{"id":3364,"date":"2019-12-17T17:19:27","date_gmt":"2019-12-17T16:19:27","guid":{"rendered":"https:\/\/www.lieben.nu\/liebensraum\/?p=3364"},"modified":"2019-12-17T17:19:27","modified_gmt":"2019-12-17T16:19:27","slug":"duplicate-azuread-device-cleanup","status":"publish","type":"post","link":"https:\/\/lieben.nu\/liebensraum\/2019\/12\/duplicate-azuread-device-cleanup\/","title":{"rendered":"Duplicate AzureAD Device Cleanup"},"content":{"rendered":"\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/www.lieben.nu\/liebensraum\/wp-content\/uploads\/2019\/12\/2019-12-17-17_18_02-Devices-All-devices-Microsoft-Azure.png\"><img loading=\"lazy\" decoding=\"async\" width=\"1548\" height=\"161\" src=\"https:\/\/www.lieben.nu\/liebensraum\/wp-content\/uploads\/2019\/12\/2019-12-17-17_18_02-Devices-All-devices-Microsoft-Azure.png\" alt=\"\" class=\"wp-image-3366\" srcset=\"https:\/\/lieben.nu\/liebensraum\/wp-content\/uploads\/2019\/12\/2019-12-17-17_18_02-Devices-All-devices-Microsoft-Azure.png 1548w, https:\/\/lieben.nu\/liebensraum\/wp-content\/uploads\/2019\/12\/2019-12-17-17_18_02-Devices-All-devices-Microsoft-Azure-300x31.png 300w, https:\/\/lieben.nu\/liebensraum\/wp-content\/uploads\/2019\/12\/2019-12-17-17_18_02-Devices-All-devices-Microsoft-Azure-1024x107.png 1024w, https:\/\/lieben.nu\/liebensraum\/wp-content\/uploads\/2019\/12\/2019-12-17-17_18_02-Devices-All-devices-Microsoft-Azure-768x80.png 768w, https:\/\/lieben.nu\/liebensraum\/wp-content\/uploads\/2019\/12\/2019-12-17-17_18_02-Devices-All-devices-Microsoft-Azure-1536x160.png 1536w\" sizes=\"auto, (max-width: 1548px) 100vw, 1548px\" \/><\/a><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">When you swap a device by reimaging or reinstalling, the Hardware ID stays the same. This results in multiple Device Entries in Azure AD and causes issues with Conditional Access as Intune thinks the older version isn&#8217;t actually compliant even though Intune just has 1 record.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Most methods (<a rel=\"noreferrer noopener\" aria-label=\"such as Nicola's (opens in a new tab)\" href=\"https:\/\/tech.nicolonsky.ch\/clean-up-azure-ad-devices\/\" target=\"_blank\">such as Nicola&#8217;s<\/a>) to combat this is by cleaning up stale devices in Azure AD based on their last Active Date. However, the downside of this method is that it may touch devices which weren&#8217;t duplicates, just dormant during, e.g. a vacation. Additionally, a bug in AzureAD can cause the older duplicate&#8217;s active date to be updated instead of the correct device.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The following script detects duplicates based on the Hardware ID and registration date instead and disables all but the most recent entry. It can supplement stale device removal based on Last Activity.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Note: only works for Windows registered devices.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Git: <a rel=\"noreferrer noopener\" aria-label=\"disable-duplicateAzureAdDevices.ps1 (opens in a new tab)\" href=\"https:\/\/gitlab.com\/Lieben\/assortedFunctions\/blob\/master\/disable-duplicateAzureAdDevices.ps1\" target=\"_blank\">disable-duplicateAzureAdDevices.ps1<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>When you swap a device by reimaging or reinstalling, the Hardware ID stays the same. This results in multiple Device Entries in Azure AD and causes issues with Conditional Access as Intune thinks the older version isn&#8217;t actually compliant even though Intune just has 1 record. Most methods (such as Nicola&#8217;s) to combat this is &hellip; <a href=\"https:\/\/lieben.nu\/liebensraum\/2019\/12\/duplicate-azuread-device-cleanup\/\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">Duplicate AzureAD Device Cleanup<\/span> <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_crdt_document":"","footnotes":""},"categories":[7,39],"tags":[],"class_list":["post-3364","post","type-post","status-publish","format-standard","hentry","category-azuread","category-powershell"],"_links":{"self":[{"href":"https:\/\/lieben.nu\/liebensraum\/wp-json\/wp\/v2\/posts\/3364","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lieben.nu\/liebensraum\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lieben.nu\/liebensraum\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lieben.nu\/liebensraum\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/lieben.nu\/liebensraum\/wp-json\/wp\/v2\/comments?post=3364"}],"version-history":[{"count":0,"href":"https:\/\/lieben.nu\/liebensraum\/wp-json\/wp\/v2\/posts\/3364\/revisions"}],"wp:attachment":[{"href":"https:\/\/lieben.nu\/liebensraum\/wp-json\/wp\/v2\/media?parent=3364"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lieben.nu\/liebensraum\/wp-json\/wp\/v2\/categories?post=3364"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lieben.nu\/liebensraum\/wp-json\/wp\/v2\/tags?post=3364"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}