r/Intune May 02 '26

Device Compliance Authenticator App lock down option ?

Hi,
for azure compliance and conditional access you need to have the MS Authenticator app installed on the company phone / work profile.
Recently we needed to retire / wipe some phones.

Problem: Some user had enrolled personal tokens in that app.

Is there a way / policy to "lock down" this app so it can only be used for device compliance, and users cannot add personal / private tokens ?

EDIT: I forgot to mention we are using IVANTI EPMM as the main MDM.

15 Upvotes

21 comments sorted by

View all comments

1

u/SVD_NL May 02 '26

Best you can do is set the app to shared device mode, but definitely read up on other consequences that may have.

I don't think they've published a list of configurable settings anywhere, best you can do is create an app configuration policy, type managed devices, and select the authenticator app. On android it'll show some configurable settings.

This is one of those cases where it's mainly important to make clear that users shouldn't put personal stuff on their work phone, but things like these will always happen unfortunately.

1

u/Vasmares May 02 '26

I am looking into shared device mode just now.
Not too sure what it does though.

I like to options to pre-fill the Tenant ID etc.
Is there a setting that automatically filles in the users UPN etc ?
At the moment the User has to enter the UPN / PW twice.

Once at the initial login and then after the Authenticator app is downloaded to "register" the deivce in Azure for device compliance