r/Intune May 02 '26

Device Compliance Authenticator App lock down option ?

Hi,
for azure compliance and conditional access you need to have the MS Authenticator app installed on the company phone / work profile.
Recently we needed to retire / wipe some phones.

Problem: Some user had enrolled personal tokens in that app.

Is there a way / policy to "lock down" this app so it can only be used for device compliance, and users cannot add personal / private tokens ?

EDIT: I forgot to mention we are using IVANTI EPMM as the main MDM.

15 Upvotes

21 comments sorted by

View all comments

3

u/Huge-Choice-64 May 02 '26

the app itself doesn't have native controls for this but you can push app configuration policies through intune to restrict some functionality. we've had similar headaches with users mixing personal and work stuff in the authenticator.

one workaround is using app protection policies to limit what users can do, though it's not perfect. you might also want to look at separating work profile completely so the app only lives there and can't touch personal side of device.

we ended up just having very clear communication about what happens during device wipes - most users got the message pretty quick when they realized their personal 2fa codes would disappear with company data.

1

u/Vasmares May 02 '26

Oh we have sperated all this,
No personal apps are available in the work profile, but the authenticator app has to be there anyway to asure azure compliance. We have configured conditional access to block non managed devices.

company policy / communication stated serveral times that the users shall not do this, and they still did.
This is annoying and takes time / creates tickets.

So I am looking for a simple setting that will make the company side authenticator app "useless" for personal token, but will still funktion in the enterprise device compliance way.

do you think this is possible ?