If you have a private phone that is not managed at all, it might be that it has no pin-code, which means that anyone that gets hold of that phone and the user’s credentials could authenticate. And that is a security issue. We don’t allow BYOD, but we can’t stop the users from using their own mobile when it comes to the Authenticator app.
How to restrict microsoft authenticator app on private mobile
We use intune and users start install microsoft authenticator app on their private devices. Higher management asked to disable it. How can i disable use the app and enable only on enrolled ones?
4 additional answers
Sort by: Most helpful
-
Jason Sandys 31,311 Reputation points Microsoft Employee
2022-11-07T18:57:26.823+00:00 This isn't really specific to Intune in any way. Curious as to why, what scenario is undesirable here or what are you/they trying to prevent by doing this?
-
Wojciech Napierała 1 Reputation point
2022-11-07T19:17:49.547+00:00 They think that is:
- security issue
- users should only use work phones (which are in intune)
all the time trying to explain that there is an option (conditional access) that disables BYOD completely, but there is an expectation to do it in steps and start with MS Auth. So I started to recognize the technical possibilities of such an approach.Ultimately (it is not yet known when) only devices from Intune will be used for work.
-
Jason Sandys 31,311 Reputation points Microsoft Employee
2022-11-07T21:11:33.243+00:00 security issue
Why? What's the issue exactly? What's the attack vector, exploit, or weakness here making it a security issue? What's the scenario where this will compromise the organization or its data?
-
Wojciech Napierała 41 Reputation points
2022-11-28T08:24:31.583+00:00 Thanks (Jason, Henrik) everyone for the replies. I spoke to the engineer at Premier Support about this. there is no simple solution. The engineer had no such case. Technically it is not possible and this is the way I will introduce my friends from work.