logo
search
Security Policy Errors

How to Remove Inactive Devices from Microsoft Defender for Endpoint

Huma Ashraf ChHuma Ashraf Ch Sep 28, 2026 870 views

Question details

The user needs to remove inactive devices from the Microsoft Defender for Endpoint portal, but cannot use the standard offboarding script because the devices have already been deleted from Azure or the physical environment.

How to Remove Inactive Devices from Microsoft Defender for Endpoint
Product
Microsoft Defender for Endpoint
Device & OS
not provided
Scenario
Attempting to clean up the security.microsoft.com device inventory after devices are permanently offline or deleted.
Observed behavior
The inactive devices remain listed as onboarded in the portal and there is no direct delete option available in the user interface to manually remove them.
Before you start

Verify your organization's data retention policy in the Microsoft Defender portal, as inactive devices are often retained automatically for compliance and auditing purposes before being permanently deleted.

Solution 1Recommended

Rely on Automatic Data Retention Cleanup

Because Microsoft Defender for Endpoint does not provide a manual delete button for inactive devices, the primary method is to allow the system's data retention policy to automatically clear the records.

To preserve security audit trails, Microsoft intentionally restricts the manual deletion of onboarded device records. When a device is deleted from Azure or permanently disconnected without running the offboarding script, its state will eventually switch to 'Inactive'.

Once marked inactive, the device will remain in the portal until the configured data retention period expires. After this period, the system will automatically purge the device record.

1
Log in to the portal

Navigate to security.microsoft.com and sign in with your administrator credentials.

2
Access retention settings

Go to Settings > Endpoints > Data retention to view your current configuration.

3
Verify retention period

Check how many days your data is retained (typically between 30 and 180 days). The inactive device will automatically disappear from the onboarded list once it exceeds this timeframe.

Rely on Automatic Data Retention Cleanup
Device State: Inactive devices do not consume active licenses and will not negatively impact your current security score while waiting for the retention period to expire.
Free Microsoft Office alternative

Streamline Your Office Work with WPS Office

While managing enterprise security endpoints and Microsoft policies can be complex, your daily document management doesn't have to be. WPS Office offers a completely free, lightweight, and easy-to-use alternative to Microsoft Office, ensuring your workflow remains smooth and hassle-free.

  1. 1. Download the installer: Visit the official WPS Office website and download the free version for your operating system.
  2. 2. Install the software: Run the installer and follow the simple on-screen prompts to complete the setup in minutes.
  3. 3. Open and edit seamlessly: Launch WPS Office and instantly open your existing Microsoft Word, Excel, or PowerPoint files without losing formatting.
Fully compatible with Microsoft Office formats including DOCX, XLSX, and PPTX.Lightweight installation with blazing fast loading speeds.No complex enterprise administration or backend management required.Familiar tabbed user interface for seamless migration.
microsoft office alternative - wps office

Frequently Asked Questions

Why is there no 'delete' button for devices in Microsoft Defender?

Microsoft purposely omits a manual delete button to preserve security logs and maintain an accurate audit trail for compliance. Devices must either be offboarded via a script or naturally age out according to your organization's data retention policy.

How long will an inactive device stay in the Defender portal?

The duration depends on your data retention settings in the Microsoft Defender portal, which is typically configured to retain data for 30, 90, or 180 days. Once the device has been inactive longer than this period, it is automatically removed.

What is the standard way to remove a device if it still exists?

If the device is still active and accessible, you should navigate to Settings > Endpoints > Offboarding in the Defender portal, download the offboarding package for the specific operating system, and run the script on the local machine.