Need to restore a device record recently deleted from intune

Jeremy Hildeen 0 Reputation points
2024-05-09T21:45:32.9633333+00:00

Greetings Internet Hive Mind.

iI have quite a conundrum on my hands. I recently had a user leave my company who took it upon himself to wipe his hard drive on the way out. Attempts to recover the data have all failed. Following the IT protocol I have deleted the device from AD, AAD and Intune. Now I am told they want to go after this former employee legally and want every record they can find on him. Is there a way to recover this recently deleted intune record? I have found bits and peices across the interwebs but nothing solid.

Any help you can provide would be greatly appreciated.

Microsoft Intune Security
Microsoft Intune Security
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
359 questions
Microsoft Intune Enrollment
Microsoft Intune Enrollment
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Enrollment: The process of requesting, receiving, and installing a certificate.
1,277 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,521 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. ZhoumingDuan-MSFT 9,390 Reputation points Microsoft Vendor
    2024-05-10T02:08:35.2333333+00:00

    @Jeremy Hildeen, Thanks for posting in Q&A.

    From your description, I know you want to restore a device record recently deleted from Intune.

    Based on my searches, there is no way to recover a device that has been deleted from Intune, you will need to re-join the device to Intune, but you can check the Audit logs to find out which user deleted a device as well as make sure that the device was actually indeed enrolled to Intune.

    Here is the location of the Audit log.

    Intune portal > Tenant administration > Audit logs

    User's image

    Moreover, you can check the logs in the Event Viewer and look for the Intune cert issued by Sc_Online_Issuing on the device side to confirm that the device was enrolled to Intune.

    Location of Log: Event Viewer > Applications and Services Logs > Microsoft > Windows > DeviceManagement-Enterprise-Diagnostics-Provider > Admin

    Location of certificate: From the Start menu, type Run > MMC > Choose File > Add/Remove Snap-ins > Double-click Certificates, choose Computer account > Next, and select Local Computer > Double-click Certificates (Local computer) and choose Personal > Certificates.

    Hope it will help.

    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.