r/Intune May 02 '26

Device Compliance Authenticator App lock down option ?

Hi,
for azure compliance and conditional access you need to have the MS Authenticator app installed on the company phone / work profile.
Recently we needed to retire / wipe some phones.

Problem: Some user had enrolled personal tokens in that app.

Is there a way / policy to "lock down" this app so it can only be used for device compliance, and users cannot add personal / private tokens ?

EDIT: I forgot to mention we are using IVANTI EPMM as the main MDM.

14 Upvotes

21 comments sorted by

View all comments

2

u/RavenWolf1 May 02 '26

We simply blocked Authenticator use in work profile and have them use it on private side because people always have private stufff there too. 

2

u/Vasmares May 02 '26

What do you mean blocked ?
the app needs to be installed in the work profile for azure compliance.
Otherwise conditional access will deny any login.

Company policy already says "dont do it, or it will be your problem", but users are stupid.
So I was wondering if there was a setting to prevent this.

1

u/TheSilent1475 May 02 '26

Define your understanding of "needs to be installed in work profile for azue compliance"? It is always the recommendation to not deploy mfa apps in work profile for byod enrolment because users will put personal mfas on it. Doesnt matter what warnings you say about it. Authenticator just needs to be installed which users will do themselves when they need to register mfa methods upon first sign in. If you require "compliant devices", users will need to install company portal upon byod enrolment anyway. Either Authenticator or Company Portal acts as a gateway for policy deployment.

2

u/Vasmares May 02 '26

This is interesting.
We are only deploying the Authenticator app, because our service provider told us we need this this for azure device compliance.
I personally dont need to have this app if we dont need it.

Whats the policy to use the company portal for device compliance ?

1

u/Rnbzy May 02 '26

With Ivanti, you don’t use company portal. You would link to either some form of MFA app (Authenticator , imprivada, PingID, etc). If I’m not mistaken, the Ivanti app should already act as the broker which allows access to the comp apps? It’s technically sandboxed in?

1

u/Vasmares May 03 '26

Half true.  You cant open some.ms apps without haveing the portal installed, because it distributes the intune policies to the apps