FREE STUDY NOTES · MD-102

Intune retire vs wipe vs delete vs Fresh Start

Which Intune remote action keeps personal data and which resets the device, with platform support, wipe options and daily limits.

From Ultra Transcenders MD-102 by Tony Rough (coming December 2026)

These four actions remove data, and choosing the wrong one either destroys personal files or leaves company data behind. The decision depends on ownership and on whether the device should stay usable.

Action Personal data Company data and management Typical use Daily limit
Retire Kept Intune apps, settings, Wi-Fi/VPN profiles and certificates removed; device unenrolled Personal (BYOD) devices, user leaving 1,000
Wipe Removed (unless keep-user-data option on Windows) Everything reset to factory settings Corporate devices being repurposed, lost or stolen 500
Delete Depends on the triggered action Record removed from Intune immediately; Retire or Wipe sent Cleaning up devices no longer needed 1,000
Fresh Start Optionally kept (Windows home folder) OEM apps and settings removed Removing preinstalled bloatware on Windows Not listed

Retire

Retire runs at the next check-in, so the device may still appear until then. It supports Android device administrator, Android Enterprise personally owned work profile, iOS/iPadOS, macOS, tvOS, visionOS and Windows. On an Android personally owned work profile it removes the whole work profile. On iOS/iPadOS it removes apps pinned to the management profile, triggers a selective wipe of app-protected Microsoft apps, removes Intune email profiles and revokes certificates. On Windows:

Retiring or deleting a BitLocker-protected, Entra joined device makes Intune remove the OS volume key protectors and suspend BitLocker, so back up the recovery key and local admin credentials first.

Wipe

Wipe supports Android Enterprise corporate-owned dedicated, fully managed and work profile devices, AOSP, ChromeOS, iOS/iPadOS, macOS, tvOS, visionOS and Windows. Windows has three options:

Windows wipe option Behaviour CSP node
No options selected Factory reset; if interrupted, tries to roll back doWipe
Wipe device, but keep enrollment state and associated user account Reset that keeps user data and accounts; MDM policies removed but device stays enrolled doWipePersistUserData
Wipe device, and continue to wipe even if device loses power Full reset that also overwrites free space and survives power loss; can leave some devices unbootable doWipeProtected

Other platform options: macOS needs a six-digit Recovery PIN (for Macs without the T2 chip) and an Obliteration Behavior fallback; iOS/iPadOS and Android corporate-owned devices preserve eSIM data plans unless you choose to remove them. On Zebra Android devices, Wipe removes only corporate data; a factory reset needs StageNow or OEMConfig. Samsung fully managed devices fail to wipe if Factory Reset is blocked in device restrictions.

Delete and cleanup

Delete immediately hides the device from the admin center and sends a command whose type depends on the platform:

Platform and enrolment type Command sent by Delete
Windows, iOS/iPadOS, macOS Retire
Android device administrator, Android Enterprise personally owned work profile Retire
Android Enterprise fully managed, dedicated or corporate-owned work profile, AOSP Wipe

A Completed delete status means only that the server side finished. After Retire, Wipe or Delete you may also need to deregister the device from Windows Autopilot, release an ADE device from Apple Business Manager, and remove the stale Microsoft Entra device record, because Intune actions don’t always do those for you.

Device cleanup rules (Devices > Device cleanup rules) automatically hide records that haven’t checked in for 30 to 270 days, one rule per platform; if both an “All platforms” rule and a platform rule exist, the shorter period wins. They send no retire or wipe, and a hidden device reappears if it checks in before its certificate expires.

Fresh Start

Fresh Start (Windows only) removes apps installed by the manufacturer. With Retain user data on this device, the device stays Entra joined, re-enrols automatically when an Entra user signs in and keeps the user’s home folder. Without it, the device returns to the OOBE-completed state with the built-in administrator account, and BYOD devices are removed from Entra ID and MDM.

Common trap: Retiring an Android Enterprise fully managed device to free it for reuse - Retire isn’t supported on corporate-owned Android Enterprise devices; use Wipe (which is also what Delete sends for those enrolment types).

Common trap: Assuming Delete or a cleanup rule always tidies Microsoft Entra ID - a cleanup rule never removes the Entra device object, and Delete removes it only where the Retire it triggers does (for example, an Entra joined Windows device not registered in Autopilot); handle stale Entra records separately in Microsoft Entra ID.

Get the whole book

This note is one section of Ultra Transcenders MD-102: Managing and Securing Microsoft 365 Endpoints by using Intune, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.

Amazon.co.ukKindle: coming soonPaperback: coming soon
Amazon.comKindle: coming soonPaperback: coming soon

Due on Amazon in December 2026, in Kindle and paperback editions.

About the book · MD-102 terms in the glossary · All MD-102 study notes

More MD-102 study notes