<style> .chartjs-size-monitor { display: none !important; height: 0 !important; overflow: hidden !important; }p { margin: 0; }span.fr-emoticon.fr-emoticon-img { background-repeat: no-repeat !important; font-size: inherit; height: 1em; width: 1em; min-height: 20px; min-width: 20px; display: inline-block; margin: -0.1em 0.1em 0.1em; line-height: 1; vertical-align: middle; } span.fr-emoticon { font-weight: normal; font-family: "Apple Color Emoji", "Segoe UI Emoji", "NotoColorEmoji", "Segoe UI Symbol", "Android Emoji", "EmojiSymbols"; display: inline; line-height: 0; } blockquote { border-left: solid 2px #5e35b1; color: #5e35b1; margin-left:0; padding-left:5px;}blockquote blockquote{ border-color: #00bcd4; color: #00bcd4;}blockquote blockquote blockquote{ border-color: #43a047; color: #43a047;} table.grid{ border-collapse: collapse;} table.grid td, table.grid th { border: 1px solid #ddd;} .fr-fic.fr-dib{ display: block; margin: 5px auto;}.fr-fic.fr-dib.fr-fir{ text-align: right; margin: 5px 0 5px auto;}.fr-fic.fr-dib.fr-fil{ text-align: left; margin: 5px auto 5px 0;}.fr-fic.fr-dii{ float: none; margin: 5px auto;}.fr-fic.fr-dii.fr-fil{ float: left; margin: 5px auto;}.fr-fic.fr-dii.fr-fir{ float: right; margin: 5px auto;}img.fr-dib.fr-fir { margin-right: 0; text-align: right;}img.fr-dib.fr-fil { margin-left: 0; text-align: left;}img.fr-dib { margin: 5px auto; display: block; float: none;}img.fr-bordered { box-sizing: content-box; border: solid 5px #CCC;}img.fr-shadow { box-shadow: 10px 10px 5px 0px #cccccc;}img.fr-rounded { border-radius: 10px; -moz-border-radius: 10px; -webkit-border-radius: 10px; -moz-background-clip: padding; -webkit-background-clip: padding-box; background-clip: padding-box;}</style><style>
.chartjs-size-monitor {
display: none !important; height: 0 !important; overflow: hidden !important;
}
p {
margin: 0;
}
span.fr-emoticon.fr-emoticon-img {
background-repeat: no-repeat !important; font-size: inherit; height: 1em; width: 1em; min-height: 20px; min-width: 20px; display: inline-block; margin: -0.1em 0.1em 0.1em; line-height: 1; vertical-align: middle;
}
span.fr-emoticon {
font-weight: normal; font-family: "Apple Color Emoji", "Segoe UI Emoji", "NotoColorEmoji", "Segoe UI Symbol", "Android Emoji", "EmojiSymbols"; display: inline; line-height: 0;
}
blockquote {
border-left: solid 2px #5e35b1; color: #5e35b1; margin-left: 0; padding-left: 5px;
}
blockquote blockquote {
border-color: #00bcd4; color: #00bcd4;
}
blockquote blockquote blockquote {
border-color: #43a047; color: #43a047;
}
table.grid {
border-collapse: collapse;
}
table.grid td,
table.grid th {
border: 1px solid #ddd;
}
.fr-fic.fr-dib {
display: block; margin: 5px auto;
}
.fr-fic.fr-dib.fr-fir {
text-align: right; margin: 5px 0 5px auto;
}
.fr-fic.fr-dib.fr-fil {
text-align: left; margin: 5px auto 5px 0;
}
.fr-fic.fr-dii {
float: none; margin: 5px auto;
}
.fr-fic.fr-dii.fr-fil {
float: left; margin: 5px auto;
}
.fr-fic.fr-dii.fr-fir {
float: right; margin: 5px auto;
}
img.fr-dib.fr-fir {
margin-right: 0; text-align: right;
}
img.fr-dib.fr-fil {
margin-left: 0; text-align: left;
}
img.fr-dib {
margin: 5px auto; display: block; float: none;
}
img.fr-bordered {
box-sizing: content-box; border: solid 5px #CCC;
}
img.fr-shadow {
box-shadow: 10px 10px 5px 0px #cccccc;
}
img.fr-rounded {
border-radius: 10px; -moz-border-radius: 10px; -webkit-border-radius: 10px; -moz-background-clip: padding; -webkit-background-clip: padding-box; background-clip: padding-box;
}
</style><style>
.chartjs-size-monitor {
display: none !important; height: 0 !important; overflow: hidden !important;
}
p {
margin: 0;
}
span.fr-emoticon.fr-emoticon-img {
background-repeat: no-repeat !important; font-size: inherit; height: 1em; width: 1em; min-height: 20px; min-width: 20px; display: inline-block; margin: -0.1em 0.1em 0.1em; line-height: 1; vertical-align: middle;
}
span.fr-emoticon {
font-weight: normal; font-family: "Apple Color Emoji", "Segoe UI Emoji", "NotoColorEmoji", "Segoe UI Symbol", "Android Emoji", "EmojiSymbols"; display: inline; line-height: 0;
}
blockquote {
border-left: solid 2px #5e35b1; color: #5e35b1; margin-left: 0; padding-left: 5px;
}
blockquote blockquote {
border-color: #00bcd4; color: #00bcd4;
}
blockquote blockquote blockquote {
border-color: #43a047; color: #43a047;
}
table.grid {
border-collapse: collapse;
}
table.grid td,
table.grid th {
border: 1px solid #ddd;
}
.fr-fic.fr-dib {
display: block; margin: 5px auto;
}
.fr-fic.fr-dib.fr-fir {
text-align: right; margin: 5px 0 5px auto;
}
.fr-fic.fr-dib.fr-fil {
text-align: left; margin: 5px auto 5px 0;
}
.fr-fic.fr-dii {
float: none; margin: 5px auto;
}
.fr-fic.fr-dii.fr-fil {
float: left; margin: 5px auto;
}
.fr-fic.fr-dii.fr-fir {
float: right; margin: 5px auto;
}
img.fr-dib.fr-fir {
margin-right: 0; text-align: right;
}
img.fr-dib.fr-fil {
margin-left: 0; text-align: left;
}
img.fr-dib {
margin: 5px auto; display: block; float: none;
}
img.fr-bordered {
box-sizing: content-box; border: solid 5px #CCC;
}
img.fr-shadow {
box-shadow: 10px 10px 5px 0px #cccccc;
}
img.fr-rounded {
border-radius: 10px; -moz-border-radius: 10px; -webkit-border-radius: 10px; -moz-background-clip: padding; -webkit-background-clip: padding-box; background-clip: padding-box;
}
</style><p><strong>In this guide we will cover:</strong></p><p><strong>- What is Intune App Protection?</strong></p><p><strong>- Key Terms and Pre-Requisites </strong></p><p><strong>- Required Microsoft Configuration</strong></p><p><strong>- Halo Configuration</strong></p><p><strong>- Intune App Protection (MAM) setup</strong></p><p><strong>- Intune MDM setup (optional)</strong></p><p><strong>- Conditional Access (optional, recommended)</strong></p><p><strong>- Broker apps (Company Portal / Microsoft Authenticator)</strong></p><p><strong>- Troubleshooting (admin-facing)</strong></p><p><br></p><p><strong>Related Guides:</strong></p><ul><li data-pasted="true"><a href="https://www.usehalo.com/guides/2391" target="_blank" rel="noopener noreferrer"><strong>Mobile App</strong></a></li><li data-pasted="true"><a href="https://www.usehalo.com/guides/2667" target="_blank" rel="noopener noreferrer"><strong>Single Sign-On (SSO) in Halo</strong></a></li></ul><p><span style="color: rgb(226, 80, 65);"><strong>Note: The functionality outlined in this guide is available from v2.244+.</strong></span></p><p><br></p><p><span style="font-size: 14pt;"><strong>What is Intune App Protection?</strong></span></p><p data-pasted="true">The Halo mobile app lets Agents connect to your Halo instance from a phone or tablet.</p><p><br></p><p>By default, sign-in uses the same method as the Halo web application, however you can opt to protect this further with Microsoft Intune App Protection so that Halo data on the device is PIN-gated and remotely wipeable. </p><p><br></p><p>There are two sign-in modes, chosen automatically based on your Halo settings:</p><p><br></p><ul><li data-pasted="true"><strong>Standard SSO</strong><span style="white-space:pre;"><strong> (Default):</strong> </span>Normal Halo or Entra sign-in based on how you have configured this in your web application. Halo tokens stored securely on device.</li><li><strong>Intune-protected (MAM):</strong><span style="white-space:pre;"> </span>Entra sign-in via the Microsoft broker app, Intune enrolment, then Halo access - with App Protection policy applied.</li></ul><p><br></p><p data-pasted="true">You can use MAM alone, MDM alone, or both. Most organisations protecting Halo on personal devices want MAM.</p><p> </p><table class="styled-table grid" style="width: 64%; height: 436px;"><colgroup><col style="width: 40.8696%;"></colgroup> <colgroup><col style="width: 59.1304%;"></colgroup><tbody><tr><td style="text-align: center; background-color: rgb(0, 204, 248);"><strong><span style="color: rgb(255, 255, 255); font-size: 12pt;">Your Goal</span></strong></td><td style="text-align: center; background-color: rgb(0, 204, 248);"><strong><span style="color: rgb(255, 255, 255); font-size: 12pt;">Configure</span></strong></td></tr><tr style="height: 47px;"><td id="">Entra sign-in via the Microsoft broker app</td><td><strong data-pasted="true">Entra SSO</strong> + <strong>Halo settings. </strong>This is the baseline method for Sign-in.</td></tr><tr><td>Protect Halo data on personal/BYOD devices</td><td><strong data-pasted="true">MAM </strong>- Configure Entra SSO + Halo Settings + App Protection Policy. </td></tr><tr><td>Guarantee protection is enforced, not just attempted</td><td><p data-pasted="true"><strong>Conditional Access</strong> "Require app protection policy".</p><p><br></p><p data-pasted="true"><strong><em>Note: It is recommended to use Conditional Access to enforce protection. Halo's "Intune enrolment mode = Required" is a convenient in-app fallback, but Intune Conditional Access is the robust, Microsoft-native enforcement point.</em></strong></p></td></tr><tr><td>Force a device to be managed before access</td><td><strong data-pasted="true">MDM </strong>- Configure Entra SSO + MAM (not required by highly recommended) + Device Enrolment + (optionally) Conditional Access.</td></tr><tr style="height: 47px;"><td>Auto-connect the app to a fixed Halo URL on managed devices</td><td><strong data-pasted="true">MDM </strong>- managed config halo_url.</td></tr></tbody></table><p><br></p><p data-pasted="true"><span style="font-size: 14pt;"><strong>Key Terms and Pre-Requisites </strong></span></p><p>The following key terms will be referenced throughout this guide.</p><p><br></p><ul><li data-pasted="true"><strong>Mobile Device Management (MDM)</strong><strong> -</strong> Manages the whole device (device enrolment via Company Portal). Needed only if you want device-wide control, managed-config auto-connect, or device-compliance Conditional Access.</li><li><strong>Mobile Application Management (MAM) </strong><strong>- </strong>Protects app's data only, without device enrolment. PIN, copy/paste and screenshot controls, selective wipe - without managing the device. Ideal for BYOD policies. This is the primary Intune feature for the Halo app. </li><li><strong>Conditional Access (CA</strong><strong>) -</strong> Entra rules gating token issuance.</li><li><strong>Broker App</strong><strong>- </strong>The app that controls authentication on the device. Company Portal (Android) / Microsoft Authenticator (iOS).</li><li><strong>User principal name (UPN) / Entra object id (OID) / Directory id (Tenant ID) </strong><strong>-</strong> User matching for the Halo exchange is by OID + Tenant ID. UPN matching is disabled for multi-tenant security.</li><li><strong>Token exchange </strong><strong>-</strong> The grant Halo uses to swap the Entra-issued token for a Halo session token.</li></ul><p><br></p><p>The following prerequisites must be met to use Intune App Protection.</p><p><br></p><ul><li>Halo web app on version 2.244+ or later. </li><li>Halo mobile applications (iOS or Android) on version 1.5 or later.</li><li>Halo mobile application enabled in your Halo instance.</li><li>Microsoft Entra ID (Azure AD) Tenant with an SSO app registration already configured for Halo. <strong><em>Note: This must be configured in the "Single Sign-on" module <strong data-pasted="true"><em>- not the legacy Entra SSO settings.</em></strong></em></strong></li><li>Halo Agents are synced with Microsoft Entra ID (Azure AD).</li><li>An Intune subscription (Plan 1 or a suite that includes it) and the appropriate admin roles.</li><li>Admin who can grant Tenant admin consent in Entra.</li></ul><p>If some Agents in your Instance do not have Intune they can still use MSAL sign-in with the Broker App (providing enrolment is made optional in Halo). Those Agents can sign in with MSAL flow and have no MAM policies apply, and those with Intune and targeted with a MAM policy would still have these apply to them. </p><p><br></p><p data-pasted="true"><span style="font-size: 14pt;"><strong>Required Microsoft Configuration</strong></span></p><p data-pasted="true">Configuration happens in up to three places. Microsoft Entra ID (Halo SSO app registration), and Halo Configuration are required to enable sign-in with a Microsoft broker app. Intune configuration is optional, but MAM policies are recommended to allow enrolment with Intune.</p><p><br></p><p data-pasted="true">At sign-in, the app reads your instance's settings, and if Intune is enabled, it authenticates against your SSO app registration through the Microsoft broker, enrols the app with Intune, then exchanges that token for a Halo session.</p><p><br></p><p>If no broker app (Intune Company Portal on Android, Microsoft Authenticator on iOS) is installed on the device, then sign-in can still be completed but, Intune enrolment cannot be completed.</p><p><br></p><p data-pasted="true">These steps let the Halo mobile app use a native Microsoft broker app to request a token scoped to your SSO application, which Halo then validates and exchanges for a Halo session.</p><p><br></p><p><span style="font-size: 12pt;"><strong>Prerequisites:</strong></span></p><ul><li>Standard Entra SSO for Halo must already be working. The steps below modify that same SSO app registration.<br>To configure Single Sign-On with Entra in Halo, please see the following guide linked <a href="https://www.usehalo.com/guides/2667" target="_blank" rel="noopener noreferrer">here</a>. </li></ul><p><br></p><p data-pasted="true">In the Microsoft Entra admin center > Entra ID > App registrations, open your Halo SSO application.</p><p>Under Manage > Expose an API, confirm the Application ID URI. By default, Entra proposes api://{your-sso-app-client-id}. Keep the default unless you have a reason to use a custom URI or you already have a custom URI configured. If using a Custom URI, whatever you set here must match what Halo validates against. Set the matching Application ID URI value in the Single Sign-On tab of the Entra Integration in Halo.</p><p><br></p><p>Select "Add a scope" and create a scope with:</p><ul><li>Scope name: access_as_user</li><li>Who can consent: Admins and users (or Admins only, per your policy)</li><li>Display name/description: e.g. "Access Halo as a user"</li><li>State: Enabled</li><li>Save. </li></ul><p>The full scope string is the Application ID URI + /access_as_user.</p><p><br></p><p><strong><img data-fr-image-pasted="true" src="https://halo.haloservicedesk.com/api/attachment/image?token=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpZCI6ImJlYzhlZTVlLWYyYjAtNDkyZC04MzNlLTYzOWVjMTM4MjUzNiJ9.hPqGbeKmEHoaNKXMETZfhio1zhNXv8WbgAPy77bSynI" width="1119" style="box-sizing: inherit; border-style: none; cursor: pointer; padding: 0px 1px; user-select: none; text-align: left; color: rgb(0, 0, 0); font-family: sans-serif; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; white-space: normal; background-color: rgb(255, 255, 255); text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial; width: 1121px; height: 582.957px; max-width: none !important;" data-pasted="true" class="fr-fil fr-dib" height="583"></strong></p><p data-pasted="true"><span style="font-size: 10pt;" data-pasted="true"><strong>Fig 1. Exposing an API</strong></span></p><p><br></p><p><strong><em>Note: If you changed the Application ID URI from the default, you must also set the matching value in Halo.</em></strong></p><p data-pasted="true"><br></p><p data-pasted="true">Still under Expose an API, under Authorized client applications, select "Add a client application", and create an application with:</p><ul><li>Client ID: 65d704f3-fff1-42e0-a7bb-cec47b215837 (the Halo Mobile app - a multi-tenant app published in Halo's own tenant).</li><li>Tick the access_as_user scope you created.</li><li>Add application.</li></ul><p data-pasted="true">This pre-authorises the mobile app so your users aren't prompted to consent to the scope individually.</p><p><br></p><p>In the SSO application, open Manifest.</p><ul><li>In the Microsoft Graph App Manifest, ensure the requestedAccessTokenVersion is set to 2. This may not show, and you may only have access to the AAD Graph App Manifest or the Microsoft Graph App Manifest; in which case skip this step.</li><li>Save.</li></ul><p><img src="https://halo.haloservicedesk.com/api/attachment/image?token=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpZCI6ImQ0YTEzOTY4LTkwZTMtNGM4OS04ZWZiLWU1YTc0MGE5ZmVhYSJ9.WSZVaK_MWSdLIfTki0wJhwWPE4qnSlt0If9TUDmfubM" class="fr-fic fr-fil fr-dib" width="1329" style="width: 1331px; height: 488.467px;" height="488"></p><p data-pasted="true"><span style="font-size: 10pt;" data-pasted="true"><strong>Fig 2. Setting the requestedAccessTokenVersion</strong></span></p><p><br></p><p data-pasted="true">The Halo Mobile app requests the delegated permissions User.Read and DeviceManagementManagedApps.ReadWrite (the latter allows the app to enrol itself for Intune App Protection). These typically require tenant admin consent.</p><p><br></p><p>Grant consent from Entra ID > Enterprise applications > Halo Mobile > Permissions > Grant admin consent, or use the consent link Halo provides on the Advanced Settings page in the "Mobile App" section (this will show when "Enable Intune App Protection (MAM) for the Mobile App" is enabled).</p><p><img src="https://halo.haloservicedesk.com/api/attachment/image?token=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpZCI6IjkwMjMzZmVhLTI2YzMtNDc0Zi1hMTU0LTk0MWY4OTVkNGFhMiJ9.x1vfR2tlK4cyVr5hEMroomCI4Ol31_7CPHDea3WXUxg" class="fr-fic fr-fil fr-dib" width="437" height="750"></p><p data-pasted="true"><span style="font-size: 10pt;" data-pasted="true"><strong>Fig 3. Granting permissions</strong></span></p><p><br></p><p data-pasted="true"><span style="font-size: 12pt;"><strong>Halo Mobile App identifiers</strong></span></p><table class="styled-table grid" style="width: 64%;"><colgroup><col style="width: 40.8696%;"></colgroup> <colgroup><col style="width: 59.1304%;"></colgroup><tbody><tr><td style="text-align: center; background-color: rgb(0, 204, 248);"><strong><span style="color: rgb(255, 255, 255); font-size: 12pt;">Item</span></strong></td><td style="text-align: center; background-color: rgb(0, 204, 248);"><strong><span style="color: rgb(255, 255, 255); font-size: 12pt;">Value</span></strong></td></tr><tr><td id="">Halo Mobile app (client id)<span style="white-space:pre;" data-pasted="true"> </span></td><td>65d704f3-fff1-42e0-a7bb-cec47b215837</td></tr><tr><td>App bundle / package id<span style="white-space:pre;" data-pasted="true"> </span></td><td>com.haloservicesolutions</td></tr><tr><td>Delegated permissions</td><td>User.Read, DeviceManagementManagedApps.ReadWrite</td></tr><tr><td>Scope to expose</td><td>{Application ID URI}/access_as_user</td></tr><tr><td>Managed config key</td><td>halo_url</td></tr></tbody></table><p><br></p><p><br></p><p data-pasted="true"><span style="font-size: 14pt;"><strong>Halo Configuration</strong></span></p><p data-pasted="true">Head to Configuration > Advanced Settings. Click "Enable Intune App Protection (MAM) for the Mobile App". This turns on the Intune-protected sign-in flow for your instance. When enabled (and an SSO record is selected), the app stops using the standard authorization-code flow and routes through Intune.</p><p><br></p><p data-pasted="true">Select which Entra Single Sign-on record the mobile app should use for its MSAL sign-in in the "Mobile app single sign-on configuration (Microsoft Enta) field". The app takes the client id and tenant id from this record.</p><p><br></p><p>Set the Intune enrolment mode to either:</p><ul><li>Required - in-app gate: users cannot sign in until Intune enrolment succeeds.</li><li>Optional - enrolment is attempted; if it fails, the user is still allowed in (with messages shown in some cases).</li></ul><p data-pasted="true">Conditional Access, if configured, overrides this and makes enrolment mandatory regardless. Use this setting as a fallback where Conditional Access isn't in place.</p><p><br></p><p>Note that a MAM policy targeting the agents using the mobile app will need to be configured if setting enrolment to required.</p><p><br></p><p><img src="https://halo.haloservicedesk.com/api/attachment/image?token=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpZCI6ImI3MTA2NWQyLWI0NzUtNDk3MC04MzJkLWJiNjVlNzFlOGQwMiJ9.xb_bGz7365iZ6cOYvNTCBwJbBNXPmbJqRFoR-tR9WY0" class="fr-fic fr-fil fr-dib" width="989" style="width: 991px; height: 871.314px;" height="871"></p><p data-pasted="true"><span style="font-size: 10pt;" data-pasted="true"><strong>Fig 4. Enable Intune App Protection (MAM) for the Mobile App</strong></span></p><p><br></p><p>If using a customised Application ID URI, you will now need to set the "Application ID URI" to match the custom Application ID URI on your SSO app registration. Leave blank to use the Entra default (api://{client-id}). This is found on the Single Sign-On Configuration record in Configuration > Integrations > Single Sign-On.</p><p><br></p><p data-pasted="true">The app reads its configuration from /api/InstanceInfo, which exposes the resulting settings to the app: mobileapp_enable_mam, mobileapp_azure_tenant_id, mobileapp_api_scope (api://.../access_as_user), and mobileapp_intune_enrollment_mode.</p><p><br></p><p><img src="https://halo.haloservicedesk.com/api/attachment/image?token=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpZCI6Ijk4MmNmOTdkLTlkYjYtNGZlYS1hYWI5LTc3MjA2ZTU4NzFmOCJ9.LG4ZYcmTNHMgVwQvPNJE0p2wTXBGKJQ1-ukurjAZGIc" class="fr-fic fr-fil fr-dib" width="720" style="width: 722px; height: 463.871px;" height="464"></p><p data-pasted="true"><span style="font-size: 10pt;" data-pasted="true"><strong>Fig 5. Application ID URI</strong></span></p><p><br></p><p data-pasted="true"><span style="font-size: 14pt;"><strong>Intune App </strong></span><span style="color: rgb(0, 0, 0); font-size: 14pt; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: left; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; white-space: normal; background-color: rgb(255, 255, 255); text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial; float: none; display: inline !important;" data-pasted="true"><strong>Protection</strong></span><span style="font-size: 14pt;"><strong> (MAM) setup</strong></span></p><p>MAM allows you to protect data on the app without having to enrol the devices. This allows Agents to bring their own device and access the Halo app while having protection policies in place. Intune is required for MAM despite not requiring the device to be enrolled. Using MAM only (without MDM) gives a small improvement in User experience. Agents only need to enter their Halo URL and then are prompted to sign in with MSAL within the App via the Broker.</p><p><br></p><p>If you are using another tool for device enrolment you can still use Intune MAM, as MAM only requires Users Intune licence and the Broker App, not full device enrolment, allowing device enrolment by another provider.</p><p><br></p><p><span style="font-size: 12pt;"><strong>Prerequisites</strong></span></p><ul><li>Licensing: Intune Plan 1 (or a suite that includes it) with MAM capability. Device-only licences do not support App Protection Policies. Your Halo agents that log into the Mobile app will require an Intune licence.</li><li>Admin role: Intune Administrator / Global Administrator (or an Application Manager RBAC role with Managed-apps permissions).</li><li>Broker app on the device: Company Portal (Android) / Microsoft Authenticator (iOS). Enrolment requires the broker.</li></ul><p><br></p><p><span style="font-size: 12pt;"><strong>Create App Protection Policies</strong></span></p><p data-pasted="true">Create one policy per platform:</p><p><br></p><p>In the Microsoft Intune admin center, head to Apps > Protection (a.k.a. App protection policies) > Create policy > choose iOS/iPadOS or Android.</p><p><br></p><p><img src="https://halo.haloservicedesk.com/api/attachment/image?token=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpZCI6ImRjNjdiM2YzLTA2NTMtNDhkNC1hOWI2LTg1YTczMjQ1NDg4OCJ9.7I7NMe9qH6jUihFTv3OSTHMcxoOiSTl1ecSD_66k-Ew" class="fr-fic fr-fil fr-dib" width="1106" style="width: 1108px; height: 383.938px;" height="384"></p><p data-pasted="true"><span style="font-size: 10pt;" data-pasted="true"><strong>Fig 6. App Protection Policies</strong></span></p><p><br></p><p>1. Set a name (e.g. Halo - iOS - APP) and description for your policy. </p><p>2. Click "Next", and select the Halo app. You can add the Halo app to Intune (required if you plan on using MDM) or add it as a custom app by bundle id/package name (com.haloservicesolutions).</p><p>3. Once set, click "Next" to get to the Data Protection page section. Here configure DLP controls (For example: cut/copy/paste, save-as, "send org data to other apps").</p><p>4. Next set your Access requirements: PIN, biometrics, credentials.</p><p>5. Click "Next" to get to the Conditional launch section. Here set a minimum of: OS/app/SDK version, jailbreak/root checks, and the action on failure (block/wipe).</p><p>6. On the final page, assign to the policy to the relevant User groups.</p><p>7. Click "Create".</p><p><br></p><p>For more information on creating App Protection Policies please see Microsoft's guide linked <a href="https://learn.microsoft.com/en-us/intune/app-management/protection/create-policy" target="_blank" rel="noopener noreferrer">here</a>. </p><p><br></p><p><strong><em>Note: App protection policies take time to apply and are delivered/refreshed on app check-in, so newly-set controls (clipboard, screenshots, PIN) may not be active immediately after first sign-in.</em></strong></p><p><br></p><p><span style="font-size: 14pt;"><strong>Intune MDM setup (optional)<br></strong></span></p><p data-pasted="true">Only needed for device-level management, managed-config auto-connect, or device-compliance Conditional Access. This method requires you to be managing your devices through Intune. Using MDM has the largest improvement on User experience. Users already have Halo pushed to their device, when they open it the first time, due to managed configuration it already knows the Halo URL. It then signs in using MSAL. Since the User is already signed into the Broker App, this happens automatically.</p><p><br></p><p data-pasted="true">Add the Halo app to Intune (Intune > Apps)</p><p><br></p><ul><li><strong>iOS</strong>: add the App Store app (and assign it); the Halo bundle id is com.haloservicesolutions.</li><li><strong>Android</strong>: add via Managed Google Play; app id com.haloservicesolutions.</li></ul><p data-pasted="true">Enrol devices via Company Portal (Android Enterprise / iOS Automated or Device Enrolment). See <a href="https://learn.microsoft.com/en-us/intune/device-enrollment/enroll-devices?tabs=work-profile%2Ccorporate-owned-apple%2Cautomatic-enrollment" target="_blank" rel="noopener noreferrer">Microsoft documentation</a> on how to configure this.</p><p><br></p><p data-pasted="true"><span style="font-size: 12pt;"><strong>Auto-connect via managed config (halo_url)</strong></span></p><p>You can pre-set and lock the Halo URL so the app skips the "enter your Halo URL" screen.</p><p><br></p><p><strong><em>Note: This uses the Managed devices app configuration channel, which requires an MDM-enrolled device. It does not work through the MAM-only channel. BYOD/MAM-only users type the URL as normal.</em></strong></p><p><br></p><p>Console: Apps > Configuration > Create > Managed devices, one policy per platform, targeting the Halo app, with key halo_url = your Halo URL (e.g. https://mycompany.usehalo.com).</p><p><br></p><p>When this is set, the "Enter your Halo URL" screen will not show, and it will instead show a "Connecting to Halo" screen and auto-connect to the Halo instance specified.</p><p><br></p><p><span style="font-size: 14pt;"><strong>Conditional Access (optional, recommended)<br></strong></span></p><p data-pasted="true">Conditional access (CA) is the Microsoft-native way to enforce that the app is protected before it can obtain a token.</p><p data-pasted="true">With a "Require app protection policy" Conditional access policy in place, Entra will not issue a token to the app until it is enrolled and protected. The app detects this and drives the user through Intune enrolment automatically, then completes sign-in.</p><p><br></p><p><span style="font-size: 12pt;"><strong>Creating the Policy</strong></span></p><p>1. Microsoft Intune Admin Center > Endpoint security > Conditional access, Create new policy (or via Entra ID > Conditional Access).</p><p>2. Users: Target the relevant users/groups.</p><p>3. Target resources: The cloud app(s) the policy protects. The target for this is your Halo SSO app (not the Halo Mobile application).</p><p>4. Conditions: Set Device platforms (iOS, Android).</p><p>5. Grant: Require app protection policy.</p><p>6. Enable and create.</p><p><br></p><p data-pasted="true"><strong><em>Note: App Protection Policies must exist and be assigned before turning this on, or users will be blocked. App Protection Policies take time to apply.</em></strong></p><p data-pasted="true"><br></p><p>A Conditional Access policy that requires a compliant/managed device ("Require device to be marked as compliant"/hybrid-joined) cannot be satisfied by MAM app protection - the device itself must be MDM-enrolled via Company Portal. The Halo app detects this case and tells the user to enrol their device; it cannot do it for them. Only use device-compliance CA if you're running full MDM. </p><p><br></p><p data-pasted="true"><strong><span style="font-size: 12pt;">Conditional Access vs Halo enrolment mode</span></strong></p><table class="styled-table grid" style="width: 70%;"><colgroup><col style="width: 39.2438%;"></colgroup> <colgroup><col style="width: 26.5971%;"></colgroup> <colgroup><col style="width: 34.1591%;"></colgroup><tbody><tr><td style="text-align: center; background-color: rgb(0, 204, 248);"><strong><span style="color: rgb(255, 255, 255); font-size: 12pt;">Setting</span></strong></td><td style="text-align: center; background-color: rgb(0, 204, 248);"><strong><span style="color: rgb(255, 255, 255); font-size: 12pt;">Enforcement point</span></strong></td><td style="text-align: center; background-color: rgb(0, 204, 248);"><strong data-pasted="true"><span style="color: rgb(255, 255, 255); font-size: 12pt;">Notes</span></strong></td></tr><tr><td id="">CA "Require app protection policy"</td><td>Microsoft Entra</td><td>Recommended. Robust; overrides Halo enrolment mode.</td></tr><tr><td>Halo enrolment mode = Required</td><td>Halo app</td><td>Fallback where CA isn't configured.</td></tr><tr><td>Halo enrolment mode = Optional</td><td>Halo app</td><td>Attempts enrolment; allows access if it fails.</td></tr></tbody></table><p><br></p><p><br></p><p><span style="font-size: 14pt;"><strong>Broker apps (Company Portal / Microsoft Authenticator)<br></strong></span></p><p data-pasted="true">Intune enrolment and CA remediation require a Microsoft broker app on the device:</p><p><br></p><ul><li><strong>Android</strong>: Intune Company Portal.</li><li><strong>iOS</strong>: Microsoft Authenticator.</li></ul><p>Without the broker, sign-in may fall back to the browser but enrolment cannot complete. If a user is missing it, the app prompts them to install the correct one from the store. Consider deploying the broker to users in advance.</p><p><br></p><p><span style="font-size: 14pt;"><strong>Troubleshooting (admin-facing)</strong></span></p><style>
.styled-table thead tr th:first-child {
width: 28em; min-width: 28em; max-width: 28em; word-break: break-word;
}
.styled-table thead tr th:nth-child(2) {
width: 8em; min-width: 8em; max-width: 8em; word-break: break-word;
}
.styled-table thead tr th:nth-child(3) {
width: 8em; min-width: 8em; max-width: 8em; word-break: break-word;
}
.styled-table thead tr th:nth-child(4) {
width: 8em; min-width: 8em; max-width: 8em; word-break: break-word;
}
.styled-table thead tr th:nth-child(5) {
width: 8em; min-width: 8em; max-width: 8em; word-break: break-word;
}
.styled-table {
border-radius: 5px; border-collapse: collapse; margin: 25px 0; font-size: 1rem; font-family: "Poppins", sans-serif, "Roboto"; width: 100%; box-shadow: 0 0 20px rgba(0, 0, 0, 0.15);
}
.styled-table thead tr {
text-align: left; border-radius: 5px;
}
.styled-table th {
border-radius: 5px; padding: 12px 15px;
}
.styled-table td {
padding: 12px 15px;
}
.styled-table tbody tr {
border-bottom: 1px solid #dddddd;
}
.styled-table tbody tr:nth-of-type(even) {
background-color: #fafafa;
}
.styled-table tbody tr:last-of-type {
border-bottom: 2px solid $orcolor;
}
</style><p><br></p><table class="styled-table grid" style="width: 79%; height: 515px;"><colgroup><col style="width: 29.3836%;"></colgroup> <colgroup><col style="width: 40.6849%;"></colgroup> <colgroup><col style="width: 29.9315%;"></colgroup><tbody><tr style="height: 50.8889px;"><td style="text-align: center; background-color: rgb(0, 204, 248);"><strong><span style="color: rgb(255, 255, 255); font-size: 12pt;">User sees</span></strong></td><td style="text-align: center; background-color: rgb(0, 204, 248);"><strong data-pasted="true"><span style="color: rgb(255, 255, 255); font-size: 12pt;">Likely cause</span></strong></td><td style="text-align: center; background-color: rgb(0, 204, 248);"><strong data-pasted="true"><span style="color: rgb(255, 255, 255); font-size: 12pt;">Fix</span></strong></td></tr><tr style="height: 46.8889px;"><td id="">"Needs admin approval" at sign-in</td><td>Admin consent not granted.</td><td>Grant tenant admin consent for Halo Mobile.</td></tr><tr style="height: 69.8889px;"><td>"Install Company Portal / Microsoft Authenticator"</td><td>Broker app missing.</td><td>Install the correct broker.</td></tr><tr style="height: 46.8889px;"><td>No Intune licence / not licensed</td><td>User has no Intune licence, or no APP assigned.</td><td>Assign an Intune licence and an App Protection Policy.</td></tr><tr style="height: 69.8889px;"><td>Enrolment/setup not completed by your organisation</td><td>"Expose an API" / client authorisation/consent incomplete.</td><td>Recheck the Expose an API scope, Client authorisation, and admin consent steps.</td></tr><tr style="height: 64.8889px;"><td>Device must be enrolled (compliance)</td><td><p data-pasted="true">Device-compliance CA in place; device not MDM-enrolled.</p></td><td>User enrols device via Company Portal, or relax the CA.</td></tr><tr style="height: 46.8889px;"><td>"Sign in again - new policies"</td><td>Halo MAM/SSO settings changed since last sign-in.</td><td>Expected after config changes; user re-signs in.</td></tr><tr style="height: 69.8889px;"><td>Tenant mismatch error</td><td>Signed-in account isn't in the SSO tenant configured in Halo.</td><td>Confirm the SSO record/tenant.</td></tr><tr style="height: 46.8889px;"><td>Unable to validate token</td><td>Token exchange failed, likely configuration not completed or Application ID URI doesn't match between Halo and Entra</td><td>Recheck the Application ID URI records match.</td></tr><tr><td>Agent not found with Azure OID</td><td>The Entra user/tenant combo does not exist in Halo as an Agent account</td><td>Run an Entra sync for the tenant, and sync Entra users to Halo agent accounts. Verify the agent can log into the Web application with Entra SSO.</td></tr></tbody></table>