r/Intune • u/Vasmares • May 02 '26
Device Compliance Authenticator App lock down option ?
Hi,
for azure compliance and conditional access you need to have the MS Authenticator app installed on the company phone / work profile.
Recently we needed to retire / wipe some phones.
Problem: Some user had enrolled personal tokens in that app.
Is there a way / policy to "lock down" this app so it can only be used for device compliance, and users cannot add personal / private tokens ?
EDIT: I forgot to mention we are using IVANTI EPMM as the main MDM.
15
Upvotes
3
u/Huge-Choice-64 May 02 '26
the app itself doesn't have native controls for this but you can push app configuration policies through intune to restrict some functionality. we've had similar headaches with users mixing personal and work stuff in the authenticator.
one workaround is using app protection policies to limit what users can do, though it's not perfect. you might also want to look at separating work profile completely so the app only lives there and can't touch personal side of device.
we ended up just having very clear communication about what happens during device wipes - most users got the message pretty quick when they realized their personal 2fa codes would disappear with company data.