<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>article MAM configuration for Qlik Analytics mobile app with Intune in Official Support Articles</title>
    <link>https://community.qlik.com/t5/Official-Support-Articles/MAM-configuration-for-Qlik-Analytics-mobile-app-with-Intune/ta-p/2550335</link>
    <description>&lt;P&gt;This article documents an example of how to configure&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;MAM control&lt;/STRONG&gt;&lt;/FONT&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;of the&lt;FONT color="#339966"&gt;&lt;STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Qlik Analytics Mobile app&lt;/STRONG&gt;&lt;/FONT&gt;.&amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE class="quote"&gt;&lt;STRONG&gt;The example is provided as is.&lt;/STRONG&gt; Qlik does not offer guidance on configuring Entra Conditional Access policies or broader Intune deployments. For those details, see&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/intune/device-security/conditional-access-integration/overview" target="_blank" rel="noopener nofollow noreferrer" aria-describedby="audioeye_new_window_message"&gt;Learn about Conditional Access and Intune&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;in the Microsoft documentation.&lt;/BLOCKQUOTE&gt;
&lt;P&gt;As per&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://help.qlik.com/en-US/cloud-services/Subsystems/Hub/Content/Sense_Hub/Admin/configure-mobile-app.htm" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Securing and configuring the Qlik Analytics mobile app with Microsoft Intune&lt;/STRONG&gt;&lt;/A&gt;&amp;nbsp;and the section titled&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://help.qlik.com/en-US/cloud-services/Subsystems/Hub/Content/Sense_Hub/Admin/configure-mobile-app.htm#:~:text=Conditional%20Access%20policy%20guidance" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Conditional Access scope considerations&lt;/STRONG&gt;&lt;/A&gt;, the authentication flow for the mobile app follows the Qlik Cloud IDP OIDC progression.&lt;/P&gt;
&lt;P&gt;The pattern and steps outlined in this article are the working example Qlik used in verification testing of the Conditional Access control for the Qlik Analytics mobile app policy deployment. Your own policy and configuration definitions may vary, and Microsoft documentation or support should be contacted for further help that is specific to your Entra and Intune environments.&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Identify the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;IDP App Registration&lt;/STRONG&gt;:&lt;BR /&gt;&lt;BR /&gt;
&lt;OL class="lia-list-style-type-lower-alpha"&gt;
&lt;LI&gt;&lt;SPAN&gt;Navigate to&amp;nbsp;&lt;STRONG&gt;Entra ID&lt;/STRONG&gt;&amp;nbsp;→&amp;nbsp;&lt;STRONG&gt;App registrations&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Locate the&amp;nbsp;&lt;STRONG&gt;OIDC IDP app&lt;/STRONG&gt;&amp;nbsp;registration and note the&amp;nbsp;&lt;STRONG&gt;Application (client) ID&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Confirm this is the client ID presenting itself during the OIDC browser redirect&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Modify Existing&amp;nbsp;&lt;STRONG&gt;All Cloud Apps&lt;/STRONG&gt;&amp;nbsp;Policy&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;
&lt;OL class="lia-list-style-type-lower-alpha"&gt;
&lt;LI&gt;Navigate to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Protection&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;→&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Conditional Access&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;→&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Policies&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Open the existing&amp;nbsp;&lt;STRONG&gt;All Cloud Apps&lt;/STRONG&gt;&amp;nbsp;policy&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Go to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Cloud apps or actions&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;→&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Exclude&amp;nbsp;&lt;/STRONG&gt;and&amp;nbsp;add the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;IDP app registration client ID&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;In&amp;nbsp;&lt;STRONG&gt;Conditions&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;→&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Device platforms: Any device&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;In&amp;nbsp;&lt;STRONG&gt;Conditions&lt;/STRONG&gt;&amp;nbsp;→&amp;nbsp;&lt;STRONG&gt;Client apps: Browser&lt;/STRONG&gt;&amp;nbsp;&lt;STRONG&gt;+ Mobile apps and desktop clients&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Grant access&lt;/STRONG&gt;:&amp;nbsp;Require device to be marked as compliant&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Save&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and set to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Report-only&lt;/STRONG&gt;&amp;nbsp;at first&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;/LI&gt;
&lt;LI&gt;Create a new&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Targeted Policy for IDP Registration&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;
&lt;OL class="lia-list-style-type-lower-alpha"&gt;
&lt;LI&gt;&lt;SPAN&gt;Create a new&amp;nbsp;&lt;STRONG&gt;CA policy&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Set&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Users&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;to the same scope as the existing policy&lt;/LI&gt;
&lt;LI&gt;Set&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Cloud apps&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;to include IDP app registration only&lt;/LI&gt;
&lt;LI&gt;In&amp;nbsp;&lt;STRONG&gt;Conditions&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;→&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Device platforms: iOS, Android, macOS, Linux&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;In&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Conditions&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;→&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Client apps: Browser + Mobile apps and desktop clients&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Grant access:&amp;nbsp;&lt;/STRONG&gt;Require multifactor authentication (MFA)&lt;/LI&gt;
&lt;LI&gt;Set to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Report-only&lt;/STRONG&gt;&amp;nbsp;at first&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;/LI&gt;
&lt;LI&gt;Validate in&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Report-Only&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;before enabling&lt;BR /&gt;&lt;BR /&gt;
&lt;OL class="lia-list-style-type-lower-alpha"&gt;
&lt;LI&gt;Navigate to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Sign-in logs&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Attempt the auth flow on a test device&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Check the sign-in log entry for the OIDC redirect leg&lt;/LI&gt;
&lt;LI&gt;Confirm report-only shows that the existing policy (Step 2) would have passed for a compliant device excluded&lt;/LI&gt;
&lt;LI&gt;Confirm report-only shows that the new policy (Step 3) would have passed for MFA on Authentication via Authenticator&lt;/LI&gt;
&lt;LI&gt;Once both are confirmed, switch both policies to enabled&lt;/LI&gt;
&lt;/OL&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;STRONG&gt;On the test device:&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Clear app session state and OIDC tokens&lt;/LI&gt;
&lt;LI&gt;Re-attempt the full auth flow end-to-end&lt;/LI&gt;
&lt;LI&gt;Confirm OIDC leg completes → local token issued -&amp;gt; on Authentication via Authenticator&lt;/LI&gt;
&lt;LI&gt;Confirm MSAL leg completes → MAM policy on device confirmed&lt;/LI&gt;
&lt;LI&gt;Confirm Qlik Analytics loads successfully&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4 id="toc-hId-291236090" role="heading" aria-level="2"&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Environment&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H4&gt;
&lt;UL&gt;
&lt;LI&gt;Qlik Cloud&lt;/LI&gt;
&lt;LI&gt;Qlik Analytics mobile with Intune&lt;/LI&gt;
&lt;/UL&gt;</description>
    <pubDate>Mon, 01 Jun 2026 11:37:59 GMT</pubDate>
    <dc:creator>Andrew_Kruger</dc:creator>
    <dc:date>2026-06-01T11:37:59Z</dc:date>
    <item>
      <title>MAM configuration for Qlik Analytics mobile app with Intune</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/MAM-configuration-for-Qlik-Analytics-mobile-app-with-Intune/ta-p/2550335</link>
      <description>&lt;P&gt;This article documents an example of how to configure&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;MAM control&lt;/STRONG&gt;&lt;/FONT&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;of the&lt;FONT color="#339966"&gt;&lt;STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Qlik Analytics Mobile app&lt;/STRONG&gt;&lt;/FONT&gt;.&amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE class="quote"&gt;&lt;STRONG&gt;The example is provided as is.&lt;/STRONG&gt; Qlik does not offer guidance on configuring Entra Conditional Access policies or broader Intune deployments. For those details, see&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/intune/device-security/conditional-access-integration/overview" target="_blank" rel="noopener nofollow noreferrer" aria-describedby="audioeye_new_window_message"&gt;Learn about Conditional Access and Intune&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;in the Microsoft documentation.&lt;/BLOCKQUOTE&gt;
&lt;P&gt;As per&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://help.qlik.com/en-US/cloud-services/Subsystems/Hub/Content/Sense_Hub/Admin/configure-mobile-app.htm" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Securing and configuring the Qlik Analytics mobile app with Microsoft Intune&lt;/STRONG&gt;&lt;/A&gt;&amp;nbsp;and the section titled&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://help.qlik.com/en-US/cloud-services/Subsystems/Hub/Content/Sense_Hub/Admin/configure-mobile-app.htm#:~:text=Conditional%20Access%20policy%20guidance" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Conditional Access scope considerations&lt;/STRONG&gt;&lt;/A&gt;, the authentication flow for the mobile app follows the Qlik Cloud IDP OIDC progression.&lt;/P&gt;
&lt;P&gt;The pattern and steps outlined in this article are the working example Qlik used in verification testing of the Conditional Access control for the Qlik Analytics mobile app policy deployment. Your own policy and configuration definitions may vary, and Microsoft documentation or support should be contacted for further help that is specific to your Entra and Intune environments.&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Identify the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;IDP App Registration&lt;/STRONG&gt;:&lt;BR /&gt;&lt;BR /&gt;
&lt;OL class="lia-list-style-type-lower-alpha"&gt;
&lt;LI&gt;&lt;SPAN&gt;Navigate to&amp;nbsp;&lt;STRONG&gt;Entra ID&lt;/STRONG&gt;&amp;nbsp;→&amp;nbsp;&lt;STRONG&gt;App registrations&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Locate the&amp;nbsp;&lt;STRONG&gt;OIDC IDP app&lt;/STRONG&gt;&amp;nbsp;registration and note the&amp;nbsp;&lt;STRONG&gt;Application (client) ID&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Confirm this is the client ID presenting itself during the OIDC browser redirect&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Modify Existing&amp;nbsp;&lt;STRONG&gt;All Cloud Apps&lt;/STRONG&gt;&amp;nbsp;Policy&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;
&lt;OL class="lia-list-style-type-lower-alpha"&gt;
&lt;LI&gt;Navigate to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Protection&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;→&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Conditional Access&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;→&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Policies&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Open the existing&amp;nbsp;&lt;STRONG&gt;All Cloud Apps&lt;/STRONG&gt;&amp;nbsp;policy&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Go to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Cloud apps or actions&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;→&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Exclude&amp;nbsp;&lt;/STRONG&gt;and&amp;nbsp;add the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;IDP app registration client ID&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;In&amp;nbsp;&lt;STRONG&gt;Conditions&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;→&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Device platforms: Any device&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;In&amp;nbsp;&lt;STRONG&gt;Conditions&lt;/STRONG&gt;&amp;nbsp;→&amp;nbsp;&lt;STRONG&gt;Client apps: Browser&lt;/STRONG&gt;&amp;nbsp;&lt;STRONG&gt;+ Mobile apps and desktop clients&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Grant access&lt;/STRONG&gt;:&amp;nbsp;Require device to be marked as compliant&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Save&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and set to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Report-only&lt;/STRONG&gt;&amp;nbsp;at first&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;/LI&gt;
&lt;LI&gt;Create a new&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Targeted Policy for IDP Registration&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;
&lt;OL class="lia-list-style-type-lower-alpha"&gt;
&lt;LI&gt;&lt;SPAN&gt;Create a new&amp;nbsp;&lt;STRONG&gt;CA policy&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Set&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Users&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;to the same scope as the existing policy&lt;/LI&gt;
&lt;LI&gt;Set&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Cloud apps&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;to include IDP app registration only&lt;/LI&gt;
&lt;LI&gt;In&amp;nbsp;&lt;STRONG&gt;Conditions&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;→&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Device platforms: iOS, Android, macOS, Linux&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;In&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Conditions&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;→&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Client apps: Browser + Mobile apps and desktop clients&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Grant access:&amp;nbsp;&lt;/STRONG&gt;Require multifactor authentication (MFA)&lt;/LI&gt;
&lt;LI&gt;Set to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Report-only&lt;/STRONG&gt;&amp;nbsp;at first&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;/LI&gt;
&lt;LI&gt;Validate in&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Report-Only&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;before enabling&lt;BR /&gt;&lt;BR /&gt;
&lt;OL class="lia-list-style-type-lower-alpha"&gt;
&lt;LI&gt;Navigate to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Sign-in logs&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Attempt the auth flow on a test device&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Check the sign-in log entry for the OIDC redirect leg&lt;/LI&gt;
&lt;LI&gt;Confirm report-only shows that the existing policy (Step 2) would have passed for a compliant device excluded&lt;/LI&gt;
&lt;LI&gt;Confirm report-only shows that the new policy (Step 3) would have passed for MFA on Authentication via Authenticator&lt;/LI&gt;
&lt;LI&gt;Once both are confirmed, switch both policies to enabled&lt;/LI&gt;
&lt;/OL&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;STRONG&gt;On the test device:&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Clear app session state and OIDC tokens&lt;/LI&gt;
&lt;LI&gt;Re-attempt the full auth flow end-to-end&lt;/LI&gt;
&lt;LI&gt;Confirm OIDC leg completes → local token issued -&amp;gt; on Authentication via Authenticator&lt;/LI&gt;
&lt;LI&gt;Confirm MSAL leg completes → MAM policy on device confirmed&lt;/LI&gt;
&lt;LI&gt;Confirm Qlik Analytics loads successfully&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4 id="toc-hId-291236090" role="heading" aria-level="2"&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Environment&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H4&gt;
&lt;UL&gt;
&lt;LI&gt;Qlik Cloud&lt;/LI&gt;
&lt;LI&gt;Qlik Analytics mobile with Intune&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Mon, 01 Jun 2026 11:37:59 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/MAM-configuration-for-Qlik-Analytics-mobile-app-with-Intune/ta-p/2550335</guid>
      <dc:creator>Andrew_Kruger</dc:creator>
      <dc:date>2026-06-01T11:37:59Z</dc:date>
    </item>
  </channel>
</rss>

