Back to blog

Guides  ·  4 min read

Intune retires the device. It does not prove the drive was sanitized.

Most IT teams running Microsoft Intune already have a device retirement process. Wipe the device, retire it from the tenant, remove it from the device list, move on. What that process does not produce, on its own, is something you can hand an auditor as proof the drive was actually sanitized.

What the Intune wipe action actually does

Per Microsoft's own documentation, the Wipe action in Intune resets a managed device to its factory default settings, and the Retire action removes company data, apps, and management from a device without a full factory reset. Both are device management actions performed through the Intune service and reported back through device check-in.

That documentation describes what the action tells the device to do and how the result is reported to the console. It does not describe a destruction certificate, a per-drive sanitization record, or a signed attestation of what happened to the physical storage. That is not a gap in Microsoft's documentation. A device management platform is built to manage devices, not to produce forensic evidence of drive sanitization. Reading the wipe or retire status as that kind of evidence is asking the tool to do something it was never built to do.

The three states an IT admin cannot tell apart afterward

Once a wipe or retire command has been sent, an admin looking at the Intune console is looking at a status flag, not a completed fact. That status can reflect any of three real-world outcomes, and from the console alone, they look the same or close to it:

  1. The reset completed. The device did what it was told, the drive was reset, and the device checked back in to confirm it.
  2. The reset failed silently. The command was sent, the device attempted it, something went wrong partway through, and the failure state is ambiguous or was never surfaced clearly.
  3. The device never checked in. The command is queued or marked sent, but the device was offline, decommissioned, or otherwise never received it, so nothing happened on the actual hardware.

An admin cannot distinguish these three states from a device list export with confidence. All three can show up looking like "action sent" or "pending" depending on timing, and a device that never checks in again looks identical to one that reset and then went dark.

What an auditor asks for at offboarding

When a device is retired, sold, donated, or recycled, an auditor is not going to ask "did you send the wipe command." They are going to ask for proof that the specific drive in that specific device no longer holds recoverable data, tied to that device's serial number, with a timestamp and a result. A device list showing "retired" or "wiped" in a status column does not answer that question, because a status column reflects what was requested, not what was independently verified on the drive itself.

Where WipeCert fits

WipeCert connects to your Entra tenant through Microsoft Graph and lists your Intune-managed devices in the WipeCert dashboard. From there, a wipe is triggered against the device, completion is tracked, and a signed certificate is issued per drive once the action finishes. That certificate carries the record an auditor is actually asking for: device and drive serial, sanitization method against the NIST 800-88 term, start and end time, verification result, and a signature you and the auditor can both check independently on WipeCert's public verification page. The evidence lives outside the MDM console, so it survives even after the device itself is gone from the tenant.

The Intune connection is a separate add-on on top of a WipeCert plan, priced at $129 a month or $1,290 a year, and it is included at no extra charge with the Enterprise plan.

Honest limits

WipeCert's Intune integration triggers and tracks the wipe action against a managed device through Graph. It does not change what Intune itself reports, and it cannot retroactively produce a certificate for a wipe that already happened before the integration was connected. What it adds is a signed, per-drive record generated at the time of that specific wipe, which the Intune console by itself does not produce.

This connection is for devices that are already enrolled and managed in Intune. It does not cover unmanaged or bare-metal hardware outside an MDM tenant.

Try it on your own tenant

Start a free WipeCert trial. Two wipes are included and no card is required, so you can connect a test device, trigger a wipe through your own Intune tenant, and see the signed certificate before you decide anything.

Connect your Intune tenant.

Two free wipes, no card required, and a signed certificate for every drive.

Start free trial