Affect on device after removing license

IntuneUser 171 Reputation points
2022-06-29T04:33:28.947+00:00

I have EMS license assigned to a user. And the user has an enrolled device.

I would like to know what the effect would be if I directly remove the license for the user from Intune portal.

(a) Will the device remain enrolled in Intune if my device is:
-> Only Azure AD Joined
-> Hybrid Azure AD Joined
-> Co-managed with SCCM
I would like to know the enrollment status in all the above 3 scenarios.

(b) What will happen to the policies that are targeted to the device. Will those policy stop taking affect?

(c) Suppose I deployed a BitLocker policy to the device. After removing the Intune license, will my BitLocker policy stop taking effect and my device would decrypt itself and would no longer be BitLocker encrypted ?

Windows 10 Security
Windows 10 Security
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
2,753 questions
Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,715 questions
Microsoft Intune Enrollment
Microsoft Intune Enrollment
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Enrollment: The process of requesting, receiving, and installing a certificate.
1,244 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,321 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Limitless Technology 39,351 Reputation points
    2022-06-29T14:58:37.267+00:00

    Hello IntuneUser-0687 ,
    Based Upon the information provided.
    Yes that is possible that when we assigned the license to the user and then remove it directly for the user from Intune portal then this will affect the compliance status. and the device is no logger be compliant.
    Thus the the device will not remain enrolled in Intune For:
    -> Only Azure AD Joined
    -> Hybrid Azure AD Joined
    -> Co-managed with SCCM
    What will happen to the policies that are targeted to the device. Will those policy stop taking affect?
    Yes this will take affect.
    and if you delete the device from AAD and the device communicates with AAD again (nothing can happen if it doesn't communicate again as it would never know the AAD object was deleted), then the key protector is removed from the OS volume leaving BitLocker enabled but suspended.

    ------------------------------------------------------------------------------------------------------------------------------

    --If the reply is helpful, please Upvote and Accept as answer--

    1 person found this answer helpful.

  2. Lu Dai-MSFT 28,341 Reputation points
    2022-06-29T07:08:34.753+00:00

    @IntuneUser Thanks for posting in our Q&A.

    Based on my research, if we remove intune license from a user that has managed devices, it may affect the compliance or management of these devices.

    So, if you want to use intune to manage devices and apps, it is suggested to assign intune license to users.

    Thanks for your understanding.


    If the answer is the right solution, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments