Sync Devices
This script connects to Microsoft Graph and triggers synchronization operations on targeted devices. You can target devices by specific names, device IDs, or by Entra ID group membership. The script provides real-time feedback on sync operations and handles errors gracefully.
New to runbook deployment? Follow the step-by-step guide from the Deploy to Azure button to the first scheduled run, including granting Graph permissions to the managed identity.
// QUALITY CHECKS
Validation status
Quality checks
All checks pass- ParsePass
- LintPass
- MetadataPass
- Runbook-readyPass
- Module depsPass
Tests run automatically on every change. What does each check mean?
// REQUIRED PERMISSIONS
Microsoft Graph scopes
DeviceManagementManagedDevices.PrivilegedOperations.AllAllows the app to perform remote high impact actions such as wiping the device or resetting the passcode on devices managed by Microsoft Intune, without a signed-in user.
DeviceManagementManagedDevices.Read.AllAllows the app to read the properties of devices managed by Microsoft Intune, without a signed-in user.
GroupMember.Read.AllAllows the app to read memberships and basic group properties for all groups without a signed-in user.
Running this as an Azure Automation runbook? These scopes must be granted to the account's managed identity, which has no portal UI. The deployment walkthrough shows the exact Cloud Shell commands.
// CHANGELOG
Version history
Entry · 01
1.8 - Let the finally block own Graph disconnection so early exits do not emit a second-disconnect error
Entry · 02
1.7 - Ignore empty string-array values supplied by Azure Automation when validating the selected target
Entry · 03
1.6 - Added a portal-safe DryRun mode and records an empty target group as a successful no-op
Entry · 04
1.5 - Added Azure Automation contract validation, portal-safe boolean parameters, beta Graph endpoints, and terminating paging errors
Entry · 05
1.4 - Azure Automation now records script progress, outcomes, and summaries in job history
Entry · 06
1.3 - Exit code 1 when any sync fails; 429 retry with 60s wait on sync calls; group matching now falls back to userPrincipalName/mail so user-membership groups work; group lookup failures abort with a distinct error; added $select to managed device queries
Entry · 07
1.2 - Local runs now use MgGraphCommunity for WAM-free interactive sign-in (auto-installed if missing)
Entry · 08
1.0 - Initial release
Entry · 09
1.1 - Improved authentication scopes and fixed group device members search
Entry · 10
added `DeviceManagementManagedDevices.PrivilegedOperations.All` scope for interactive Graph auth
Entry · 11
fixed `Get-DevicesByEntraGroup` to correctly match devices by `azureADDeviceId`
Entry · 12
replaced `+=` with `[System.Collections.Generic.List[Object]]` for faster result handling
Entry · 13
standardized string quoting to single quotes
Entry · 14
optimized `Get-MgGraphAllPage` with strongly typed list
Entry · 15
replaced `Out-Null` with `$null =` assignment for cleaner output suppression
Entry · 16
improved consistency in logging and error handling
// CODE
Source
<#
.TITLE
Sync Devices
.SYNOPSIS
Trigger synchronization on specific managed devices in Intune or devices in an Entra ID group.
.DESCRIPTION
This script connects to Microsoft Graph and triggers synchronization operations on targeted devices.
You can target devices by specific names, device IDs, or by Entra ID group membership.
The script provides real-time feedback on sync operations and handles errors gracefully.
.TAGS
Operational,Devices
.MINROLE
Intune Administrator
.PERMISSIONS
DeviceManagementManagedDevices.PrivilegedOperations.All,DeviceManagementManagedDevices.Read.All,GroupMember.Read.All
.AUTHOR
Ugur Koc
.VERSION
1.8
.CHANGELOG
1.8 - Let the finally block own Graph disconnection so early exits do not emit a second-disconnect error
1.7 - Ignore empty string-array values supplied by Azure Automation when validating the selected target
1.6 - Added a portal-safe DryRun mode and records an empty target group as a successful no-op
1.5 - Added Azure Automation contract validation, portal-safe boolean parameters, beta Graph endpoints, and terminating paging errors
1.4 - Azure Automation now records script progress, outcomes, and summaries in job history
1.3 - Exit code 1 when any sync fails; 429 retry with 60s wait on sync calls; group matching now falls back to userPrincipalName/mail so user-membership groups work; group lookup failures abort with a distinct error; added $select to managed device queries
1.2 - Local runs now use MgGraphCommunity for WAM-free interactive sign-in (auto-installed if missing)
1.0 - Initial release
1.1 - Improved authentication scopes and fixed group device members search
- added `DeviceManagementManagedDevices.PrivilegedOperations.All` scope for interactive Graph auth
- fixed `Get-DevicesByEntraGroup` to correctly match devices by `azureADDeviceId`
- replaced `+=` with `[System.Collections.Generic.List[Object]]` for faster result handling
- standardized string quoting to single quotes
- optimized `Get-MgGraphAllPage` with strongly typed list
- replaced `Out-Null` with `$null =` assignment for cleaner output suppression
- improved consistency in logging and error handling
.LASTUPDATE
2026-07-30
.EXAMPLE
.\sync-devices.ps1 -DeviceNames "LAPTOP001","DESKTOP002"
Synchronizes specific devices by name
.EXAMPLE
.\sync-devices.ps1 -DeviceIds "12345678-1234-1234-1234-123456789012","87654321-4321-4321-4321-210987654321"
Synchronizes specific devices by their Intune device IDs
.EXAMPLE
.\sync-devices.ps1 -EntraGroupName "IT Department Devices"
Synchronizes all devices belonging to users in the specified Entra ID group
.EXAMPLE
.\sync-devices.ps1 -EntraGroupName "Sales Team" -ForceSync "true"
Forces synchronization of all devices for users in the Sales Team group
.EXAMPLE
.\sync-devices.ps1 -EntraGroupName "Sales Team" -DryRun "true"
Lists the target devices without sending a synchronization action
.NOTES
- Supports both local execution and Azure Automation Runbook environments
- Automatically detects execution environment and uses appropriate authentication method
- Local execution: Uses interactive authentication with specified scopes
- Azure Automation: Uses Managed Identity authentication
- Requires Microsoft.Graph.Authentication module (auto-installs if missing in local environment)
- Use -ForceModuleInstall to skip installation prompts in local environment
- Requires appropriate permissions in Azure AD
- Sync operations are triggered immediately but may take time to complete on the device
- Use -ForceSync to override the 1-hour sync threshold
- The script will show real-time progress and results
- Local interactive sign-in uses the MgGraphCommunity module to avoid the Graph SDK's mandatory WAM broker on Windows
#>
[CmdletBinding()]
param(
[Parameter(Mandatory = $false)]
[string[]]$DeviceNames,
[Parameter(Mandatory = $false)]
[string[]]$DeviceIds,
[Parameter(Mandatory = $false)]
[string]$EntraGroupName,
[Parameter(Mandatory = $false)]
[ValidateSet("true", "false", "1", "0", '$true', '$false')]
[string]$ForceSync,
[Parameter(Mandatory = $false, HelpMessage = "Preview target devices without synchronizing them")]
[ValidateSet("true", "false", "1", "0", '$true', '$false')]
[string]$DryRun,
[Parameter(Mandatory = $false)]
[int]$SyncDelaySeconds = 2,
[Parameter(Mandatory = $false, HelpMessage = 'Force module installation without prompting')]
[ValidateSet("true", "false", "1", "0", '$true', '$false')]
[string]$ForceModuleInstall
)
# Normalize the local module-install override for Azure Automation parameter binding.
$forceModuleInstallRaw = [string]$ForceModuleInstall
Remove-Variable -Name ForceModuleInstall
if ([string]::IsNullOrWhiteSpace($forceModuleInstallRaw)) {
$ForceModuleInstall = $false
}
elseif ($forceModuleInstallRaw.Trim().ToLowerInvariant() -in @("true", "1", '$true')) {
$ForceModuleInstall = $true
}
elseif ($forceModuleInstallRaw.Trim().ToLowerInvariant() -in @("false", "0", '$false')) {
$ForceModuleInstall = $false
}
else {
throw "Parameter 'ForceModuleInstall' accepts only true, false, 1, 0, $true, or $false."
}
# Azure Automation supplies portal parameter values as strings. Normalize the
# public boolean parameters once so local and runbook execution use real booleans.
foreach ($runbookBooleanParameter in @('ForceSync', 'DryRun')) {
$runbookBooleanRaw = [string](Get-Variable -Name $runbookBooleanParameter -ValueOnly)
Remove-Variable -Name $runbookBooleanParameter
if ([string]::IsNullOrWhiteSpace($runbookBooleanRaw)) {
Set-Variable -Name $runbookBooleanParameter -Value $false
continue
}
switch ($runbookBooleanRaw.Trim().ToLowerInvariant()) {
{ $_ -in @("true", "1", '$true') } {
Set-Variable -Name $runbookBooleanParameter -Value $true
}
{ $_ -in @("false", "0", '$false') } {
Set-Variable -Name $runbookBooleanParameter -Value $false
}
default {
throw "Parameter '$runbookBooleanParameter' accepts only true, false, 1, 0, $true, or $false."
}
}
}
$DeviceNames = @($DeviceNames | Where-Object { -not [string]::IsNullOrWhiteSpace([string]$_) })
$DeviceIds = @($DeviceIds | Where-Object { -not [string]::IsNullOrWhiteSpace([string]$_) })
$selectedTargets = @(
if ($DeviceNames.Count -gt 0) { 'DeviceNames' }
if ($DeviceIds.Count -gt 0) { 'DeviceIds' }
if (-not [string]::IsNullOrWhiteSpace($EntraGroupName)) { 'EntraGroup' }
)
if ($selectedTargets.Count -ne 1) {
throw "Specify exactly one target: DeviceNames, DeviceIds, or EntraGroupName."
}
$TargetMode = $selectedTargets[0]
# ============================================================================
# ENVIRONMENT DETECTION AND SETUP
# ============================================================================
function Initialize-RequiredModule {
<#
.SYNOPSIS
Ensures required modules are available and loaded
#>
param(
[string[]]$ModuleNames,
[bool]$IsAutomationEnvironment,
[bool]$ForceInstall = $false
)
foreach ($ModuleName in $ModuleNames) {
Write-Verbose "Checking module: $ModuleName"
# Check if module is available
$module = Get-Module -ListAvailable -Name $ModuleName | Select-Object -First 1
if (-not $module) {
if ($IsAutomationEnvironment) {
$errorMessage = @"
Module '$ModuleName' is not available in this Azure Automation Account.
To resolve this issue:
1. Go to Azure Portal
2. Navigate to your Automation Account
3. Go to 'Modules' > 'Browse Gallery'
4. Search for '$ModuleName'
5. Click 'Import' and wait for installation to complete
Alternative: Use PowerShell to import the module:
Import-Module Az.Automation
Import-AzAutomationModule -AutomationAccountName "YourAccount" -ResourceGroupName "YourRG" -Name "$ModuleName"
"@
throw $errorMessage
}
else {
# Local environment - attempt to install
Write-Information "Module '$ModuleName' not found. Attempting to install..." -InformationAction Continue
if (-not $ForceInstall) {
$response = Read-Host "Install module '$ModuleName'? (Y/N)"
if ($response -notmatch '^[Yy]') {
throw "Module '$ModuleName' is required but installation was declined."
}
}
try {
# Check if running as administrator for AllUsers scope
$isAdmin = ([Security.Principal.WindowsPrincipal] [Security.Principal.WindowsIdentity]::GetCurrent()).IsInRole([Security.Principal.WindowsBuiltInRole] 'Administrator')
$scope = if ($isAdmin) { 'AllUsers' } else { 'CurrentUser' }
Write-Information "Installing '$ModuleName' in scope '$scope'..." -InformationAction Continue
Install-Module -Name $ModuleName -Scope $scope -Force -AllowClobber -Repository PSGallery
Write-Information "✓ Successfully installed '$ModuleName'" -InformationAction Continue
}
catch {
throw "Failed to install module '$ModuleName': $($_.Exception.Message)"
}
}
}
# Import the module
try {
Write-Verbose "Importing module: $ModuleName"
Import-Module -Name $ModuleName -Force -ErrorAction Stop
Write-Verbose "✓ Successfully imported '$ModuleName'"
}
catch {
throw "Failed to import module '$ModuleName': $($_.Exception.Message)"
}
}
}
# Detect execution environment
if ($PSPrivateMetadata.JobId.Guid) {
Write-Output 'Running inside Azure Automation Runbook'
$IsAzureAutomation = $true
}
else {
Write-Output 'Running locally in IDE or terminal'
$IsAzureAutomation = $false
}
# Initialize required modules
$RequiredModules = @(
'Microsoft.Graph.Authentication'
)
# MgGraphCommunity gives WAM-free interactive sign-in for local runs
if (-not $IsAzureAutomation) {
$RequiredModules += "MgGraphCommunity"
}
try {
Initialize-RequiredModule -ModuleNames $RequiredModules -IsAutomationEnvironment $IsAzureAutomation -ForceInstall $ForceModuleInstall
Write-Verbose '✓ All required modules are available'
}
catch {
Write-Error "Module initialization failed: $_"
exit 1
}
# ============================================================================
# AUTHENTICATION
# ============================================================================
try {
if ($IsAzureAutomation) {
# Azure Automation - Use Managed Identity
Write-Output 'Connecting to Microsoft Graph using Managed Identity...'
Connect-MgGraph -Identity -NoWelcome -ErrorAction Stop
Write-Output '✓ Successfully connected to Microsoft Graph using Managed Identity'
}
else {
# Local execution - WAM-free interactive sign-in via MgGraphCommunity
Write-Output 'Connecting to Microsoft Graph with interactive authentication...'
$scopes = @('DeviceManagementManagedDevices.PrivilegedOperations.All', 'DeviceManagementManagedDevices.Read.All')
if ($TargetMode -eq 'EntraGroup') {
$scopes += 'GroupMember.Read.All'
}
Connect-MgGraphCommunity -Scopes $scopes -NoWelcome -ErrorAction Stop
Write-Output '✓ Successfully connected to Microsoft Graph'
}
}
catch {
Write-Error "Failed to connect to Microsoft Graph: $($_.Exception.Message)"
exit 1
}
# Function to get all pages of results
function Get-MgGraphAllPage {
param(
[string]$Uri,
[int]$DelayMs = 100
)
[System.Collections.Generic.List[PSCustomObject]]$allResults = @()
$nextLink = $Uri
$requestCount = 0
do {
try {
# Add delay to respect rate limits
if ($requestCount -gt 0) {
Start-Sleep -Milliseconds $DelayMs
}
$response = Invoke-MgGraphRequest -Uri $nextLink -Method GET
$requestCount++
if ($null -ne $response.value) {
$response.value | ForEach-Object {
$allResults.Add($_)
}
}
else {
$allResults.Add($response)
}
$nextLink = $response.'@odata.nextLink'
}
catch {
if ($_.Exception.Message -like '*429*' -or $_.Exception.Message -like '*throttled*') {
Write-Information "`nRate limit hit, waiting 60 seconds..." -InformationAction Continue
Start-Sleep -Seconds 60
continue
}
throw "Error fetching data from $nextLink : $($_.Exception.Message)"
}
} while ($nextLink)
return $allResults
}
# Function to trigger device sync
function Invoke-DeviceSync {
param(
[string]$DeviceId,
[string]$DeviceName
)
try {
$syncUri = "https://graph.microsoft.com/beta/deviceManagement/managedDevices('$DeviceId')/syncDevice"
Invoke-MgGraphRequest -Uri $syncUri -Method POST
Write-Information "✓ Sync triggered successfully for device: $DeviceName" -InformationAction Continue
return $true
}
catch {
if ($_.Exception.Message -like '*429*' -or $_.Exception.Message -like '*throttled*') {
Write-Information "Rate limit hit for device $DeviceName, waiting 60 seconds before retry..." -InformationAction Continue
Start-Sleep -Seconds 60
try {
Invoke-MgGraphRequest -Uri $syncUri -Method POST
Write-Information "✓ Sync triggered successfully for device: $DeviceName" -InformationAction Continue
return $true
}
catch {
Write-Information "✗ Failed to sync device $DeviceName after retry: $($_.Exception.Message)" -InformationAction Continue
return $false
}
}
Write-Information "✗ Failed to sync device $DeviceName : $($_.Exception.Message)" -InformationAction Continue
return $false
}
}
# Function to get devices by Entra ID group
function Get-DevicesByEntraGroup {
param([string]$GroupName)
try {
Write-Information "Finding Entra ID group: $GroupName..." -InformationAction Continue
# Find the group
$groupUri = "https://graph.microsoft.com/beta/groups?`$filter=displayName eq '$GroupName'"
$groups = @(Get-MgGraphAllPage -Uri $groupUri)
if ($groups.Count -eq 0) {
throw "Group '$GroupName' not found"
}
elseif ($groups.Count -gt 1) {
throw "Multiple groups found with name '$GroupName'. Please use a more specific name."
}
$group = $groups[0]
Write-Information "✓ Found group: $($group.displayName) (ID: $($group.id))" -InformationAction Continue
# Get group members
Write-Information 'Retrieving group members...' -InformationAction Continue
$membersUri = "https://graph.microsoft.com/beta/groups/$($group.id)/members"
$members = @(Get-MgGraphAllPage -Uri $membersUri)
Write-Information "✓ Found $($members.Count) members in group" -InformationAction Continue
# Get all managed devices
Write-Information 'Retrieving managed devices...' -InformationAction Continue
$devicesUri = "https://graph.microsoft.com/beta/deviceManagement/managedDevices?`$select=id,deviceName,azureADDeviceId,userPrincipalName,operatingSystem,osVersion,model,lastSyncDateTime"
$allDevices = @(Get-MgGraphAllPage -Uri $devicesUri)
# Filter devices by group members (device membership first, then user membership fallback)
[System.Collections.Generic.List[PSCustomObject]]$targetDevices = @()
foreach ($device in $allDevices) {
$deviceInGroup = $false
if ($device.azureADDeviceId -and $members.deviceId -contains $device.azureADDeviceId) {
$deviceInGroup = $true
}
elseif ($device.userPrincipalName) {
$userInGroup = $members | Where-Object { $_.userPrincipalName -eq $device.userPrincipalName -or $_.mail -eq $device.userPrincipalName }
if ($userInGroup) {
$deviceInGroup = $true
}
}
if ($deviceInGroup) {
$targetDevices.Add($device)
}
}
Write-Information "✓ Found $($targetDevices.Count) devices belonging to group members" -InformationAction Continue
return $targetDevices
}
catch {
throw "Failed to get devices by Entra ID group: $($_.Exception.Message)"
}
}
# ============================================================================
# MAIN SCRIPT LOGIC
# ============================================================================
try {
# Get target devices based on parameter set
$targetDevices = @()
switch ($TargetMode) {
'DeviceNames' {
Write-Output 'Retrieving devices by names...'
$devicesUri = "https://graph.microsoft.com/beta/deviceManagement/managedDevices?`$select=id,deviceName,azureADDeviceId,userPrincipalName,operatingSystem,osVersion,model,lastSyncDateTime"
$allDevices = Get-MgGraphAllPage -Uri $devicesUri
foreach ($deviceName in $DeviceNames) {
$matchingDevices = $allDevices | Where-Object { $_.deviceName -eq $deviceName }
if ($matchingDevices) {
$targetDevices += $matchingDevices
Write-Output "✓ Found device: $deviceName"
}
else {
Write-Warning "Device not found: $deviceName"
}
}
}
'DeviceIds' {
Write-Output 'Retrieving devices by IDs...'
foreach ($deviceId in $DeviceIds) {
try {
$deviceUri = "https://graph.microsoft.com/beta/deviceManagement/managedDevices/$deviceId`?`$select=id,deviceName,azureADDeviceId,userPrincipalName,operatingSystem,osVersion,model,lastSyncDateTime"
$device = Invoke-MgGraphRequest -Uri $deviceUri -Method GET
$targetDevices += $device
Write-Output "✓ Found device: $($device.deviceName)"
}
catch {
Write-Warning "Device not found with ID: $deviceId"
}
}
}
'EntraGroup' {
$targetDevices = Get-DevicesByEntraGroup -GroupName $EntraGroupName
}
}
if ($targetDevices.Count -eq 0) {
Write-Output 'No target devices found. No synchronization action is required.'
exit 0
}
# Display target information
Write-Output "`n📱 TARGET DEVICES SUMMARY"
Write-Output '========================='
Write-Output "Total devices to process: $($targetDevices.Count)"
if ($DryRun) {
foreach ($device in $targetDevices) {
Write-Output "• $($device.deviceName) [$($device.id)]"
}
Write-Output "✓ Dry run completed. No synchronization actions were sent."
exit 0
}
# Process sync operations
$successfulSyncs = 0
$failedSyncs = 0
$skippedSyncs = 0
$processedDevices = 0
Write-Output "`nProcessing device synchronization..."
foreach ($device in $targetDevices) {
$processedDevices++
Write-Progress -Activity 'Synchronizing Devices' -Status "Processing device $processedDevices of $($targetDevices.Count): $($device.deviceName)" -PercentComplete (($processedDevices / $targetDevices.Count) * 100)
# Calculate time since last sync
$hoursSinceSync = if ($device.lastSyncDateTime) {
[math]::Round(((Get-Date) - [DateTime]$device.lastSyncDateTime).TotalHours, 1)
}
else {
999
}
# Determine if sync should be triggered
$shouldSync = $ForceSync -or $hoursSinceSync -gt 1 -or $null -eq $device.lastSyncDateTime
if ($shouldSync) {
$syncSuccessful = Invoke-DeviceSync -DeviceId $device.id -DeviceName $device.deviceName
if ($syncSuccessful) {
$successfulSyncs++
}
else {
$failedSyncs++
}
# Add delay between sync operations to avoid overwhelming the service
if ($processedDevices -lt $targetDevices.Count) {
Start-Sleep -Seconds $SyncDelaySeconds
}
}
else {
Write-Output "⏭️ Skipping $($device.deviceName) - synced $hoursSinceSync hours ago"
$skippedSyncs++
}
}
Write-Progress -Activity 'Synchronizing Devices' -Completed
# Display final summary
Write-Output "`n🔄 SYNC OPERATION SUMMARY"
Write-Output '========================='
Write-Output "Total Devices Processed: $($targetDevices.Count)"
Write-Output "Successful Syncs: $successfulSyncs"
Write-Output "Failed Syncs: $failedSyncs"
Write-Output "Skipped Devices: $skippedSyncs"
# Show failed devices if any
if ($failedSyncs -gt 0) {
Write-Output "`n❌ Failed sync operations require manual review."
exit 1
}
Write-Output "`n🎉 Device synchronization completed successfully!"
}
catch {
Write-Error "Script execution failed: $($_.Exception.Message)"
exit 1
}
finally {
# Disconnect from Microsoft Graph
try {
if (Get-MgContext) {
$null = Disconnect-MgGraph -ErrorAction SilentlyContinue
Write-Output '✓ Disconnected from Microsoft Graph'
}
}
catch {
# Ignore disconnection errors - this is expected behavior when already disconnected
Write-Verbose 'Graph disconnection completed (may have already been disconnected)'
}
}
// NOTES
Author notes
- Supports both local execution and Azure Automation Runbook environments - Automatically detects execution environment and uses appropriate authentication method - Local execution: Uses interactive authentication with specified scopes - Azure Automation: Uses Managed Identity authentication - Requires Microsoft.Graph.Authentication module (auto-installs if missing in local environment) - Use -ForceModuleInstall to skip installation prompts in local environment - Requires appropriate permissions in Azure AD - Sync operations are triggered immediately but may take time to complete on the device - Use -ForceSync to override the 1-hour sync threshold - The script will show real-time progress and results - Local interactive sign-in uses the MgGraphCommunity module to avoid the Graph SDK's mandatory WAM broker on Windows
// RELATED
Scripts that travel together.
Picked by shared tags, category, and script type — nothing magic, just metadata overlap.
Add Devices to Entra ID Groups from CSV
This script reads a CSV file containing device identifiers and group names, then adds the specified devices to their corresponding Entra ID groups. It supports multiple device identifiers (Device Name, Serial Number, Azure AD Device ID) for flexible device matching and can add devices to multiple groups. The script validates that devices exist in Intune before processing, checks for existing group memberships to avoid duplicates, and can create new groups with user confirmation. A dry-run mode allows previewing changes before execution.
OperationalDevicesCleanup Orphaned Autopilot Devices
This script connects to Microsoft Graph and identifies Windows Autopilot devices that are registered in the Autopilot service but are no longer present as managed devices in Intune. These orphaned devices can accumulate over time when devices are retired, reimaged, or replaced without proper cleanup of the Autopilot registration. The script provides options to preview orphaned devices before removal and supports batch operations with confirmation prompts for safety. It helps maintain a clean Autopilot device inventory and prevents potential enrollment issues.
OperationalDevicesCleanup Duplicate Intune Device Records
This script groups all Intune managed devices by serial number and identifies duplicates - typically left behind by re-enrollment, OS reinstalls, or Autopilot resets. For every duplicate set it keeps the record with the most recent sync and marks the older records for cleanup. By default the script only reports; deletion requires the -Remove switch and is preview-safe via -WhatIf. Removing a device record from Intune does not wipe the device; it only deletes the stale management object. Scope is limited to Intune managed-device records returned by /deviceManagement/managedDevices. The script does not inspect or delete Microsoft Entra device objects or Windows Autopilot registrations. Duplicate-looking Entra objects can be expected with Hybrid Autopilot deployments and must not be treated as stale Intune records.
DevicesOperational