Which Intune remote action keeps personal data and which resets the device, with platform support, wipe options and daily limits.
From Ultra Transcenders MD-102 by Tony Rough (coming December 2026)
These four actions remove data, and choosing the wrong one either destroys personal files or leaves company data behind. The decision depends on ownership and on whether the device should stay usable.
| Action | Personal data | Company data and management | Typical use | Daily limit |
|---|---|---|---|---|
| Retire | Kept | Intune apps, settings, Wi-Fi/VPN profiles and certificates removed; device unenrolled | Personal (BYOD) devices, user leaving | 1,000 |
| Wipe | Removed (unless keep-user-data option on Windows) | Everything reset to factory settings | Corporate devices being repurposed, lost or stolen | 500 |
| Delete | Depends on the triggered action | Record removed from Intune immediately; Retire or Wipe sent | Cleaning up devices no longer needed | 1,000 |
| Fresh Start | Optionally kept (Windows home folder) | OEM apps and settings removed | Removing preinstalled bloatware on Windows | Not listed |
Retire runs at the next check-in, so the device may still appear until then. It supports Android device administrator, Android Enterprise personally owned work profile, iOS/iPadOS, macOS, tvOS, visionOS and Windows. On an Android personally owned work profile it removes the whole work profile. On iOS/iPadOS it removes apps pinned to the management profile, triggers a selective wipe of app-protected Microsoft apps, removes Intune email profiles and revokes certificates. On Windows:
Retiring or deleting a BitLocker-protected, Entra joined device makes Intune remove the OS volume key protectors and suspend BitLocker, so back up the recovery key and local admin credentials first.
Wipe supports Android Enterprise corporate-owned dedicated, fully managed and work profile devices, AOSP, ChromeOS, iOS/iPadOS, macOS, tvOS, visionOS and Windows. Windows has three options:
| Windows wipe option | Behaviour | CSP node |
|---|---|---|
| No options selected | Factory reset; if interrupted, tries to roll back | doWipe |
| Wipe device, but keep enrollment state and associated user account | Reset that keeps user data and accounts; MDM policies removed but device stays enrolled | doWipePersistUserData |
| Wipe device, and continue to wipe even if device loses power | Full reset that also overwrites free space and survives power loss; can leave some devices unbootable | doWipeProtected |
Other platform options: macOS needs a six-digit Recovery PIN (for Macs without the T2 chip) and an Obliteration Behavior fallback; iOS/iPadOS and Android corporate-owned devices preserve eSIM data plans unless you choose to remove them. On Zebra Android devices, Wipe removes only corporate data; a factory reset needs StageNow or OEMConfig. Samsung fully managed devices fail to wipe if Factory Reset is blocked in device restrictions.
Delete immediately hides the device from the admin center and sends a command whose type depends on the platform:
| Platform and enrolment type | Command sent by Delete |
|---|---|
| Windows, iOS/iPadOS, macOS | Retire |
| Android device administrator, Android Enterprise personally owned work profile | Retire |
| Android Enterprise fully managed, dedicated or corporate-owned work profile, AOSP | Wipe |
A Completed delete status means only that the server side finished. After Retire, Wipe or Delete you may also need to deregister the device from Windows Autopilot, release an ADE device from Apple Business Manager, and remove the stale Microsoft Entra device record, because Intune actions don’t always do those for you.
Device cleanup rules (Devices > Device cleanup rules) automatically hide records that haven’t checked in for 30 to 270 days, one rule per platform; if both an “All platforms” rule and a platform rule exist, the shorter period wins. They send no retire or wipe, and a hidden device reappears if it checks in before its certificate expires.
Fresh Start (Windows only) removes apps installed by the manufacturer. With Retain user data on this device, the device stays Entra joined, re-enrols automatically when an Entra user signs in and keeps the user’s home folder. Without it, the device returns to the OOBE-completed state with the built-in administrator account, and BYOD devices are removed from Entra ID and MDM.
Common trap: Retiring an Android Enterprise fully managed device to free it for reuse - Retire isn’t supported on corporate-owned Android Enterprise devices; use Wipe (which is also what Delete sends for those enrolment types).
Common trap: Assuming Delete or a cleanup rule always tidies Microsoft Entra ID - a cleanup rule never removes the Entra device object, and Delete removes it only where the Retire it triggers does (for example, an Entra joined Windows device not registered in Autopilot); handle stale Entra records separately in Microsoft Entra ID.
This note is one section of Ultra Transcenders MD-102: Managing and Securing Microsoft 365 Endpoints by using Intune, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.
Due on Amazon in December 2026, in Kindle and paperback editions.
About the book · MD-102 terms in the glossary · All MD-102 study notes
How Microsoft Entra registered, Entra joined and hybrid joined devices differ in ownership, sign-in, management and the scenarios each one suits.
The tenant-wide compliance settings and per-platform policies behind Intune compliance, and how a device's overall status is worked out.
Which devices can back up a local admin password to Entra ID or Active Directory, and how to build the Windows LAPS policy in Intune.
The six ways Intune manages Android devices, from personal work profiles to fully managed, dedicated and AOSP, and how to choose between them.
How user-driven, pre-provisioned and self-deploying Autopilot modes differ in join type, user interaction and TPM requirements.
What each Enrollment Status Page setting does, from blocking apps and time limits to quality updates during OOBE, and where to create profiles.
How Intune update rings set quality and feature update deferrals, deadlines, grace periods and restart behaviour for groups of Windows devices.
How Intune app protection policies protect work data inside apps on enrolled and personal devices, and the three-level data protection framework.