Protection against phishing, malware, and other threats targeting email and collaboration tools in Microsoft 365
In Microsoft Defender for Endpoint, a device that was decommissioned without being offboarded will:
- Stop sending signals once it is powered off/removed.
- Be marked Inactive after it has sent no signals for more than seven days.
- Remain visible in the device inventory, with past alerts and timeline data, for up to the configured data retention period (typically up to 180 days). It is not immediately or automatically deleted when it becomes inactive.
- Not be counted in the organization’s exposure score if it hasn’t been active in the last 30 days.
So it will remain as an inactive (stale) entry for the retention period, but it won’t affect exposure scoring after 30 days.
To remove an inactive, decommissioned device from active views:
- Use filters in the Microsoft Defender portal (for example, filter by sensor health state = Inactive, or by device tags or device groups) to hide or exclude inactive devices from day‑to‑day views and reports.
- If the device was offboarded (or effectively stopped reporting), no further action is required for data flow; its historical data will automatically age out and be removed from the portal once the retention period (up to 180 days) expires.
There is no separate manual “delete now” operation for Defender for Endpoint device records described in the provided material; cleanup is handled by the service based on inactivity and retention.
References: