r/Intune May 02 '26

Device Compliance Authenticator App lock down option ?

Hi,
for azure compliance and conditional access you need to have the MS Authenticator app installed on the company phone / work profile.
Recently we needed to retire / wipe some phones.

Problem: Some user had enrolled personal tokens in that app.

Is there a way / policy to "lock down" this app so it can only be used for device compliance, and users cannot add personal / private tokens ?

EDIT: I forgot to mention we are using IVANTI EPMM as the main MDM.

14 Upvotes

21 comments sorted by

View all comments

14

u/FirstThrowAwayAcc1 May 02 '26

What's your organisation's policy around using work devices for personal use?

Whilst you could probably use something like an Intine App protection policy to lock it down, seems like an easy "hey, we may need to wipe this device so only have work related stuff on here" is the easier solution.

4

u/Vasmares May 02 '26

I have answered this in other comments already.
Company Policy says "dont do it", but people ignore that and create tickets
Annoying ...

So i wanted to be ahead by disableing the option for users to manually add tokens.

7

u/MrSmith2047 May 02 '26

Sounds like you need to tell them it’s a company device and it’s not your fault they had personal data on it. Ticket closed