Free tools Windows power users keep installed
One-click scans. No signup required.
Microsoft Intune lets administrators send one supported remote command to multiple enrolled devices from Devices → All devices → Bulk device actions. Choose the operating system and action, select eligible devices, review the consequences, and choose Create. The request is then delivered when devices check in; submission does not mean every device has finished.
Most general Intune bulk-action workflows document a limit of up to 100 devices per operation. Intune for Education supports up to 2,000 devices, while Windows 365 Cloud PC bulk operations can support up to 5,000 Cloud PCs. Limits vary by experience, platform, and action.
What Intune bulk device actions do
A bulk action sends the same supported remote command to a specifically selected set of managed devices. It is different from bulk enrollment, group-based policy assignment, application deployment, app selective wipe, Microsoft Graph automation, and device cleanup rules. Unless an action-specific workflow offers group selection, the command applies only to devices you select in the portal.
Devices generally must be enrolled and able to communicate with Intune. An offline device cannot receive the command until it checks in, and an unhealthy enrollment may prevent processing altogether. Microsoft’s action guidance is available at Microsoft Intune device actions documentation.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →#1 Best Overall
- Dual band router upgrades to 1200 Mbps high speed internet (300mbps for 2.4GHz plus 900Mbps for 5GHz), reducing buffering and ideal for 4K stream
- Full Gigabit Ports - Gigabit Router with 4 Gigabit LAN ports, ideal for any internet plan and allow you to directly connect your wired devices
- Boosted Coverage - Four external antennas equipped with Beamforming technology extend and concentrate the Wi-Fi signals
- MU-MIMO technology - (5GHz band) allows high speeds for multiple devices simultaneously
- Access Point Mode - Supports AP Mode to transform your wired connection into wireless network, an ideal wireless router for home
Before you start
- Confirm that the devices are enrolled in Intune and belong to the intended tenant.
- Verify that your Intune role includes the relevant device-management or remote-task permission. Requirements differ by action.
- Check platform, enrollment-type, licensing, and configuration prerequisites.
- Confirm the target devices can connect to Intune and note their last check-in times.
- Use a small pilot before issuing Restart, Retire, Wipe, Delete, or Autopilot Reset.
- For disruptive actions, announce a maintenance window and protect devices used for clinical, manufacturing, presentation, or point-of-sale work.
How to run a bulk action
1. Open the bulk-action wizard
- Sign in to the Microsoft Intune admin center.
- Select Devices.
- Select All devices.
- Select Bulk device actions.
2. Choose the platform and command
On Basics, select the target operating system and the action. The list is contextual: available commands depend on the platform, enrollment type, device state, tenant configuration, licensing, and permissions. Complete any action-specific options, then select Next.
3. Select and validate devices
- Select + Select devices to include.
- Search with the identifiers offered by the portal, such as device name, serial number, IMEI, user principal name, or email address.
- Apply filters where available.
- Select only devices eligible for the chosen command.
- Check the selected count against the action limit and verify names, owners, operating systems, and last check-in times.
- Select Next.
4. Review and create
On Review + create, verify the operating system, action, options, and complete device list. Read the destructive-action warning when it appears. Select Create only after a second administrator or approved change record confirms the scope for high-impact operations.
5. Monitor delivery and completion
Go to Devices → Monitor → Device actions. Filter or export the report for change records. Typical states are Completed, Pending, Failed, and Unknown. A success message after selecting Create confirms submission, not device-side completion. For attribution, use Intune audit logs: the status report shows what happened to targets, while audit logs help identify the administrator or process that initiated the change. User-initiated Company Portal actions may be recorded differently.
Rank #2
- 【Five Gigabit Ports】1 Gigabit WAN Port plus 2 Gigabit WAN/LAN Ports plus 2 Gigabit LAN Port. Up to 3 WAN ports optimize bandwidth usage through one device.
- 【One USB WAN Port】Mobile broadband via 4G/3G modem is supported for WAN backup by connecting to the USB port. For complete list of compatible 4G/3G modems, please visit TP-Link website.
- 【Abundant Security Features】Advanced firewall policies, DoS defense, IP/MAC/URL filtering, speed test and more security functions protect your network and data.
- 【Highly Secure VPN】Supports up to 20× LAN-to-LAN IPsec, 16× OpenVPN, 16× L2TP, and 16× PPTP VPN connections.
- Security - SPI Firewall, VPN Pass through, FTP/H.323/PPTP/SIP/IPsec ALG, DoS Defence, Ping of Death and Local Management. Standards and Protocols IEEE 802.3, 802.3u, 802.3ab, IEEE 802.3x, IEEE 802.1q
Actions, uses, and cautions
| Action | Use | Important qualification |
|---|---|---|
| Sync | Request an Intune check-in so pending policy, app, or command work can be received. | It cannot make an offline device check in or repair a broken enrollment. |
| Restart | Restart devices after updates or troubleshooting. | Warn about unsaved work; support varies by platform and Windows version. |
| Rename | Apply a naming operation to selected devices. | Templates must produce unique, valid names; some devices need a restart before the local name is reflected. |
| Retire | Remove organizational management, profiles, apps, and data where supported while normally preserving personal data. | The device must receive the command; an offline device remains managed until it checks in. |
| Wipe | Reset or erase a device. | Behavior depends on platform and options such as retaining enrollment state or the user account. |
| Delete | Remove the device record from Intune. | It is not a substitute for Retire or Wipe and does not by itself guarantee corporate-data removal. |
| Autopilot Reset | Return supported Windows devices to a business-ready state for reassignment. | Designed to preserve the device’s management identity and enrollment connection in supported scenarios. |
| Collect diagnostics | Gather troubleshooting logs. | Device, platform, and action-specific limits apply; older guidance cited 25 Windows devices, so verify the current portal limit. |
| Custom notifications | Send a message through supported Intune applications. | Requires the supported app and platform conditions shown by Intune. |
Microsoft’s inventory changes. Current action availability is organized by platform, including Windows, Apple mobile, macOS, Android, and ChromeOS, so trust the commands presented after you choose the operating system rather than a static historical list.
Retire, Wipe, Delete, and Autopilot Reset compared
| Need | Use | Do not confuse it with |
|---|---|---|
| Remove corporate management while preserving personal data | Retire | Delete |
| Erase or reset a lost, transferred, or reassigned device | Wipe | Delete |
| Remove only an Intune inventory record | Delete | Data erasure |
| Quickly prepare a supported Windows Autopilot device for another user | Autopilot Reset | A conventional factory wipe |
| Remove corporate data from managed applications only | App selective wipe | Device Wipe |
For iOS and Android in particular, do not assume that deleting the Intune record retires or wipes company data. When data removal is required, use Retire or Wipe first as appropriate, then delete the record. See the documented change in delete behavior.
Action-specific operating guidance
Sync
Sync is a check-in request, not a policy repair. It may remain pending when a device is powered off, disconnected, unenrolled, duplicated, or unable to process MDM commands. A policy can also be correctly assigned but not applicable to that device.
Rank #3
- Dual-band Wi-Fi with 5 GHz speeds up to 867 Mbps and 2.4 GHz speeds up to 300 Mbps, delivering 1200 Mbps of total bandwidth¹. Dual-band routers do not support 6 GHz. Performance varies by conditions, distance to devices, and obstacles such as walls.
- Covers up to 1,000 sq. ft. with four external antennas for stable wireless connections and optimal coverage.
- Supports IGMP Proxy/Snooping, Bridge and Tag VLAN to optimize IPTV streaming
- Access Point Mode - Supports AP Mode to transform your wired connection into wireless network, an ideal wireless router for home
- Advanced Security with WPA3 - The latest Wi-Fi security protocol, WPA3, brings new capabilities to improve cybersecurity in personal networks
Restart
Schedule restarts, notify users, and pilot the command. Intune cannot protect unsaved work, and support depends on the selected platform.
Rename
Design a template around unique names, device reuse, Autopilot conventions, directory naming rules, maximum length, allowed characters, and whether a restart is required.
Retire
Retire is appropriate when organizational control and data should be removed without treating the device as a full factory-reset case. Delivery is deferred until the device checks in.
Rank #4
- DUAL-BAND WIFI 6 ROUTER: Wi-Fi 6(802.11ax) technology achieves faster speeds, greater capacity and reduced network congestion compared to the previous gen. All WiFi routers require a separate modem. Dual-Band WiFi routers do not support the 6 GHz band.
- AX1800: Enjoy smoother and more stable streaming, gaming, downloading with 1.8 Gbps total bandwidth (up to 1200 Mbps on 5 GHz and up to 574 Mbps on 2.4 GHz). Performance varies by conditions, distance to devices, and obstacles such as walls.
- CONNECT MORE DEVICES: Wi-Fi 6 technology communicates more data to more devices simultaneously using revolutionary OFDMA technology
- EXTENSIVE COVERAGE: Achieve the strong, reliable WiFi coverage with Archer AX1800 as it focuses signal strength to your devices far away using Beamforming technology, 4 high-gain antennas and an advanced front-end module (FEM) chipset
- OUR CYBERSECURITY COMMITMENT: TP-Link is a signatory of the U.S. Cybersecurity and Infrastructure Security Agency’s (CISA) Secure-by-Design pledge. This device is designed, built, and maintained, with advanced security as a core requirement.
Wipe
Read every option before creating the action. Retaining enrollment state or a user account can materially change the result, and platform behavior differs.
Autopilot Reset
Use it for supported Windows reassignment scenarios where personal files, apps, and settings should be removed while the original management identity and Intune connection remain.
Windows 365 Cloud PCs
Cloud PC workflows add actions such as restore, reprovision, resize, restart, power operations, and diagnostics. Microsoft documents up to 5,000 Cloud PCs for supported bulk Cloud PC operations, and selection requirements can differ from ordinary device actions. Details are in Microsoft’s Windows 365 remote-management documentation.
Best Value
- Next-Gen Gigabit Wi-Fi 6 Speeds: 2402 Mbps on 5 GHz and 574 Mbps on 2.4 GHz bands ensure smoother streaming and faster downloads; support VPN server and VPN client¹
- A More Responsive Experience: Enjoy smooth gaming, video streaming, and live feeds simultaneously. OFDMA makes your Wi-Fi stronger by allowing multiple clients to share one band at the same time, cutting latency and jitter.²
- Expanded Wi-Fi Coverage: 4 high-gain external antennas and Beamforming technology combine to extend strong, reliable, Wi-Fi throughout your home.
- Improved Battery Life: Target Wake Time helps your devices to communicate efficiently while consuming less power.
- Improved Cooling Design: No heat ups, no throttles. A larger heat sink and redefined case design cools the WiFi 6 system and enables your network to stay at top speeds in more versatile environments.
Troubleshooting pending and failed actions
Pending or unknown
- Check power, internet access, and last check-in.
- Confirm that enrollment is healthy and the device is not blocked, retired, or already deleted.
- Wait for the next successful check-in instead of repeatedly submitting a destructive command.
Failed
- Recheck platform and enrollment-type support.
- Review action-specific permissions, licensing, and configuration.
- For resets, verify storage, power, and competing management controls.
- Inspect Intune and device-side logs, then retry on one test device.
Wrong devices selected
- For Sync or Restart, notify users and assess operational impact.
- For Rename, correct the naming operation only after validating the intended list.
- For Retire, Wipe, or Delete, invoke your incident-response process; deleting a record does not reverse a command already delivered.
When another method is better
Groups and policy assignment
Use dynamic or assigned groups for applications, configuration profiles, compliance policies, and security baselines. Bulk actions are imperative commands, not a replacement for declarative policy assignment.
Cleanup rules
Cleanup rules remove stale records. They do not deliberately retire or wipe a device.
Graph or PowerShell automation
Use Microsoft Graph or PowerShell when you need repeatable, conditional, or larger-scale operations. Build device-ID validation, an allowlist, a dry-run report, rate-limit handling, retries, error logging, separate approval for Wipe/Retire/Delete, status polling, and audit-log correlation. Portal limits and API limits are not necessarily identical, and automation is not risk-free.
Operational checklist
- Define the intended outcome: Sync, Restart, Retire, Wipe, Delete, Reset, or diagnostics.
- Confirm platform support, permissions, licensing, connectivity, and action limits.
- Export or record the target list and pilot the command.
- Notify users and schedule disruptive work.
- Create the action after reviewing every option.
- Monitor Completed, Pending, Failed, and Unknown results.
- Export evidence and investigate exceptions before closing the change.
For a broader remote-support capability, Microsoft documents Remote Help and TeamViewer as separate integrations with their own setup and licensing requirements: Intune remote assistance documentation.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitchesQuick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




