Home · Solutions · IT & services

Solution · IT & services

One record per device, from the purchase order to the certificate that it was erased

Every laptop accounted for, from order to wipe certificate

Every laptop, phone and dock carries one record from order to disposal: reserved, enrolled in Microsoft Intune, signed for at handover, returned on the leaving date and erased with evidence.

DepartmentalMicrosoft TeamsHuman in the loopDeterministic automation
4,100devices sit on the asset list of this illustrative company. The last time anyone checked that list against reality, it took a walk round four buildings.

Executive summary

Challenge

Hardware ordered by email, handed over without a record, and written off when the auditor asks.

What changes

The design has one rule: the serial number is the record, and nothing enters or leaves the estate without an event written against it.

Business value

Starters receive the device reserved for them, because stock is a number the flow maintains rather than a look in a cupboard.

Systems involved

the asset register in Microsoft Lists; Microsoft Intune; Microsoft Entra ID

Business problem

IT asset management

A device is three things at once, and each belongs to a different department. It is capital that finance depreciates, a security boundary that IT answers for, and the reason an employee can work on Monday. Nobody owns all three, so the record that ties them together is never anyone's first priority.

Each act looks small. Ordering a laptop is one email, a handover takes five minutes in a corridor, a return is a box on a desk. Multiply that by the joiners, movers, breakages, upgrades and leavers of a few thousand people and it becomes a permanent stream of small acts, each easy to skip.

What breaks at scale is the register. It is accurate on the day it is built and drifts from then on, because the events that should update it happen in chats, at reception desks and in cupboards. Within two years the company owns three partial answers: the list, the console and the depreciation schedule.

The consequences hide their cause. IT buys hardware it already owns because the stock figure is not trusted. Repairs are paid for outside a warranty that was still running. Devices from leavers sit in drawers, counted as active, still holding company data. Once a year somebody builds an inventory that is out of date the week after it is signed.

How it works today

This is the pattern in companies running a few thousand devices without a dedicated asset system.

  1. PersonA manager emails IT that a starter needs a laptop; the service desk checks the cupboard, then the reseller
  2. WaitingBoxes arrive at a reception desk and wait until somebody has time to open them
  3. PersonThe service desk enrols the device and hands it over in person; the protocol is signed in some offices, not others
  4. SystemThe serial number is typed into a SharePoint list, and into the fixed-asset register weeks later
  5. Risk of errorReturns from leavers go to whoever sits nearest; the record is a chat message, or nothing
  6. Risk of errorA device in a drawer keeps its console entry and its directory object, so reports still count it as in use
  7. WaitingWarranty dates live in the reseller's portal, so replacement is decided when a device fails
  8. PersonOnce a year the list is reconciled by walking the floors with a printout
PersonWaitingSystemRisk of error

Why the current process costs more than it appears

Time that disappears before anyone measures it.

  • Buying is cheaper than searching, which is why it happens. When the stock figure cannot be trusted, the fastest way to equip a starter is a new order, and the cupboard fills with hardware already paid for.
  • Warranty is money spent in advance and then not used. A free repair arrives as an invoice, because nobody could say what cover that serial number carried.
  • Devices that leave without a record keep costing after they are gone: they stay in the console, stay in the directory, distort every count management sees, and remain a data question until somebody asks.
  • Finance and IT maintain two versions of the same estate. The difference is written off rather than explained, which is what an external auditor looks for.

Cost of inaction

Twelve months of handovers, returns and floor walks≈ €34,320
The same twelve months plus 60 devices that leave the estate unrecorded≈ €88,300
Four years of it, which is one full refresh cycle≈ €137,200

Sixty devices a year, about one and a half percent of an estate of 4,100, is the assumption behind the middle row, priced at a modelled €900 each. Whether the real rate is half that or twice it, the loss is never defended in a budget, because each device goes missing on its own and in a different month. The bottom row carries today's administration through a four-year refresh.

What decays quietly is the ability to answer any question about the estate. Every month the register drifts further from the console and the directory, so when the question arrives, from an auditor, an insurer or an incident, the answer is rebuilt by hand. A device nobody can locate is also one nobody can prove was erased.

Illustrative scenario

A plausible organisation with realistic proportions. The figures are there to be recalculated on your data; they are not a client result.

Organisation

A professional services and retail support group, 2,600 employees in Poland, Czechia and Germany; 4,100 managed devices, mostly laptops, docks, monitors and phones; Microsoft 365 E3 with Microsoft Intune and Microsoft Entra ID; fixed assets in the ERP.

Volume

260 device lifecycle events a month: roughly 95 assignments, 70 replacements and repairs, 60 returns and 35 transfers, against a four-year refresh cycle.

Current process

Requests and orders by email, a SharePoint list as the register, handovers signed in some offices, returns recorded in chats, one inventory count a year.

Bottleneck

About 22 minutes of administration per event across the service desk, the line manager and finance, and a register nobody uses because nobody believes it.

Solution

One record per serial number, opened by the order and closed by the disposal certificate. Microsoft Intune enrols and later erases the device, UiPath robots run the ordering, return and reconciliation steps, and Microsoft Teams carries the handover and the exceptions.

Potential outcome

In the modelled case administration falls to the exceptions, returns are chased against a date rather than a memory, the annual floor walk becomes a monthly comparison of three systems, and the refresh budget comes from the estate rather than last year's figure. All of it is arithmetic on assumptions, not a client measurement.

Proposed solution

The design has one rule: the serial number is the record, and nothing enters or leaves the estate without an event written against it. The record opens when the order is placed, not when somebody finds time to type it in, and closes with a disposal certificate.

The register is deliberately ordinary: a Microsoft List with one item per device, carrying status, holder, cost centre, purchase date, warranty end and refresh date. Requests arrive from your joiner or replacement trigger, or from a form in Microsoft Teams; stock is reserved where it exists, and robots raise the order where it does not.

This flow owns the object, not the identity. Accounts, licences and system roles are a separate pipeline; the two exchange two messages, the leaving date that opens a dated return task here, and the confirmation that the device came back and was erased, which closes the equipment line on offboarding. Erasure is the Microsoft Intune Wipe action, which factory-resets the device and reports its status back to be written against the record.

The control that makes the rest believable runs monthly. Through Microsoft Graph the flow reads managed devices from Microsoft Intune and device objects from Microsoft Entra ID and compares both against the register; anything missing from one of the three becomes a task with its evidence. Warranty and refresh dates feed a Power BI view that prices the replacement budget by device age and cover.

Native capabilities used

Microsoft Intune enrolment, compliance state and the remote Wipe action with status reporting; Microsoft Entra ID device records; Microsoft Lists; SharePoint eSignature; Microsoft Teams Approvals app; Microsoft Graph; UiPath Orchestrator queues, triggers and credential stores; UiPath Action Center tasks in Microsoft Teams; Power BI

What we build

The asset record model and its statuses, the request and reservation flow, order and delivery matching, the handover protocol, the dated return sequence, the disposal evidence pack, the monthly reconciliation and the refresh reporting

Custom integration

Reseller ordering and despatch notes where the portals offer no API; the ERP fixed-asset register; the recycler's collection request and certificate retrieval

How the automated process works

  1. AutomationA device request from your joiner or replacement trigger opens an asset record; stock is reserved, or the record starts as "on order"
  2. SystemRobots raise the order with the reseller or as an ERP requisition and write the confirmed delivery date onto the record
  3. AutomationSerial numbers from the despatch note are matched to open order lines and each device moves to "in stock" with its warranty end date
  4. AutomationEnrolment is confirmed by reading the managed device from Microsoft Intune through Microsoft Graph, and the record is linked to holder and cost centre
  5. PersonThe employee confirms handover in Microsoft Teams and, above the threshold, signs the protocol through SharePoint eSignature
  6. AutomationA leaving or replacement date opens a dated return task with the line manager as escalation, and the device leaves available stock
  7. AutomationOn receipt the Wipe action runs, its status is written to the record, and the device is re-stocked, repaired or added to a disposal batch
  8. AutomationMonthly, the register is compared with Microsoft Intune and Microsoft Entra ID, and every difference becomes a task with its evidence
AutomationSystemPerson

Human-in-the-loop model

Automation handles

  • Record creation, status changes and the link between a device, its holder and its cost centre
  • Ordering, delivery matching, warranty capture and the enrolment check
  • Return deadlines, reminders and escalation to the line manager
  • Erasure, its evidence, and the monthly comparison with Microsoft Intune and Microsoft Entra ID

People decide

  • Whether a returned device is re-stocked, repaired or scrapped, and what a non-standard request may cost
  • Exceptions to a return date: notice worked from home, long-term absence, a device held for a rehire
  • Write-off of anything the reconciliation cannot find, approved by the asset owner in finance
  • The device standard per role and the threshold above which a handover needs a signature

Before and after

BeforeAfter
Administration per lifecycle eventabout 22 min across three rolesminutes, on exceptions only
Leaving date to device back in stockweeks, if anyone chasesa dated task with an escalation
Evidence that a device was eraseda message in a chatwipe status and certificate on the record
Register against Intune and the directoryone floor walk a yeara monthly comparison

Systems and integrations

Everything below runs on licences and systems you already hold, or would need anyway.

Inputs

  • joiner, mover and leaver dates from the HR system
  • device requests in Microsoft Teams
  • reseller confirmations and despatch notes
  • repair tickets
  • the existing asset list

Automation layer

  • UiPath Orchestrator
  • UiPath Robots
  • UiPath Action Center
  • Power Automate
  • Microsoft Graph

Target systems

  • the asset register in Microsoft Lists
  • Microsoft Intune
  • Microsoft Entra ID
  • the ERP fixed-asset register
  • the SharePoint evidence archive

Human touchpoints: handover confirmation and signature; return and exception tasks in Microsoft Teams; the stock and refresh view in Power BI

joinerUiPath OrchestratorUiPath Robotsthe asset register in Microsoft Listshandover confirmation

Technologies used

Microsoft Intune

enrolment, compliance state, and the remote Wipe that erases a returned device and reports its status

A
Microsoft Entra ID

the device objects and users the register is reconciled against

A
Microsoft Lists

the asset register: one item per serial number with status, holder, cost centre and warranty end

A
UiPath Robots + Orchestrator

queue every lifecycle event, drive the reseller and ERP steps, and write the audit trail

A
Microsoft Graph

reads managed devices, directory device objects and users for the monthly reconciliation

A
Microsoft Teams (Approvals app)

handover confirmations, dated return tasks and exception approvals

A
SharePoint eSignature

the signed handover protocol, stored with the device record and audited in Microsoft Purview

A
Power BI

stock, warranty expiry, refresh dates and the replacement budget by device age

A
Averified product capability (vendor documentation)

Illustrative economic model

A model, not a promise.

Illustrative model
260 device lifecycle events a month × 22 minutes of administration= 95 h / month
95 h × €30 blended fully loaded hourly cost= €2,860 / month
× 12 months≈ €34,320 / year
Annual administration effort released (illustrative)≈ €34,320

Twenty-two minutes is not the time it takes to hand somebody a laptop; it is what a whole event costs across the service desk, the line manager and finance once chasing, double entry and correction are counted, and it is illustrative rather than measured at a client. €30 is a blended fully loaded hourly cost for those roles in Central Europe. The inventory count, the over-ordering and the devices that never come back sit outside it.

Run the numbers on your data

hours released per month
of annual capacity released

An illustrative estimate from your own inputs. It models released capacity; it is not a promise of savings.

Business benefits

  • Starters receive the device reserved for them, because stock is a number the flow maintains rather than a look in a cupboard
  • Returns carry a date, an owner and an escalation, so equipment comes back while the leaver is still reachable
  • Erasure produces its own evidence, so whether a laptop was wiped is answered from the record, not from memory
  • Warranty gets used before it expires: a fault goes to the supplier while cover lasts, not to a purchase order
  • Finance and IT stop describing two estates, because the same events update the register and the fixed-asset record

The management view

  • Stock, assignments, returns due and disposals become a monthly number instead of an annual exercise with a printout
  • A new site or a hiring wave becomes a stock decision taken against data, not an urgent order
  • The estate can be evidenced on demand: what exists, who holds it, what was erased and when
  • The process stops depending on the two people who know where things are

Board-level KPIs

devices ready on the start datedays from leaving date to device returnedreturns erased with evidencedifferences per monthly reconciliationshare of the estate inside warranty

Security and governance

Control is not an add-on.

  • Each robot signs in as its own named account with the narrowest Microsoft Graph permissions its job needs: read managed devices and directory objects, write only to the asset list. Secrets are drawn at run time from the credential store or your own vault.
  • Erasure is treated as an evidence event: the wipe command, the status Microsoft Intune returns, the authoriser and the completion time are kept with the disposal certificate for as long as retention requires.
  • Nobody both loses a device and writes it off. Differences the reconciliation cannot explain are cleared by the asset owner in finance, not by the service desk that reported them.
  • Personal data on the record stays at holder, cost centre and location; the register, protocols and certificates remain in your Microsoft 365 tenant, while queues run in the UiPath Automation Cloud EU region.

Why now

01

Disposal is a documented act under EU law. Directive 2012/19/EU requires separately collected waste electrical and electronic equipment to undergo proper treatment (Article 8(1)), and for equipment from business users it requires producers or third parties acting on their behalf to provide for collection (Article 5(5)). The evidence is easier to hold when created at collection than reconstructed for an audit.

02

The administration alone is modelled at €2,860 a month, the part that counts easily; devices that leave the register without leaving the building are worth more and sit on no budget line.

03

The reconciliation this rests on is a read rather than a project: Microsoft Graph exposes Intune managed devices, directory objects and users, and the Wipe action reports its own completion.

Relevant executive roles

CIO

One record per device replaces three partial ones, and the estate is reported without sending anyone round the buildings

CFO

The fixed-asset register and the real estate agree, and the replacement budget comes from device age and warranty

CISO

Every device that leaves employment is erased on a date, with the evidence in place before anybody asks

CHRO

The equipment line on the offboarding checklist closes by itself, so HR stops chasing IT for something it cannot see

Common questions and objections

Our service-desk tool already has an asset field.

The field is rarely the problem; the events are. A ticket tool holds what somebody typed when they had time, while this writes the record when the order is placed, the protocol is signed and the wipe completes, then proves it against Microsoft Intune every month. Where that tool is the right home for the register, we write into it.

People will not sign a protocol for a phone.

Then set the threshold by value or device class. The signature exists to make a return date enforceable and a loss conversation short; below it the record still exists, carrying a confirmation in Microsoft Teams instead.

Can automation make people return equipment?

No flow returns a laptop. What changes is that the return becomes a dated task with a named owner and an escalation, the device stops counting as stock, and what remains is a short named list a manager can act on.

When this is not the right solution

  • Estates of a few hundred devices with one person who knows where each one is: a good list and a quarterly check will cost less
  • Devices that are not centrally managed, such as a contractor estate on somebody else's tenant, because there is no enrolment record to reconcile against
  • Sites that buy their own hardware to their own specification: agree the standard and the buying route first, or the register documents the disorder

A question for the next management meeting

Could this company produce today, for twenty serial numbers picked at random from its own register, the current holder of each device and the evidence that the ones we disposed of were erased?

Implementation approach

The first week looks the same at every client: we look at the data.

We deliver

  • The asset record model: what a record holds, which statuses exist, and which event moves it
  • The request and reservation flow, connected to your existing joiner and replacement triggers
  • The handover protocol and its signature route, with thresholds by device class
  • The return sequence: dated tasks in Microsoft Teams, escalation, receipt, the Wipe action and its evidence
  • Disposal batches, the recycler hand-off and the certificate filed against each serial number
  • The monthly comparison of register, Microsoft Intune and Microsoft Entra ID, with a task per difference
  • Stock, warranty and refresh reporting in Power BI, and a service-desk runbook

We need from you

  • The current register in whatever state it is: an export, a spreadsheet or a service-desk field
  • A device standard per role, and the warranty terms you actually buy
  • Technical accounts with the Microsoft Graph permissions the reconciliation needs
  • Your reseller and recycler contacts, and what their portals allow

Stages

Discovery

Count the estate, the monthly events, and where each record lives today

Design

Record model, statuses, signature thresholds, return deadlines and reconciliation rules

Build

Flows, robots, the Teams touchpoints, the Microsoft Intune and Graph integration, reporting

Validation

Replay of last quarter's joiners, leavers and returns; a first reconciliation

Go-live

One country first, with the old list kept alongside until the two agree

Optimisation

Findings tighten the rules; further device classes and sites join the pattern

Departmental. Effort follows the number of sites and resellers, and how far today's register sits from the real estate.