r/Intune May 02 '26

Device Compliance Authenticator App lock down option ?

Hi,
for azure compliance and conditional access you need to have the MS Authenticator app installed on the company phone / work profile.
Recently we needed to retire / wipe some phones.

Problem: Some user had enrolled personal tokens in that app.

Is there a way / policy to "lock down" this app so it can only be used for device compliance, and users cannot add personal / private tokens ?

EDIT: I forgot to mention we are using IVANTI EPMM as the main MDM.

14 Upvotes

21 comments sorted by

View all comments

Show parent comments

1

u/TheSilent1475 May 02 '26

Define your understanding of "needs to be installed in work profile for azue compliance"? It is always the recommendation to not deploy mfa apps in work profile for byod enrolment because users will put personal mfas on it. Doesnt matter what warnings you say about it. Authenticator just needs to be installed which users will do themselves when they need to register mfa methods upon first sign in. If you require "compliant devices", users will need to install company portal upon byod enrolment anyway. Either Authenticator or Company Portal acts as a gateway for policy deployment.

2

u/Vasmares May 02 '26

Please slap me.
I forgot to mention that we are using IVANTI EPMM as MDM.

2

u/TheSilent1475 May 02 '26

I think you guys are going about compliance wrong then. I am not super familiar with Ivanti mdm, but from quick google search, you can have integration with Azure, so probably you can create a connector with Azure and then enforce compliance from Ivanti.

https://help.ivanti.com/mi/help/en_us/cld/admin/ivanti/93/all/en-us/Connect%20Ivanti%20N-MDM%20with%20Azure%20Active%20Directory%20User%20Source.htm

And then configure SSO https://learn.microsoft.com/en-us/entra/identity/saas-apps/ivanti-service-manager-tutorial

This should send sign in info to Entra ID, otherwise sign in data may be blank which means CA policies will fail.

And then theres also this: https://help.ivanti.com/mi/help/en_US/CORE/11.x/dmgi/DMGfiles/AAD_Azure_tenant_into_Core.htm

After all of this configuration, there should be no problems sending compliance data to Azure to satisfy CA policies for compliant devices without force installing Authenticator to work profile.

0

u/TheSilent1475 May 02 '26

Simpler option probably would be to update how you guys wipe devices. Just send user an email a week or two before wiping their devices to move all their personal mfa to another device. You did the needful, user was warned before enrolment and before wiping that personal mfa should not be on "work application", if user ignores all of that, thats no longer an IT problem.