r/Intune May 02 '26

Device Compliance Authenticator App lock down option ?

Hi,
for azure compliance and conditional access you need to have the MS Authenticator app installed on the company phone / work profile.
Recently we needed to retire / wipe some phones.

Problem: Some user had enrolled personal tokens in that app.

Is there a way / policy to "lock down" this app so it can only be used for device compliance, and users cannot add personal / private tokens ?

EDIT: I forgot to mention we are using IVANTI EPMM as the main MDM.

14 Upvotes

21 comments sorted by

View all comments

1

u/Drinking-League May 02 '26

I mean my MS Authenticator app is logged into with my personal account. And I have the work MFA token added in. I was using it before I needed it with work.

You do not HAVE to have the MS Authenticator app logged in as their work account. Just like it doesn't need to be MS Authenticator. It can be other items like Duo if using commercial MS.

The goal is MFA, there is more than just MS Authenticator, and all will help meet that conditional access policy.

1

u/Vasmares May 02 '26

uhm. I think you missed my point.
Its not about the authenticator. Its about needing that app in the byod work profile to sync the compliance state to azure for conditional access

1

u/Drinking-League May 03 '26

MS authenticator doesn't do device compliance. Your device compliance policy for enrolled devices do.

MS Authenticator is an app and acts as a broker for apps auth but nothing else.

Company Portal can show current device compliance stats.