How to Find Microsoft Entra Device Office Location with PowerShell
Question details
The user needs to automate a process via PowerShell to identify the physical office locations of Microsoft Entra devices, filter out Intune-managed devices, and clean up stale device records.

- Product
- Microsoft Entra ID
- Device & OS
- not provided
- Scenario
- Developing a PowerShell automation script for enterprise device management and directory clean-up.
- Observed behavior
- The user requires specific scripting logic or guidance on querying extension attributes and management types to accurately identify and filter targeted devices.
Ensure that the Microsoft Graph PowerShell SDK is installed on your machine and that you have the appropriate administrative permissions (such as Global Administrator or Intune Administrator) to read directory and device properties.
Seek Specialized Support in the Microsoft Q&A Community
Because managing Entra ID properties and Intune exclusions requires advanced identity management expertise, consulting Microsoft specialists is the most reliable approach.
Complex PowerShell automation involving Microsoft Entra device properties often requires custom extension attributes because a default 'Office Location' property might not be populated natively for all device objects. Engaging with the official Microsoft Entra ID community ensures you get up-to-date and secure scripting advice.
Navigate to the official Microsoft Q&A platform using your web browser.
When drafting your post, apply the 'Microsoft Entra ID' and 'Microsoft Intune' tags to reach the correct identity and device management specialists.
Share your current PowerShell snippet and clearly state your goals: identifying physical locations, removing stale entries, and excluding devices managed by Intune.

Use Microsoft Graph PowerShell to Query Device Management Types
While community help is recommended for advanced logic, you can start building your script by using the Microsoft Graph SDK to list devices and check their management types.
Equip Your Entra-Managed Devices with WPS Office
While you manage your enterprise identity and device infrastructure, ensure your workforce has the productivity tools they need. WPS Office is a highly compatible, fast, and free alternative to Microsoft Office that is easy to deploy across all your managed devices.
- 1. Download the Installer: Visit the official WPS Office website and download the enterprise-friendly setup file.
- 2. Deploy to Devices: Distribute the lightweight software to your endpoints using your preferred endpoint management tool.
- 3. Start Creating: Users can immediately open their existing Microsoft Office documents without formatting loss or compatibility issues.

Frequently Asked Questions
Does Entra ID have a default 'Office Location' attribute for devices?
Unlike user objects, device objects in Entra ID do not always have a natively populated physical office location field. Organizations usually track physical locations using Device Extension Attributes or by syncing specific attributes from on-premises Active Directory.
How do I identify Intune-managed devices via Microsoft Graph PowerShell?
When retrieving devices using 'Get-MgDevice', check the 'managementType' property. Devices managed by Microsoft Intune typically reflect 'MDM' in this field.
What is the recommended property to determine if a device is stale?
The 'approximateLastSignInDateTime' property is the most reliable indicator of device activity in Microsoft Entra. Administrators commonly use this timestamp to filter and remove devices that haven't authenticated within the last 90 or 120 days.




