Close Menu
    Facebook X (Twitter) Instagram
    Sunday, July 20
    X (Twitter) LinkedIn
    All about Endpoint Management
    • Home
    All about Endpoint Management
    Home»Intune»Automatically Delete Stale User Profiles with Intune Configuration Profiles

    Automatically Delete Stale User Profiles with Intune Configuration Profiles

    Eswar KonetiBy Eswar KonetiAugust 07, 12:35 am3 Mins Read Intune 1,431 Views
    Share
    Facebook Twitter LinkedIn Reddit

    Managing user profiles on shared or newly built Windows devices can be challenging, especially when dealing with stale profiles that haven’t been active for a while. This need arises in various scenarios:

        1. Shared Devices: Multiple users use the same device, and old profiles clutter the system.

        1. Desktop Support Validation: Support teams log in to verify device configurations before handing them over.

        1. Security Concerns: Outdated profiles can pose security risks.

        1. Vulnerability Scanning: Applications that require user profiles may still be flagged as vulnerable if users haven’t logged in to update them. Examples such as teams, zoom, and other user based applications.

      For customers using Microsoft Intune, there’s a streamlined way to handle this issue. For customers using Microsoft Intune, there’s a streamlined way to handle this issue. If  you are not using Intune to manage your endpoints yet (if co-managed, make sure the device configuration workload is moved to Intune), you can still leverage GPO to do the same.

      Here’s a step-by-step guide to leveraging Intune for automatically deleting stale user profiles:

      Choosing the Right Method

      Intune offers several methods to manage user profiles, including:

          • Remediation Scripts

          • Scheduled Tasks

          • Configuration Profiles

        Among these, Configuration Profiles (using the Settings Catalogue) is the most straightforward and effective approach.

        Finding the Right Setting in Intune

        Intune features two main options for configuring settings: Administrative Templates and the Settings Catalogue. Given recent changes, Microsoft is migrating settings from Administrative Templates to the Settings Catalogue, making it easier to locate and configure them.

        To find relevant settings, you can refer to the list of device configuration settings available on GitHub. Mike from Microsoft provides a well-organized spreadsheet that is a valuable resource:

        Device Configuration Settings by Mike on GitHub

        Download the latest spreadsheet and look in column (D) for the “Delete user profile” setting. This search will help you find the exact match for your needs.

        Creating a Configuration Profile

        Once you’ve identified the setting, follow these steps to create a new configuration profile in Intune:

            1. Create a New Configuration Profile:

                Go to the Intune, device configurations, create a new policy, with profile type “Settings Catalogue”

                • Search for “Delete user profiles older than”.

              2. Configure the Setting:

              • Set the option to Enabled.

                  • Specify the number of days after which profiles should be considered stale. For instance, to delete profiles older than 40 days, enter 40.

                3. Assign the Profile:

                • Click Next to proceed .Assign the profile to your desired device group. Consider running a pilot test before rolling it out to the entire production environment.

                    • Click Create to finalize the profile.

                  End-results:

                  On devices where policy applied successfully.

                  Before (5 user profiles excluding default, public user profile):

                  After reboot (3 user profiles):

                  2 user profiles named administrator and Test1 successfully removed and this can be verified from the event viewer as well.

                  Additional Resources

                  For more detailed information about cleanup profile settings and related documentation, refer to the ADMX_UserProfiles Policy CSP on Microsoft Learn.

                  Share. Twitter LinkedIn Email Facebook Reddit

                  Related Posts

                  Automating Intune Deployment Rings Using Entra ID Dynamic Groups and Regex

                  July 01, 10:31 pm

                  Exporting Intune Win32 Apps with All Properties Using PowerShell and Microsoft Graph

                  June 30, 7:01 pm

                  Optimize Your Intune Workflow with a Powerful Browser Extension

                  March 22, 10:39 am

                  5 Comments

                  1. Saheed on February 19, 2025 5:20 PM

                    Please help on How to remove this delete user profiles CSP policy on all devices deploy because people goes on FMLA and might login for almost a year. Help with a script to detect and remediate script

                    Reply
                    • Eswar Koneti on March 2, 2025 9:49 PM

                      If the ask is to exclude certain users or devices from the policy, you can simply add the group to exclusion so that the policy will not apply.

                      thanks,
                      Eswar

                      Reply
                  2. Saheed Adeyanju on January 12, 2025 6:35 AM

                    Thank you for this article, and Please make an article on the company portal flow and applications that failed to install

                    Reply
                    • Eswar Koneti on January 31, 2025 10:19 PM

                      Microsoft has documented the workflow of win32 apps and troubleshooting method, does this help? https://learn.microsoft.com/en-us/troubleshoot/mem/intune/app-management/develop-deliver-working-win32-app-via-intune

                      Thanks,
                      Eswar

                      Reply
                  3. Steven on September 21, 2024 10:08 AM

                    Thanks for the article, it is very useful and cleanup the old profiles to make the systems clean.

                    Reply

                  Leave a ReplyCancel reply

                  This site uses Akismet to reduce spam. Learn how your comment data is processed.

                  Sign Up

                  Get email notifications for new posts.

                  Author

                  I’m Eswar Koneti ,a tech enthusiast, security advocate, and your guide to Microsoft Intune and Modern Device Management. My goal? To turn complex tech into actionable insights for a streamlined management experience. Let’s navigate this journey together!

                  Support

                  Awards

                  Archives

                  © Copyright 2009-2024 Eswar Koneti, All rights reserved.

                  Type above and press Enter to search. Press Esc to cancel.

                   

                  Loading Comments...