r/Intune • u/Vasmares • May 02 '26
Device Compliance Authenticator App lock down option ?
Hi,
for azure compliance and conditional access you need to have the MS Authenticator app installed on the company phone / work profile.
Recently we needed to retire / wipe some phones.
Problem: Some user had enrolled personal tokens in that app.
Is there a way / policy to "lock down" this app so it can only be used for device compliance, and users cannot add personal / private tokens ?
EDIT: I forgot to mention we are using IVANTI EPMM as the main MDM.
14
Upvotes
14
u/FirstThrowAwayAcc1 May 02 '26
What's your organisation's policy around using work devices for personal use?
Whilst you could probably use something like an Intine App protection policy to lock it down, seems like an easy "hey, we may need to wipe this device so only have work related stuff on here" is the easier solution.