How to use PowerShell to export inactive Azure device inventory for cleanup. Cleaning up Entra ID device objects? A good place to start is by exporting a defensible list of device name, trust type, last sign-in time, and IDs you can track through approval and remediation. In this video, we'll go over a clean PowerShell workflow to export inactive Azure AD/Entra ID devices to CSV, optionally tag devices for local cleanup, and remove devices via Microsoft Graph. Before we begin, be sure to subscribe to NinjaOne's IT Video Hub and our YouTube channel for more tech content like this. Export inactive Azure device inventory with PowerShell. For the core CSV export workflow, you need Azure AD or Entra ID admin permissions, Microsoft Graph API access with these delegated permissions, device.read.all and directory.read.all, PowerShell 7+ Microsoft.Graph module installed. Step 1, connect to Microsoft Graph and retrieve devices. First, authenticate to Graph with the required scopes. Then, pull the device inventory using... That count ensures that you actually retrieved inventory and didn't hit a permissions issue. Step 2, filter stale or inactive Azure devices. Next, define your inactivity cutoff. 90 days is a common baseline for stale, but adjust to your policy. If you want a tighter list for cleanup, exclude hybrid objects and focus on corporate-owned devices. At this point, it's worth doing a quick spot check using... Step 3, export the CSV report. Create your output folder, then export the fields you'll actually need for review and cleanup workflows. That CSV is your control document for approvals, change records, and scripted cleanup runs. Cleanup methods. If you have access to endpoints via RMM or remote scripting, tagging is a good safety step. It lets your tooling confirm a device was reviewed before any cleanup action. Option 1, tag devices for local cleanup . With PowerShell still open, use this to tag devices for local cleanup on Windows Registry. Then, verify the process using command prompt. Option 2, remove stale devices in Entra ID. This method performs an immediate and permanent delete. There is no recycle bin. Use it only after approval. Use this method only after approval. You can also bulk delete through the Azure portal by going to Entra ID, Devices, Bulk actions, Delete. That's the workflow. Connect to Graph, pull inventory, filter by last sign-in, export a clean CSV report, and optionally tag devices before any destructive step. For more information, check out our official blog post on how to use PowerShell to export inactive Azure directory device inventory, linked in the description below.

How to Use PowerShell to Export Inactive Azure Device Inventory for Cleanup

Stale Azure AD devices quietly increase risk and clutter your tenant. In this video, we show how to use PowerShell to export inactive Azure device inventory and explain how to export the CSV of stale Azure AD device inventory for cleanup. You’ll learn how to identify inactivity thresholds, generate a clean CSV report, and use that data to support safe device removal and long-term tenant hygiene.

Read the full blog on How to Use PowerShell to Export Inactive Azure Device Inventory for Cleanup

Never miss a NinjaOne video!