An Employee’s Stolen Laptop: What Should Your Microsoft 365 Admin Do First?

A missing company laptop is more than a hardware problem. It may contain company files, cached email, browser sessions, Microsoft 365 access, and other business information.
The good news is that if the device is properly managed through Microsoft Intune and Microsoft Entra ID, administrators have several options to protect company data remotely.
But the order of actions matters.
Here is what a Microsoft 365 administrator should check and do when an employee reports that a company laptop has been lost or stolen.
1. Confirm Which Device Is Missing
Start by identifying the exact device.
Ask the employee for information such as:
Device name, if known
Make and model
Approximate time it disappeared
Whether the laptop was turned on or unlocked
Whether the employee believes anyone may know their password or PIN
Where the laptop was last used
Then locate the device in the Microsoft Intune admin center and Microsoft Entra ID.
This is important because you want to take action against the correct device without affecting another computer belonging to the employee.
Your First Response to a Stolen Laptop
For a Microsoft Entra registered or joined device, an administrator can disable the device in Microsoft Entra ID.
Microsoft states that disabling a device prevents it from authenticating through Microsoft Entra ID. It also revokes the device's Primary Refresh Token and refresh tokens and prevents the device from using Windows Hello for Business credentials.
This can be an important containment step because the goal is no longer simply to recover the computer. You also need to prevent that device from continuing to access company resources.
However, disabling the device is not the same thing as remotely deleting the data stored on it.
That is where Intune becomes important.
2. Decide Whether the Device Should Be Wiped
If the computer is company-owned and enrolled in Microsoft Intune, administrators can use the Wipe remote action.
Microsoft describes Wipe as a factory reset that removes organizational and personal data, applications, and settings from the device. Microsoft specifically lists lost or stolen devices as one of the scenarios where a wipe can be used.
For a company-owned computer that you do not expect to recover, this is usually the remote action administrators should evaluate.
In Intune, administrators can locate the device and initiate the appropriate remote action from the device management interface.
One important limitation is easy to overlook: the device generally needs to communicate with Microsoft's management services before a remote action can be completed. A laptop that is turned off or disconnected from the internet cannot immediately receive a new command.
That is why a remote wipe should not be your only layer of protection.
3. Do Not Delete the Device Too Early
There is an important difference between wiping a device and simply deleting its record from your management environment.
Microsoft recommends wiping or retiring an Intune-managed device before deleting the
device object when it is no longer going to be used.
Microsoft also specifically advises administrators managing Entra devices to wipe or retire devices managed by systems such as Intune before deleting them.
In other words, do not immediately start deleting device records simply because the computer is missing.
First determine what remote security actions you need to perform and confirm their status.
4. Consider the Employee's Microsoft 365 Sessions
The next question is whether the problem is limited to the physical laptop or whether the employee's account may also be at risk.
For example, the risk is higher if:
The computer was unlocked when it disappeared.
The employee believes someone saw or obtained their password.
Suspicious Microsoft 365 activity appears after the device disappeared.
There is reason to believe the user's credentials were stored insecurely.
Microsoft Entra allows administrators to revoke a user's sessions. Microsoft documents this capability as part of emergency access revocation when an account might be compromised.
If account compromise is suspected, password reset and session revocation may therefore be appropriate in addition to actions taken against the device.
Keep in mind that revoking the user's sessions affects the user, not only the missing computer, so the employee may need to authenticate again on their legitimate devices.
5. Review Microsoft Entra Sign-In Logs
Do not assume that possession of the computer automatically means the Microsoft 365 account was accessed.
Check the evidence.
Microsoft Entra maintains sign-in logs that administrators can use to review authentication activity. The logs can help identify:
Which user signed in
Which application was used
Which resource was accessed
Successful and failed sign-in attempts
Other details associated with authentication activity
Microsoft documents the sign-in logs under:
Microsoft Entra admin center → Entra ID → Monitoring & health → Sign-in logs.
Look particularly at activity that occurred after the employee reported losing control of the computer.
Unexpected sign-ins should be investigated rather than automatically assumed to be malicious, because legitimate applications can also create sign-in activity.
6. Check Whether BitLocker Was Enabled
This is one of the most important questions after the incident:
Was the laptop encrypted?
BitLocker is Microsoft's full-volume encryption technology for Windows.
Microsoft specifically explains that BitLocker addresses the threat of data theft or exposure from lost or stolen computers. Without encryption, someone with physical access may try to read the disk directly or move the drive to another computer.
BitLocker makes this significantly more difficult by encrypting the data on the drive.
For businesses, this is exactly why disk encryption should be configured before a device disappears.
BitLocker does not eliminate the need to disable the device, review sign-ins, or consider a remote wipe. It protects a different part of the problem: access to data stored locally on the computer when an unauthorized person has physical possession of it.
7. If It Is a Personal Device, Be Careful With Wipe
Not every employee computer belongs to the company.
If your organization allows employees to use personal devices, deleting everything on the computer may not be appropriate.
Microsoft Intune provides other options.
For example, the Retire action removes company data and settings while leaving personal data intact. Microsoft also supports selective removal of organizational data from certain Intune-managed applications.
The correct action therefore depends on whether the computer is:
Company-owned and fully managed
Employee-owned but enrolled
Employee-owned with only applications protected
Not managed by your organization at all
This distinction should already be part of your device-management policy rather than something your IT team has to decide for the first time during an incident.
8. Check Microsoft Defender if Compromise Is Suspected
Losing a computer and compromising a computer are not necessarily the same event.
However, if Microsoft Defender shows suspicious activity on the device, administrators may have additional response options.
Microsoft Defender for Endpoint can isolate supported devices from the network. Microsoft explains that isolation is intended to help prevent an attacker from controlling a compromised computer, exfiltrating information, or moving laterally through the environment while maintaining certain communication with the Defender service.
Device isolation should therefore be considered when there is evidence of device compromise rather than used automatically for every missing computer.
9. Document the Incident
Keep a record of what happened and what actions were taken.
At minimum, record:
Employee name
Device name
Date and approximate time the device disappeared
Whether the computer was company-owned
Whether BitLocker was enabled
Whether the device was managed in Intune
Whether the Entra device was disabled
Whether a remote wipe or retire action was initiated
Whether user sessions were revoked
Whether the password was reset
Results of the sign-in review
Any suspicious activity identified
This gives your business a clear record of the response and makes it easier to identify weaknesses that should be fixed before another device disappears.
Preparation Is More Important Than the Emergency Response
When an employee reports a stolen laptop, the effectiveness of your response depends heavily on security controls that were configured before the incident happened.
For SMBs using Microsoft 365, that means having a device-management strategy that includes Microsoft Intune where appropriate, BitLocker encryption, Microsoft Entra security controls, Conditional Access, and endpoint protection.
For example, Intune compliance information can be integrated with Microsoft Entra Conditional Access so organizations can require devices to meet defined compliance requirements before accessing company resources.
Without centralized device management, administrators may discover during an emergency that they cannot remotely wipe the computer, verify its configuration, or properly control how it accesses company information.
A Simple Lost-Laptop Response Checklist
When a company computer disappears:
Identify the exact device.
Determine whether it is Intune-managed.
Disable the device in Microsoft Entra when appropriate.
Initiate the appropriate Intune wipe or retire action.
Do not prematurely delete the device from management.
Determine whether the user's credentials might also be compromised.
Revoke sessions and reset credentials when the account is at risk.
Review Microsoft Entra sign-in activity.
Confirm whether BitLocker protected the device.
Review Defender alerts if device compromise is suspected.
Document the incident and remediation steps.
The worst time to discover that your company laptops are not properly managed is after one disappears.
A simple device-management and incident-response review can show whether your organization has the controls needed to respond quickly when it happens.
How We Help SMBs
For many small and midsize businesses, the challenge is not purchasing Microsoft 365 security features—it is making sure those features are configured correctly and work together.
We help SMBs manage and secure Microsoft 365 environments, including Microsoft Intune device management, Microsoft Entra security, Conditional Access, BitLocker deployment, Microsoft Defender, security monitoring, and incident response.
We can also review your existing Microsoft 365 environment to identify what would happen today if an employee lost a company computer—and which security controls should be improved before an incident occurs.





Comments