Ever found yourself scratching your head over Microsoft Intune’s reset methods? With three options, Wipe, Fresh Start, and Autopilot Reset, plus the Retire and Delete actions, it’s easy to feel overwhelmed. Pick the wrong one and you’ll either nuke data you needed to keep, or leave sensitive content on a device that’s about to walk out the door.
Here’s what each method actually does, when to use it, and how the choice affects team member data, apps, Azure AD identity and Intune enrolment. By the end you’ll know exactly which button to press in any reset scenario.
Key takeaways
- Wipe is the nuclear option. Removes everything, restores factory defaults, unregisters the device from Azure AD and Intune.
- Fresh Start reinstalls Windows, strips OEM bloatware, and can preserve team member data and Intune enrolment.
- Autopilot Reset deletes team member data and apps but keeps the device tied to Azure AD and Intune, ready for a new team member in minutes.
- Retire and Delete aren’t resets. They unenrol the device but leave the OS and personal data alone, useful for BYOD off-boarding.
- Choose by scenario: lost/stolen = Wipe, sluggish/cluttered = Fresh Start, reassigning to a new team member = Autopilot Reset.

Why remote reset matters
For UK SMBs, especially those handling client data in professional services, healthcare or finance, every laptop and tablet is a potential breach waiting to happen. When a device is lost, an employee leaves, or a machine starts misbehaving, you need to act fast and act remotely. Intune’s reset actions let you do exactly that, without an engineer physically touching the device.
Done right, you stay compliant with UK GDPR, your insurer doesn’t have to file a notifiable breach, and your fleet stays clean and predictable. Done wrong, you waste hours rebuilding a device you only needed to refresh, or leave a leaver with a working laptop full of company files. Picking the right reset method matters.
Wipe: the nuclear option
Wipe is exactly what it sounds like. Send the command and the target device returns to factory defaults, no data, no apps, no settings, no Azure AD or Intune enrolment. The next person who powers it on goes through Windows out-of-box experience as if it just left the factory.
What Wipe actually does
- Deletes all personal and corporate data on the device.
- Removes every installed application, both store apps and Win32 apps.
- Resets all settings and policies.
- Unregisters the device from Azure AD and Intune.
- Restores the device to its pristine, out-of-the-box state.
When to use Wipe
- The device is lost, stolen or otherwise compromised.
- You’re handing the hardware to a new employee and want absolute certainty all previous data is gone.
- You’re disposing of or repurposing the device and need a clean handover.
Wipe is the most powerful action in the Intune toolkit. Use it deliberately, because once it runs, there’s no undo.
Caveat: wiping a device without retaining enrolment means you’ll need to reassign licences and reconfigure policies when the device is set up again. That’s fine for a leaver’s machine but overkill if all you needed was a tidy-up.
Fresh Start: a clean slate (with benefits)
Sometimes you don’t need to nuke the device, you just want a clean Windows install without all the OEM bloatware that came preinstalled. Fresh Start is built for that.
What Fresh Start does
- Reinstalls a clean, up-to-date version of Windows 10 or 11.
- Removes preinstalled OEM software and any apps the team member installed.
- Optionally preserves team member data (you choose during the action).
- Keeps the device’s Azure AD and MDM registration intact, so it’s still managed by Intune afterwards.
When to use Fresh Start
- The device is sluggish, cluttered or has accumulated three years of crud.
- You want to refresh the OS without losing the team member’s documents and settings.
- You want the device to remain enrolled in Intune so it gets policies pushed back automatically.
Important note: Fresh Start removes installed Win32 applications and most MDM-pushed policies, so you’ll need Intune to redeploy your essential business software afterwards. If your apps are properly packaged in Intune, this happens automatically. If they’re a manual install, plan accordingly.
Autopilot Reset: quick and organised
Autopilot Reset is the fastest way to prepare a device for a new team member. It removes all team member data, apps and settings while keeping the device tied to Azure AD and Intune. The reset preserves regional and Wi-Fi settings, then drops the device straight back to the Windows sign-in screen, ready for a fresh team member to log in and pick up where the policies left off.
What Autopilot Reset does
- Removes all team member data, apps and personal settings.
- Keeps the device joined to Azure AD and enrolled in Intune.
- Preserves Wi-Fi profiles and regional settings.
- Lands the device on the Windows sign-in screen for the next team member.
When to use Autopilot Reset
- You’re onboarding a new starter or contractor and need to hand them a clean device fast.
- A device is returning from long-term loan and needs to be reassigned without a full rebuild.
- You want to keep enrolment and configuration but remove the previous team’s footprint completely.
Autopilot Reset shines for organisations using Windows Autopilot. It retains the device’s identity in Azure AD, so there’s no need to reprovision from scratch, the next team member signs in and policies, apps and settings flow back automatically. Onboarding time drops from hours to minutes.
Retire and Delete: clearing management profiles
Retire and Delete aren’t reset actions, but they’re often confused with them. Both are about removing devices from Intune management, not wiping the OS.
Retire
Unenrols the device from Intune. Removes company apps, configuration profiles, certificates and policies. Personal data on the device is left alone. The device record is kept in Intune for a short period before being removed.
Delete
Same as Retire but the device record is removed from Intune immediately. Useful when you know the device isn’t coming back and you want a tidy device list.
These two are mostly used for bring-your-own-device (BYOD) scenarios. When an employee with a personal laptop leaves the company, you Retire or Delete to strip out the company data and policies while leaving their personal files alone. They keep their laptop, you keep your data, everyone’s happy.
Choosing the right reset method
Frequently asked questions
Will Wipe work if the device is offline?
Wipe queues the action and runs as soon as the device next checks in with Intune. If the device never reconnects (truly lost, smashed, or factory-reset by the thief), Intune can only remove the device from your tenant. The data on the device is gone from your control either way; what Wipe achieves is a forensic record that the action was issued.
Can I undo a Wipe or Fresh Start?
No. Both actions are destructive once they execute. Make sure team member data is backed up to OneDrive or your enterprise backup before issuing the action. Autopilot Reset is also destructive but the device stays enrolled, so re-provisioning is much faster.
What’s the difference between Wipe and “Fresh Start with no data preservation”?
Both end with a clean OS, but Wipe also unregisters the device from Azure AD and Intune. Fresh Start (without data preservation) keeps the device enrolled. If you want the device to come back into your fleet automatically, use Fresh Start. If you’re getting rid of it, use Wipe.
Does Autopilot Reset preserve installed apps?
No. Autopilot Reset removes all apps and team member data. It keeps regional/Wi-Fi settings and Azure AD/Intune enrolment, so when the next team member signs in, your Intune apps deploy automatically based on their assignments.
How does this fit with Cyber Essentials?
Intune-driven device management is one of the strongest answers to several Cyber Essentials control areas: secure configuration, team member access control, malware protection. We cover the full setup in our Cyber Essentials guide and Microsoft 365 setup guide.
What if my device isn’t enrolled in Intune yet?
You can’t use any of these actions on an unenrolled device. Step one is enrolling the device, either via Autopilot for new devices, or by joining an existing Windows device to Azure AD and pushing Intune enrolment via Conditional Access. We do this as part of every managed-IT onboarding.
Initial IT runs Microsoft Intune environments for UK businesses across Lichfield, Staffordshire and the West Midlands as part of our managed IT services. Properly deployed, Intune saves hours per device and dramatically tightens your security posture.
