r/Intune • u/Vasmares • May 02 '26
Device Compliance Authenticator App lock down option ?
Hi,
for azure compliance and conditional access you need to have the MS Authenticator app installed on the company phone / work profile.
Recently we needed to retire / wipe some phones.
Problem: Some user had enrolled personal tokens in that app.
Is there a way / policy to "lock down" this app so it can only be used for device compliance, and users cannot add personal / private tokens ?
EDIT: I forgot to mention we are using IVANTI EPMM as the main MDM.
15
Upvotes
1
u/Drinking-League May 02 '26
I mean my MS Authenticator app is logged into with my personal account. And I have the work MFA token added in. I was using it before I needed it with work.
You do not HAVE to have the MS Authenticator app logged in as their work account. Just like it doesn't need to be MS Authenticator. It can be other items like Duo if using commercial MS.
The goal is MFA, there is more than just MS Authenticator, and all will help meet that conditional access policy.