Intune

How to Wipe a Device Remotely with Intune

Published 18 March 2026 · 7 min read

Being able to remotely wipe a device is one of the core reasons organisations use Intune. Whether a laptop is lost, stolen, or being decommissioned, Intune gives you several remote actions to remove company data or perform a full factory reset. This guide covers all the remote wipe options, when to use each, and what happens to BitLocker keys and user data.

Remote actions available in Intune

📱
Intune remote actions comparison
WipeCompany-owned devices being decommissioned or recovered after loss/theft
Full factory reset - removes all data and reinstalls Windows
RetireBYOD devices or employees leaving the organisation
Removes company data only - leaves personal data
Fresh StartDevices with persistent issues that need a clean OS
Reinstalls Windows but keeps personal files and user accounts
Autopilot ResetCompany devices being reassigned to a new user
Resets to OOBE but keeps Entra ID join and Autopilot config
Remote LockLost device still online - lock while you decide next steps
Locks the device immediately
Reset PasscodeUser locked out of device
Clears the PIN/password for re-enrolment

Full wipe (factory reset)

Devices → All devices → select device → Wipe

You will be asked to confirm with two options:

⚠️
This is irreversible
A full wipe removes all data permanently. There is no undo. Make sure you have retrieved any important data or BitLocker keys before triggering a wipe.

Retire (remove company data)

Devices → All devices → select device → Retire

Retire is the correct action for BYOD devices or employees leaving. It removes:

It does not remove personal apps, photos, documents, or the operating system.

Fresh Start

Devices → All devices → select device → Fresh Start

Fresh Start reinstalls a clean version of Windows while optionally keeping the user's personal files. It removes all apps installed by the previous MDM enrolment. Useful for devices that have accumulated too much cruft but where the user's documents need to be preserved.

Autopilot Reset

Devices → All devices → select device → Autopilot Reset

Autopilot Reset returns the device to a business-ready state without a full OS reinstall. It keeps the Entra ID join, Autopilot hardware hash registration, and any Autopilot deployment profile settings. Use this when reassigning a company device to a new employee.

BitLocker keys before wiping

Before wiping any BitLocker-encrypted device, retrieve the recovery key from Entra ID in case you need it later:

Entra ID portal → Devices → select device → Recovery keys

Copy and store the recovery key securely before triggering the wipe. Once the wipe completes, the key stored against that device ID in Entra ID is no longer valid.

Monitor the wipe status

After triggering a remote action, monitor its status under:

Devices → All devices → select device → Device actions status

The action shows as Pending until the device checks in, then transitions to Complete. For online devices this typically happens within 15 minutes.

Frequently Asked Questions

Q: What is the difference between Wipe and Retire in Intune?

Wipe performs a full factory reset of the device, removing all data and reinstalling Windows. Retire removes the device from Intune management and removes company data (apps, policies, email profiles) but leaves personal data intact. Use Retire for BYOD devices and Wipe for company-owned devices being decommissioned or re-imaged.

Q: Does Intune Wipe delete BitLocker keys?

By default, yes. The Wipe action removes the BitLocker recovery key from Entra ID. If you need to recover data before wiping, retrieve the BitLocker key from the Entra ID portal first under Devices > select device > Recovery keys.

Q: How long does a remote wipe take in Intune?

The wipe command is delivered to the device at its next Intune check-in, which is typically within 15 minutes for online devices. The Windows reset itself takes 20-40 minutes depending on hardware. For offline devices, the command queues and executes when the device next connects.

Q: Can I wipe a device that is offline or turned off?

The wipe command queues in Intune and is delivered when the device next comes online. For a device that is lost or stolen and may never come back online, also consider contacting your mobile carrier to block the SIM (for cellular devices) and filing a police report.

Related Guides
-> Enable BitLocker via Intune-> Windows Autopilot-> Custom Compliance Policies
// need intune set up properly?
Fixed-price Intune setup for UK businesses

I set up Intune for UK small businesses at a fixed price - app deployment, compliance policies, Conditional Access, and full documentation.

View Packages