Strips corporate data, managed apps and MDM profiles from a device while keeping personal data, which is the key difference from a Wipe in Intune.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Retire in context, with comparison tables and the common traps.
Terms in this definition
- MDM
Mobile device management: a service such as Microsoft Intune controlling the settings, security and apps of enrolled devices. Intune can push Defender configuration this way using Policy CSP and OMA-URI.
- Index field attributes
Settings applied to each field in an Azure AI Search index:
searchablefor full text,retrievableto return it,filterablefor exact-match$filter,sortable,facetablefor counts, andkeyfor the unique document ID. - Wipe
Resets a device to factory settings from Intune, with options to retain enrolment and the user account or to carry on through a power loss. Personally owned work profile devices can't be wiped this way.
- Intune
Microsoft's device management service, once branded Microsoft Endpoint Manager. Its compliance policies are what the compliant-device grant in Conditional Access relies on.
Related terms
- Actions for noncompliance
What a compliance policy does, in order, when a device fails it. Marking the device noncompliant always happens, at day 0 unless you add a grace period; you can also send an email or push notification, lock the device remotely or put it on the retire list.
- Availability tests
Synthetic monitoring in Application Insights, using standard tests or custom TrackAvailability tests; the older URL ping tests are deprecated and now retire on 30 September 2028 (originally 30 September 2026).
- Azure Automation State Configuration
DSC service within Azure Automation, due to retire on 30 September 2027. It compiles configurations, assigns them to onboarded machines that are running, and reports back on compliance.
- Azure Disk Encryption
Due to retire on 15 September 2028, this feature encrypts VM OS and data disks from inside the guest (BitLocker or DM-Crypt), keeping keys in Key Vault. Dynamic volumes, Write Accelerator disks and ephemeral OS disks aren't supported.
- Help Desk Operator
A built-in Intune role that can assign existing apps and policies and carry out remote tasks such as Fresh Start, retire or wipe, but can't create apps or policies itself.
- Long Audio API
Asynchronous Speech API from an earlier generation, meant for producing synthesised audio of 10 minutes or more. It is due to retire on 1 April 2027, superseded by Batch synthesis.
- Multi Admin Approval
Intune access policies requiring a second admin to sign off before a change goes through. They can protect things like apps, scripts, roles, configuration and compliance policies, as well as device wipe, retire and delete actions.
- NSG flow logs
Records over time of traffic that NSGs allowed or denied. New ones have been blocked since 30 June 2025, VNet flow logs replace them, and they retire entirely on 30 September 2027.