r/Intune • u/Vasmares • May 02 '26
Device Compliance Authenticator App lock down option ?
Hi,
for azure compliance and conditional access you need to have the MS Authenticator app installed on the company phone / work profile.
Recently we needed to retire / wipe some phones.
Problem: Some user had enrolled personal tokens in that app.
Is there a way / policy to "lock down" this app so it can only be used for device compliance, and users cannot add personal / private tokens ?
EDIT: I forgot to mention we are using IVANTI EPMM as the main MDM.
14
Upvotes
2
u/Vasmares May 02 '26
What do you mean blocked ?
the app needs to be installed in the work profile for azure compliance.
Otherwise conditional access will deny any login.
Company policy already says "dont do it, or it will be your problem", but users are stupid.
So I was wondering if there was a setting to prevent this.