Skip to content
Aqil Haydel
← Work
ShopBack · Mar 2026 – Apr 2026

Halving a 1,600-Device JumpCloud Fleet

IT Support Intern, Global Corporate IT (EUC)

  • PowerShell
  • JumpCloud REST API

Outcome

Decommissioned 860 stale device records, reducing fleet size by ~50%

Context

The JumpCloud directory had accumulated years of device records, former employees, decommissioned hardware, test machines, duplicates. At ~1,600 devices, the directory was bloated, license costs were inflated, and audits took longer than necessary.

Problem & Constraints

  • 1,600 devices in directory, many stale
  • No automated cleanup process existed
  • Could not blindly delete, needed audit trail
  • License costs tied to active device count
  • Some "stale" devices were cold-spares or infrequently used lab machines

Approach

Wrote a PowerShell audit script that queried JumpCloud's REST API for all devices, calculated days since last check-in, applied a 90-day inactivity threshold, generated a pre-deletion audit report (CSV with device ID, user, last IP, MAC, last check-in date), and, after human review, batch-deleted stale records via API.

The two-phase approach (audit then cleanup, with a human gate between them) was deliberate. A fully automated pipeline would have been faster but risked deleting cold-spares or machines belonging to employees on extended leave.

Implementation

The pipeline ran in two phases. Phase 1 (audit) exported every device with inactivity metrics to CSV. The EUC team reviewed flagged devices against the helpdesk queue, any recent tickets meant the device was active despite no check-in. Phase 2 (cleanup) took the reviewed CSV and called JumpCloud's DELETE endpoint in batches, logging each deletion to an audit file.

Outcome

  • 860 stale records decommissioned (~50% fleet reduction)
  • License cost savings from halved active device count
  • Audit process that was previously manual now scripted and repeatable
  • Audit trail retained for all deletions

Reflection

The 90-day threshold was conservative, many devices at 120+ days were clearly dead. A tiered approach (soft-disable at 60 days, hard-delete at 120) would reduce manual review. The human review step was critical for accuracy but took 2–3 hours per audit cycle; adding automatic ticket-system cross-referencing would cut that significantly.