Microsoft Intune
Who is this for?
- Microsoft Entra and Intune administrators rolling Leexi out on personal or unmanaged phones.
Permissions and licenses
- Governance add-on active on your Leexi subscription.
- Global Administrator (or Privileged Role Administrator) role in Microsoft Entra, and Intune administration rights.
- A Microsoft Intune licence for every user concerned.
- Rights to edit company settings in Leexi.
How to use it
Authorise the Leexi application in your tenant
Leexi is a multi-tenant Microsoft Entra application: before a user can sign in to it with their Microsoft account and be protected by Intune, an administrator has to grant consent on behalf of your whole organisation.
Open the following link in your browser, sign in with a Global Administrator account of your tenant, then accept:
https://login.microsoftonline.com/organizations/v2.0/adminconsent?client_id=e528cc57-f5e1-4501-a89e-d5b209af4f16&scope=https%3A%2F%2Fgraph.microsoft.com%2FUser.Read%20openid%20email%20https%3A%2F%2Fmsmamservice.api.application%2FDeviceManagementManagedApps.ReadWrite&redirect_uri=https%3A%2F%2Fapp.leexi.ai%2Fentra-admin-consent
The consent screen lists exactly what Leexi asks for: reading the basic profile and email address of the user signing in (User.Read, openid, email) and enrolling the app in Intune mobile application management (DeviceManagementManagedApps.ReadWrite). Leexi gets no other access to your directory.
After accepting, you are redirected to a Leexi confirmation page that shows your tenant identifier with a copy button — keep it, it is needed in the next step.
You can also grant this consent from the portal: in entra.microsoft.com, open Applications > Enterprise applications, select Leexi, then Security > Permissions and click Grant admin consent for [your organisation]. The application only appears in that list after a first sign-in attempt by one of your users.
Find your tenant ID
If you did not note the identifier returned in the previous step, open entra.microsoft.com: the Overview of your organisation shows the Tenant ID, a value of the form 00000000-0000-0000-0000-000000000000.
Create the iOS app protection policy
In the Intune admin center, open Apps > App protection policies, click Create policy and choose iOS/iPadOS.
Name the policy (for example Leexi mobile - iOS). At the Apps step, set Target policy to to Selected apps, then click Select custom apps and enter the bundle ID ai.leexi.mobile.
The Leexi app is not yet listed in Intune's catalogue of protected apps, so this identifier-based targeting is what designates it.
Intune does not accept a custom app in a policy that targets All Apps, Microsoft Apps or Core Microsoft Apps: create a policy dedicated to Leexi rather than adding it to an existing one.
Create the Android app protection policy
Repeat the operation choosing Android, with a distinct name (for example Leexi mobile - Android). At the Apps step, set Target policy to to Selected apps, then enter the package name ai.leexi.mobile in Select custom apps.
Choose the protection rules
Both policies accept the same settings; these are the ones Leexi enforces:
- Data protection:
Save copies of org dataset to Block removes recording downloads to the phone;Restrict cut, copy and pastelimits the clipboard;Screen captureset to Block (Android) forbids screenshots. - Access requirements:
PIN for accessset to Require asks for a code when the app opens. - Conditional launch: leave the default values, they are suitable.
Do not make Managed browser mandatory for opening links: Leexi does not support that rule yet.
Assign the policies
At the Assignments step, add the Microsoft Entra group of users to protect, then create the policy. Every member needs an Intune licence; the app does not enrol for an unlicensed user or one outside the assigned groups. The device type is no longer chosen at the Apps step but here, with a filter: without a filter, the policy covers every device, including unenrolled personal phones; if you add one, keep unmanaged devices included.
Prepare the phones
Users install the Leexi app in version 1.14.0 or later together with Microsoft Authenticator on iPhone or Company Portal on Android: Intune relies on these apps to enrol Leexi in the protection.
Enter the tenant and enable Intune sign in in Leexi
In Leexi, open Settings > Governance > SSO / SCIM, section MAM setup. Enter the Entra tenant ID noted above. Once all your mobile users are on version 1.14.0 or later, turn on Require Microsoft Intune sign in for the mobile app and confirm.
On mobile, signing in to Leexi now goes exclusively through Microsoft: when they type their email address, users are sent to Microsoft, then the app asks for the PIN code your policy requires. Web, the desktop app and Teams do not change.
Going further
Check the enrolment
In the Intune admin center, Apps > Monitor > App protection status lists the users and devices on which Leexi is protected, with the policy applied and the date of the last sync.
Wipe remotely
Apps > App selective wipe removes the Leexi session and every recording on the phone, including those not yet uploaded. The wipe runs the next time the app is opened, even if it had been closed in between.
Things to watch out for
- Enable Intune sign in within Leexi only once all your mobile users have the app in version 1.14.0 or later: earlier versions can no longer sign in.
- A wrong
Entra tenant IDblocks every mobile sign-in: Leexi refuses any Microsoft account coming from another tenant. - Without admin consent, the first sign-in fails with a Microsoft message asking for an administrator's approval.
- Without Authenticator or Company Portal on the phone, the Microsoft sign-in succeeds but the Intune enrolment does not happen.
- Your other app protection policies (All Apps, Microsoft Apps…) never target Leexi, which is a custom app: they coexist with the Leexi policy on the same devices. If two policies target Leexi for the same user, Intune applies the most restrictive value of each conflicting setting.
- A Microsoft Entra Conditional Access policy that requires a compliant or Microsoft Entra hybrid joined device blocks sign-in from an unenrolled personal phone, even with the Leexi policy deployed: Intune MAM does not enrol the device in MDM, so it never becomes compliant.
- The Leexi mobile app requires iOS 17 or later.
- Turning the setting on immediately closes the mobile sessions already open: each user is sent back to the sign-in screen, signs in again with their Microsoft account and is enrolled in Intune. Web and desktop sessions are not affected. Warn your users before enabling it.
- Signing out of the mobile app also deletes the recordings that had not yet been uploaded to Leexi, like a selective wipe does: ask your users to upload their recordings before signing out.
- Intune encrypts the recordings and pictures stored on the phone, on Android and on iPhone. On iPhone the recording metadata (name, date, upload status) stays unencrypted and relies on the device encryption enforced by the policy's PIN.