Who this guide is for Tenant or system administrators responsible for device security.
Before you start Have a clear reason for the action and confirm the device owner, tenant, app type, and any active security incident details.
Steps 1. Open Device Management and use the owner, tenant, app, status, or device details to find the device. 2. Open device details and review registration date, platform, operating system, application version, other users, session history, and previous actions. 3. Force logout when the user must reauthenticate but the device itself can remain trusted. 4. Ban the device when it is lost, compromised, shared improperly, or otherwise disallowed. Record the reason. 5. Unban only after the device and user have been verified and the reason for the original ban is resolved.
Check your work The device status and history clearly show the action, reason, actor, and resulting session state.
When to stop and ask for help Stop if banning the device would interrupt a critical operational process without a safe replacement or user communication plan.