Enterprise

Find and decommission devices that haven't checked in for X days.

Identify ghost devices: not seen by Intune, not reporting to SCCM, no recent Entra sign-in. Configurable thresholds. One-click decommissioning workflow.

Included in the Enterprise tier · 14-day trial, no card

Obsolete Device Management

The problem

A workstation that hasn't checked in for 30 days might be on vacation. At 60 days, it might be a forgotten travel laptop. At 90 days, it's probably decommissioned but never cleaned up. At 180 days, it's a security risk and a license drain.

  • Manual cross-correlationidentifying obsolete devices in the SCCM or Intune console requires custom reports, manual filtering and cross-referencing.
  • Skipped routinebecause it is painful, most teams never run it — and the audit surprises them.
  • Compliance driftphantom devices keep counting in compliance percentages and exaggerate license consumption.

The TontonTools way

Obsolete Device Management aggregates last-seen data from all three systems and lets you act per device or in bulk.

  • Multi-system last-seenIntune last check-in, SCCM heartbeat, Entra ID sign-in — all in one row.
  • Configurable thresholds30, 60, 90, 180, 365 days — or any custom value.
  • Owner mail resolutionreach the manager before any action — a flagged device may be a sabbatical, not a ghost.
  • Handoff to Delete Device Everywheresend selected devices to a worklist for DDE to execute the atomic 4-system delete with rollback snapshot.

Key features

Built for high-stakes operations where forgetting a system is not an option.

  • Configurable thresholds

    30, 60, 90, 180, 365 days — or any custom day count. Pick the review threshold and the action threshold separately.

  • Multi-system last-seen

    Intune last check-in + SCCM heartbeat + Entra last sign-in, all aggregated per device. No more reconciling three exports by hand.

  • Owner mail resolution

    Reach the manager before acting — a 90-day-silent device may be a sabbatical, not a ghost. The tool gives you the answer in the same grid.

  • Sortable, filterable grid

    Sort by days-obsolete, filter by OS or department, group by owner — find the cohort that matches your policy.

  • Deferred decommissioning

    Tag devices for action without committing. Build a worklist that Delete Device Everywhere picks up directly.

  • CMTrace audit log

    Every tag, every handoff, every threshold sweep logged in CMTrace format for compliance review.

See it in action

Real screens. No marketing renders.

  • Scan stale devices across both Entra ID and Intune — one grid, every attribute in view.
  • Define stale your way: inactive from 60 days to 10 years, with the device count live.
  • Filter by compliance status, OS, owner or account to target exactly the right devices.
  • Double-click any device for full details: IDs, dates, manufacturer and model, all copyable.

Technical details

What runs where. What it writes to disk. What permissions it needs.

Authentication

SCCM — current user credentials (Kerberos)

Microsoft Graph — Client Secret or Certificate (JWT Client Assertion)

Systems

Microsoft Intune

Microsoft Entra ID

Microsoft Configuration Manager (SCCM / MECM)

Audit log

CMTrace-compatible — C:\TEMP\ObsoleteDeviceManagement.log

Handoff target

Worklist consumed by Delete Device Everywhere (Enterprise tier)

Who it's for

Enterprise IT Ops teams running regular hygiene routines. CISOs concerned about stale identity surfaces. Asset managers tracking license consumption. Architects designing decommissioning workflows.

Stop carrying ghost devices on your estate.

Try Obsolete Device Management — exclusive to the Enterprise tier.