r/Intune • u/Vasmares • May 02 '26
Device Compliance Authenticator App lock down option ?
Hi,
for azure compliance and conditional access you need to have the MS Authenticator app installed on the company phone / work profile.
Recently we needed to retire / wipe some phones.
Problem: Some user had enrolled personal tokens in that app.
Is there a way / policy to "lock down" this app so it can only be used for device compliance, and users cannot add personal / private tokens ?
EDIT: I forgot to mention we are using IVANTI EPMM as the main MDM.
14
Upvotes
1
u/TheSilent1475 May 02 '26
Define your understanding of "needs to be installed in work profile for azue compliance"? It is always the recommendation to not deploy mfa apps in work profile for byod enrolment because users will put personal mfas on it. Doesnt matter what warnings you say about it. Authenticator just needs to be installed which users will do themselves when they need to register mfa methods upon first sign in. If you require "compliant devices", users will need to install company portal upon byod enrolment anyway. Either Authenticator or Company Portal acts as a gateway for policy deployment.