Microsoft Intune (MAM)
Feature video
Who is this for?
- Companies whose staff use Leexi on their personal phone (BYOD) or on unmanaged devices.
- Security and IT administrators who run Microsoft Intune and want Leexi covered like any other business app.
Permissions and licenses
- Requires: Governance
- Requires the Governance add-on, available on any plan.
- Page restricted to people allowed to edit company settings.
- Every user concerned needs a Microsoft Intune licence and a Microsoft Entra account.
- Phones need the Leexi mobile app in version 1.14.0 or later, plus Microsoft Authenticator (iPhone) or Company Portal (Android).
How to use it
Check that the Governance add-on is active
Intune protection is part of the Governance add-on. Confirm it is active on your subscription before you start.
Prepare your Microsoft tenant
Three operations belong to your Microsoft Entra and Intune administrator: authorising the Leexi application in your tenant, creating the app protection policies that target Leexi, then assigning them to the users concerned. The step-by-step details are in the Microsoft Intune guide.
Open the page
Go to Settings > Governance > SSO / SCIM, section MAM setup.
Enter the Entra tenant ID
Enter your organisation's Entra tenant ID: it is the identifier of your Microsoft directory, which your administrator finds on the Microsoft Entra overview. Leexi will only accept Microsoft sign-ins coming from that tenant — an identity from another directory is refused, even if it carries one of your users' email addresses.
Wait for the phones to update
A version of the mobile app earlier than 1.14.0 cannot open the Microsoft sign-in this setting requires: its users would no longer be able to sign in. Make sure your users have installed version 1.14.0 or later before the next step.
Enable Intune sign in
Turn on Require Microsoft Intune sign in for the mobile app and confirm. From then on, on mobile, typing a password or using a Google or Microsoft button redirects to the Microsoft sign-in: it is the only way in. Web, the desktop app and Teams do not change.
Check on a phone
Sign in to the mobile app with your email address: the Microsoft window opens, then the app asks you to set the PIN code your policy requires. Your device appears a few minutes later in the app protection status of the Intune console.
Going further
- The protection applies to the app, not to the phone: Intune sees neither the other apps nor the personal data on the device.
- A selective wipe from the Intune console removes the Leexi session and every recording still on the phone, including those not yet uploaded.
- Signing out of the app removes the account from Intune management; the protection is put back in place at the next sign-in.
- Downloading recordings to the phone disappears when your policy blocks saving organisation data to personal storage.
Frequently asked questions
Things to watch out for
- Enable the setting only once all your mobile users have the app in version 1.14.0 or later: earlier versions can no longer sign in.
- The
Entra tenant IDmust be exact; a wrong identifier blocks every mobile sign-in. - The authorisation of the Leexi application in your tenant must be granted by an administrator before a user's first sign-in.
- A selective wipe also deletes the recordings that had not yet been uploaded to Leexi.
- Turning the setting on immediately closes the mobile sessions already open: each user is sent back to the sign-in screen, signs in again with their Microsoft account and is enrolled in Intune. Web and desktop sessions are not affected. Warn your users before enabling it.
- Signing out of the mobile app also deletes the recordings that had not yet been uploaded to Leexi, like a selective wipe does: ask your users to upload their recordings before signing out.
- Intune encrypts the recordings and pictures stored on the phone, on Android and on iPhone. On iPhone the recording metadata (name, date, upload status) stays unencrypted and relies on the device encryption enforced by the policy's PIN.