Cybersecurity & IT Operations · THE NO-PANIC PLAN
Reassign a company-managed device without leaving access behind
A device handover involves more than collecting a laptop and pressing reset. The organization must confirm ownership and management state, preserve work records that must remain available, remove the departing user's access separately, choose the correct platform action, and verify the device is ready for its next custodian. This workflow covers organization-owned devices managed through an approved endpoint program. Personally owned/BYOD devices, legal holds, regulated media, failed wipe status, and devices outside management need the organization’s privacy, legal, and security teams to direct the process. A management-console status is evidence of an action, not a substitute for an approved sanitization standard or any required assurance.
MISSION Safely transfer an organization-owned managed device by preserving required work records, removing the prior user's access, sanitizing it under the approved program, and verifying re-enrollment.
Review the device ownership, account revocation, and sanitization evidence before reassignmentTHE REAL-WORLD BIT
What happens outside this browser tab?
Open an authorized handover record and identify the device and ownership; check legal hold, retention, encryption, and backup needs; remove the former custodian's account access, sessions, and credentials separately; select the correct MDM and identity actions for the ownership and platform; sanitize the organization's media using its approved NIST-aligned program; re-enroll the device and apply a supported baseline; then verify access removal, device readiness, and custody records with a second reviewer where policy requires.
YOUR CHECKLIST, WITH FEWER DRAMATIC SIGHES
One step at a time.
Follow the order below. If a step names a Nirmion tool, its link is right there with it.
- 01
Open a handover record and confirm the device is organization-owned
Record the asset ID, serial number, assigned custodian, platform, management tenant, device ownership type, physical condition, and intended next use. Confirm the asset is organization-owned and actively managed before running a remote action; pause if ownership is personal, unclear, or disputed. Identify the authorized IT operator and approver, and document the requested transfer date and recipient. Use the Mobile Device Policy Builder to review which organizational policy applies to the asset class and handover, but treat its output as a planning aid rather than a device-management command. Keep serial numbers and user details in the approved asset system, not in a public ticket or sharing link.
- 02
Check holds, retained work records, encryption, and backup requirements
Before resetting the device, ask the data owner whether a legal hold, investigation, incident response, retention schedule, or business continuity need applies. Confirm that required organizational data has been transferred to an approved managed location and that the backup or retention copy is recoverable by the authorized successor. Review encryption and recovery-key handling under the organization's endpoint policy; do not export recovery keys into a handover note. If evidence must be preserved, stop the wipe and follow the evidence custodian's procedure. NIST SP 800-88 Rev. 2 recommends a program-based media sanitization process selected for information sensitivity and organizational controls, so do not improvise a sanitization method from a consumer reset guide.
- 03
Remove the former custodian's access independently of the device reset
Use the identity and application owners' approved offboarding process to disable or change the user's account as authorized, revoke active sessions and tokens, remove group or role assignments, and transfer ownership of business files and services. Review device certificates, VPN profiles, email access, password vaults, local administrator rights, recovery accounts, and any credentials stored on the endpoint. The Access Review Checklist can structure a human review of access items, but it does not revoke accounts or discover every system. Record the identity actions and owners separately from the device wipe ticket: a wipe request can be delayed, fail, or leave cloud accounts active, while account revocation alone does not sanitize local media.
- 04
Choose the device-management action for the ownership and platform
Check the device's management state and the vendor's current action documentation before submission. Microsoft Intune distinguishes Retire, which removes managed organization data and settings while preserving personal data in supported scenarios, from Wipe, which restores factory settings and removes device data and settings. For an organization-owned asset being reassigned, select the organization-approved full sanitization/reassignment path for that platform; do not use a personal-device retire operation as proof that all contents were erased. Confirm prerequisites, the correct device record, the expected user impact, and any second-admin approval before executing an irreversible action. If the console state or platform is ambiguous, ask the endpoint owner to resolve it first.
- 05
Run the approved sanitization process and wait for evidence of completion
Submit the authorized platform action and track its request ID, timestamp, initiating operator, device check-in, and final result. Follow the organization's current media sanitization policy, which should define approved methods, platform coverage, sensitivity levels, verification evidence, exceptions, and disposal paths in line with current NIST guidance or another adopted standard. Do not treat a successful button click or queued command as completed erasure; confirm the device checked in and the action reached its documented terminal status. If it is offline, errors, or cannot provide the required evidence, quarantine it and escalate for an approved hands-on method or secure disposition. Never resell, donate, or reassign a device whose required sanitization is unverified.
- 06
Re-enroll the clean device and apply the new custodian's baseline
After sanitization is confirmed, use the organization's approved provisioning flow to assign the device to the new custodian, enroll it into the correct tenant, and apply supported security and management baselines. Confirm current patches, disk encryption, endpoint protection, screen lock, required certificates, and role-appropriate applications before handing it over. Avoid restoring the former user's profile, credentials, tokens, browser session, or unmanaged backup. If an asset must be released from automated enrollment or a vendor-management tenant, have an authorized administrator follow the platform owner's current release process and record the resulting status. The incoming custodian should sign in using their own account and verify expected access without receiving another person's secrets.
- 07
Verify the transfer and close the custody record
Have an authorized reviewer compare the asset record, old-user access actions, sanitization result, new enrollment state, baseline status, and recipient acknowledgment. Confirm the former custodian can no longer access the device or its management records as intended, while required retained business data remains available only in approved repositories. Document exceptions, missing evidence, repair needs, accessories, new custodian, and date of transfer in the restricted asset system. Close the ticket only when the selected action and its evidence meet policy; otherwise keep the device quarantined and assign an owner and deadline for remediation. Dispose of temporary exports and recovery material under the organization's retention rules.
THE HELPER CREW
Tools for the fiddly bits.
These are the currently published Nirmion tools matched to this guide. Open a tool page for its accepted inputs and limits.
RECEIPTS, PLEASE
Sources & review notes
Each source is linked to the steps it supports. Open it to check its scope and current guidance.
Source checked 2026-10-10