:
- Ensure any important data is backed up (if applicable)
- Verify the device is registered with Windows Autopilot, or the new user is targeted with a device preparation policy
- Initiate Wipe from Microsoft Intune admin center
- Once complete, the device will be ready for the next user via Autopilot or device preparation
Expected time: 45-90 minutes
Scenario 2: BYOD device leaving management
Situation: An employee with a personal device enrolled in Microsoft Intune is leaving the company.
Recommended action: Retire
Steps:
- Initiate Retire from Microsoft Intune admin center
- Company apps and data are removed
- Personal data remains intact
- Consider removing the device from Microsoft Entra ID if appropriate
Expected time: 5-15 minutes
Scenario 3: Device performance issues
Situation: A user reports their device is slow due to accumulated software and OEM bloatware.
Recommended action: Fresh Start
Steps:
- Backup any critical user data
- Initiate Fresh Start from Microsoft Intune admin center
- Choose whether to retain user data
- Device reinstalls Windows and removes OEM apps
- Required apps are reinstalled automatically
Expected time: 60-120 minutes
Scenario 4: Shared device in classroom
Situation: A school needs to reset shared devices between terms.
Recommended action: Autopilot Reset
Steps:
- Initiate Autopilot Reset from Microsoft Intune admin center
- Devices quickly reset and return to sign-in screen
- Next user signs in and receives their assigned apps and policies
Expected time: 25-50 minutes per device
Scenario 5: Lost or stolen device
Situation: An employee reports their laptop was stolen.
Recommended action: Wipe, then Delete (if wipe cannot complete)
Steps:
- Immediately initiate Wipe to protect corporate data
- If the device never connects to complete the wipe, consider Delete after a reasonable period
- Ensure BitLocker is enabled - data remains encrypted even if wipe doesn’t complete
- Report the incident according to your security policies
Expected time: Wipe may never complete if device remains offline
Scenario 6: User self-service refresh
Situation: A power user wants to reset their device to resolve persistent issues.
Recommended action: Company Portal Reset (user-initiated)
Steps:
- User opens Company Portal on their device
- User navigates to their device and selects Reset
- User confirms the reset action
- Device resets and re-enrolls via Windows Autopilot
- Required apps install automatically; user requests available apps as needed
Expected time: 45-90 minutes
Quick reference: Comparison table
Use this table for a quick comparison of all device actions and their key characteristics.
| Action | Data removed | Apps removed | Enrollment removed | Autopilot required | User can initiate |
|---|---|---|---|---|---|
| Wipe | All | All | Yes (unless option selected) | For auto re-enroll | No |
| Retire | Company only | Company only | Yes | No | No |
| Fresh Start | Optional | All (except built-in) | No | No | No |
| Autopilot Reset | All | All | No | Yes | No |
| Delete | None | None | Record only | No | No |
| Company Portal Reset | All | All | Yes | Yes | Yes (primary user) |
Final Thoughts
Understanding the different reset and wipe options in Microsoft Intune is essential for effective device lifecycle management. Each action has specific use cases, outcomes, and limitations that IT administrators should consider before initiating.
Key takeaways:
- Wipe is the most comprehensive option for returning a device to factory state
- Retire is ideal for BYOD scenarios where personal data should remain
- Fresh Start helps with performance issues while preserving enrollment
- Autopilot Reset provides fast turnaround for shared or reassigned devices
- Delete only affects the Microsoft Intune record, not the physical device
- Company Portal Reset empowers users with self-service capabilities
For seamless re-enrollment after reset actions, ensure devices are registered with Windows Autopilot, or target users with a Windows Autopilot device preparation policy for dynamic enrollment.
–Jesper
Header image attribution: Image created with help from Microsoft Copilot


