How to Uninstall SHIELD
7 min
this article explains how to fully decommission shield to stop accruing the associated costs the process involves three steps and an optional step to delete shield desktop once you're finished, validate that all the applications and groups have been removed to remove entra groups, intune scope tags, and conditional access policies created by shield, see the shield deploy uninstall procedure https //url shilab com/deploy uninstall step 1 delete the azure resource group used for shield the first decommissioning step is to remove the azure resource group associated with shield sign in to your azure portal enterprise https //portal azure com/ https //portal azure com/ government https //portal azure us/ https //portal azure us/ navigate to subscriptions and select the subscription dedicated to shield click resource groups in the left navigation bar click on the azure resource group created for shield (e g , shield) click delete resource group at the top of the table and proceed with the deletion process this removes the shield azure app service (web app) associated storage, compute, and networking resources step 2 cancel the azure subscription once the resource group is removed, the next step is to remove the azure subscription used for shield if shield was deployed in its own dedicated azure subscription, you can go ahead and remove it if it is running in a shared subscription, this step can be skipped sign in to your azure portal enterprise https //portal azure com/ https //portal azure com/ government https //portal azure us/ https //portal azure us/ navigate to subscriptions and select the subscription dedicated to shield click cancel subscription at the top of the table and proceed with the cancelation process step 3 delete shield identity objects in entra id after azure resources are removed, you will need to remove a few identity objects these objects are created as part of the shield installation process and should be removed to fully decommission access sign in to your entra id admin center enterprise https //entra microsoft com/ https //entra microsoft com/ government https //entra microsoft us/ https //entra microsoft us/ navigate to enterprise apps in the navigation bar click on the name of the application you wish to delete you can use the search bar if needed you will need to delete the following applications shield end user login shield desktop shi data gateway click properties in the left navigation bar click the delete button at the bottom and proceed with the deletion process repeat steps 2 5 until you have deleted all the applications optional uninstall the shield desktop application (if installed) if you installed shield using the shield desktop application, you can uninstall it after shield discover is complete shield desktop is no longer required after reporting is finalized this applies whether the app was installed on a local machine an azure vm final step validate cleanup as a final check, you may want to confirm the shield resource group is fully removed confirm the shield web app no longer exists in azure app services confirm the azure subscription dedicated for shield has been canceled confirm there are no shield‑related applications in entra id confirm the shield desktop application has been uninstalled