Post

Intune Device Reprovisioning Guide

How STRSI reclaims, wipes, and reprovisions Intune-managed Windows devices from departing employees for reassignment to new users.

Intune Device Reprovisioning Guide

Overview

This guide explains the preferred STRSI process for handling a Windows laptop returned by a departing employee and preparing it for reassignment to a new user.

This process ensures:

  • Previous user data is removed
  • Device remains managed by STRSI
  • Autopilot registration is preserved
  • Intune compliance and security baselines reapply automatically
  • The next user receives a clean, ready-to-use device

Primary method: Windows Autopilot Reset
Fallback method: Full Windows reset with Autopilot re-entry


When to Use This Process

Use this workflow when:

  • A user has left STRSI
  • The device is corporate-owned
  • The device should be reused internally
  • The device is (or should be) registered in Windows Autopilot

Do not use this process for:

  • Devices being decommissioned permanently
  • BYOD devices
  • Devices leaving STRSI ownership

Prerequisites

  • Device must run Windows 10/11 Pro or Enterprise
  • Device must have internet access
  • Device must be registered in Windows Autopilot
  • Admin must have Intune permissions to manage devices
  • Returned device must not be BitLocker-locked without recovery key access

Step 1 – Unassign the Previous User (Admin Action)

Before resetting the device, ensure the previous employee is fully disassociated.

In Microsoft Intune Admin Center

  1. Navigate to: Devices → All devices
  2. Select the returned laptop
  3. Review Primary user
  4. If set to the former employee:
    • Click Change primary user
    • Clear or leave unassigned

Clearing the primary user prevents reporting, licensing, and compliance confusion.

  1. Go to Entra admin center → Devices
  2. Locate the device object
  3. Confirm the former employee is no longer listed as an owner

Step 2 – Trigger Autopilot Reset (Preferred)

Autopilot Reset does not reinstall Windows. It prepares the device for immediate reuse.

Option A: Local Autopilot Reset (In-Hand Device)

This is the recommended and fastest method when IT has physical access.

  1. Power on the device
  2. Stop at the Windows sign-in screen
  3. Press:

    1
    
    Ctrl + Windows + R
    

    If this doesn’t bring up a menu, proceed to Option B

  4. Select Autopilot Reset / Reset this device
  5. Authenticate if prompted
  6. Confirm reset

What this does:

  • Removes all user profiles and data
  • Keeps Entra ID join
  • Keeps Intune enrollment
  • Keeps Autopilot registration
  • Returns device to OOBE

Option B: Remote Autopilot Reset (If Device Is Enrolled)

If the device still appears in Intune:

  1. Go to Devices → All devices
  2. Select the device
  3. Choose Autopilot Reset
  4. Confirm

This requires the device to be actively enrolled and online.


Step 3 – Assign the New User

Once the device resets and returns to OOBE:

Option A: User-Driven Assignment (Preferred)

  1. Ship or hand the device to the new employee
  2. User signs in during OOBE with their STRSI work email
  3. Autopilot provisions the device automatically
  4. Intune assigns policies, apps, and security baselines

This is the default STRSI approach.


Option B: Pre-Assign User (Optional)

If the device is preallocated:

  1. In Intune, locate the device
  2. Assign the Primary user
  3. Ship device

Pre-assignment is optional and not required for Autopilot to function.


Step 4 – Verify Successful Reprovisioning

After the new user signs in:

  1. Confirm device appears in: Intune → Devices → All devices
  2. Verify:
    • Correct user
    • Compliance status transitions to Compliant
    • Required applications install
  3. Confirm BitLocker is enabled

Compliance may take several hours and multiple reboots.


Fallback – Full Reset (If Autopilot Reset Is Unavailable)

Use this only if Autopilot Reset does not appear.

  1. Sign in as local/admin user
  2. Navigate to: Settings → System → Recovery → Reset this PC
  3. Choose:
    • Remove everything
    • Cloud download
  4. Complete reset

After reset:

  • Device re-enters OOBE
  • Autopilot applies automatically if the device is registered

Common Pitfalls

  • Forgetting to clear the previous primary user
  • Attempting to reuse devices without resetting
  • Expecting Autopilot to rerun without OOBE
  • Using Microsoft Store or personal accounts during setup

Summary

TaskRequired
Remove old user dataAutopilot Reset
Keep device managedAutopilot Reset
Reassign to new userOOBE sign-in
Reapply policiesAutomatic
Re-import hardware hashNot required

Autopilot Reset is the STRSI standard for device reuse.


Contact

Questions or escalations: Trever Ehrfurthtehrfurth@strsi.com.

This post is licensed under CC BY 4.0 by the author.