Claude for Intune: deploy and protect Claude on iPhone and iPad with Intune
Anthropic releases Claude for Intune on the App Store: prerequisites, Entra admin consent, app protection policy, Conditional Access and BYOD, step by step.

🌐 This article was originally written in French and automatically translated. Read the original (FR)
Claude for Intune is a managed version of the Claude app for iOS and iPadOS, published by Anthropic on the App Store. It supports Intune app protection policies (MAM), including on personal, unenrolled iPhones and iPads, as well as Microsoft Entra Conditional Access. You need a Claude Enterprise plan, iOS 18, Microsoft sign-in enabled by Anthropic, Entra admin consent and the bundle ID com.anthropic.claudeforintune in the app protection policy.
It’s the question many of you have been asking me since AI assistants arrived in the enterprise: how do you let employees use Claude on their iPhone without losing control of the data? Anthropic has just answered it with Claude for Intune, a managed version of its iOS app, now available on the App Store.
In practice, Claude becomes an “Intune-aware” app like Outlook, Teams or Edge: you can apply app protection policies (MAM) to it, including on personal iPhones and iPads, and put it behind Microsoft Entra Conditional Access.
In this article, I walk you through the prerequisites, the identifiers you need and the complete configuration, step by step.
What exactly is Claude for Intune?
Claude for Intune is a separate app from the regular Claude app. Both coexist on the App Store:
| Claude (standard) | Claude for Intune | |
|---|---|---|
| Publisher | Anthropic PBC | Anthropic PBC |
| Intune app protection policies | No | Yes |
| Entra Conditional Access (require app protection policy) | No | Yes |
| Sign-in | Several methods | Microsoft account only |
| Platforms | iOS, Android | iOS / iPadOS 18 and later |
Feature-wise, you get the core of Claude: drafting and summarizing documents and emails, analyzing PDFs, spreadsheets, screenshots and images, coding help, voice mode and continuing conversations started on the web or desktop. Access, features and data controls are managed by the organization’s administrator.
The benefit is obvious for BYOD: thanks to MAM without enrollment, you protect organization data inside Claude without having to enroll or manage the employee’s personal iPhone.
Prerequisites
Before you start, check the following:
- A Claude Enterprise plan. Anthropic’s article mentions Enterprise; the App Store listing cites Team and Enterprise. If you’re on Team, confirm with Anthropic.
- Microsoft Intune and access to the Intune admin center.
- iOS or iPadOS 18.0 or later on devices.
- Microsoft Authenticator installed on devices (the authentication broker required for MAM on iOS).
- Microsoft sign-in enabled by Anthropic for your organization’s email domains.
- Admin consent granted in Microsoft Entra ID.
Step 1: have Anthropic enable Microsoft sign-in
Claude for Intune only accepts sign-in with a Microsoft account. Contact your Anthropic account team or Claude support with the email domains your employees use (for example contoso.com and contoso.fr).
Step 2: grant admin consent in Entra ID
This is the most frequently forgotten step, and it’s mandatory for every organization. A tenant admin opens the following URL, replacing {organization} with the tenant ID or domain:
https://login.microsoftonline.com/{organization}/adminconsent?client_id=bb747f0e-002b-4882-9960-916fe00a2b90
To check: Microsoft Entra admin center > Enterprise applications > Claude for Intune (Public) > Permissions. The Microsoft Mobile Application Management API must appear on the Admin consent tab. If not, select Grant admin consent.
Warning: signing in to claude.ai with “Continue with Microsoft” does not grant this consent. If your users get signed out a few seconds after signing in, it’s almost always missing. Once consent is granted, they must delete the app, reinstall it and sign in again.
Step 3: add the app in Intune
In the Intune admin center:
- Apps > Platforms > iOS/iPadOS.
- Create > iOS store app > Select.
- Search for Claude for Intune and select it.
- Under App information, set the minimum operating system to iOS 18.
- Under Assignments, assign a user group so the app shows up in Company Portal.
- Review + create.
Users then install the app from Company Portal, or directly from the App Store on a personal device.
Step 4: create the app protection policy
Apps > Protection > Create > iOS/iPadOS:
- Basics tab: give it an explicit name, for example
APP-iOS-Claude-for-Intune. - Apps tab: Target policy to Selected apps, then + Select custom apps.
- Enter the following bundle ID, select it and check that it appears under Custom apps:
com.anthropic.claudeforintune
- Configure Data protection, Access requirements and Conditional launch (see my recommendations below).
- Assignments tab: assign the relevant user group.
- Review + create.
Why enter the bundle ID manually? Because Claude for Intune doesn’t appear in Microsoft’s protected apps list yet. Once it does, you’ll be able to select it directly from the public apps.
The app only becomes managed after the user signs in with their work account. Restarting the app may be needed for the policy to apply.
My recommended settings
For BYOD use, I start from a baseline close to level 2 (“enterprise enhanced data protection”) of Microsoft’s data protection framework:
| Section | Setting | Recommended value |
|---|---|---|
| Data protection | Backup org data to iTunes and iCloud backups | Block |
| Data protection | Send org data to other apps | Policy managed apps |
| Data protection | Receive data from other apps | Policy managed apps |
| Data protection | Restrict cut, copy, and paste between other apps | Policy managed apps with paste in |
| Data protection | Save copies of org data | Block |
| Access requirements | PIN for access | Require (Face ID / Touch ID allowed) |
| Conditional launch | Jailbroken/rooted devices | Block access |
| Conditional launch | Min OS version | 18.0 (Block access) |
| Conditional launch | Offline grace period | 720 minutes, then wipe after 90 days |
With these settings, an employee can copy a Claude answer into Outlook or Teams (managed apps), but not into WhatsApp or their personal notes, and vice versa.
Step 5: require the protection policy with Conditional Access
To make sure no data is reachable from an unprotected app, add a Conditional Access policy in Entra ID:
- Users: the group targeted by the app protection policy;
- Target resources: All resources;
- Conditions > Device platforms: iOS;
- Conditions > Client apps: mobile apps and desktop clients;
- Grant: Require app protection policy.
The key point, stated by Anthropic: the rule must target All resources. A policy that only targets Office 365 or Claude’s SSO app does not cover Claude for Intune.
As always with Conditional Access, start in report-only mode, check the sign-in logs, then enable the policy.
Step 6: communicate with employees
One last, often overlooked point: the two apps look alike. Tell your users clearly to install Claude for Intune (not the standard Claude app) wherever Intune protection is required, for example with the direct App Store link:
https://apps.apple.com/us/app/claude-intune/id6812855318
Also remind them to install Microsoft Authenticator, otherwise sign-in will fail.
Identifier cheat sheet
| Item | Value |
|---|---|
| Bundle ID (app protection policy) | com.anthropic.claudeforintune |
| Client ID (admin consent) | bb747f0e-002b-4882-9960-916fe00a2b90 |
| Entra enterprise application | Claude for Intune (Public) |
| App Store ID | id6812855318 |
| Minimum version | iOS / iPadOS 18.0 |
My take
This is great news for IT departments that were hesitant to open up generative AI on mobile. Until now, the choice was binary: block Claude on personal devices, or let people use it with no control over copy-paste and backups. With Claude for Intune, you can finally apply the same rules as for Outlook or Teams, and the app protection policy + Conditional Access combination enables clean BYOD.
Two things to watch: the app being added to Microsoft’s official protected apps list, and a possible Android version. I’ll update this article as soon as there’s news.
Key takeaways
- Claude for Intune is a separate app from the standard Claude app: Intune policies only apply to it.
- It works with MAM without enrollment: you protect Claude data on personal devices (BYOD) without managing the device.
- Prerequisites: Claude Enterprise, iOS/iPadOS 18+, Microsoft sign-in only, Microsoft Authenticator on the device.
- Entra admin consent (client ID bb747f0e-002b-4882-9960-916fe00a2b90) is mandatory, otherwise users get signed out within seconds.
- Until Microsoft lists it, the app is targeted in the app protection policy by its bundle ID com.anthropic.claudeforintune.
Frequently asked questions
What is Claude for Intune?
It's a managed version of the Claude app for iPhone and iPad, published by Anthropic on the App Store. It integrates the Intune SDK: admins can apply app protection policies (MAM) and Microsoft Entra Conditional Access to it.
Does the iPhone need to be enrolled in Intune to use Claude for Intune?
No. App protection policies also apply to personal, unenrolled devices (MAM without enrollment). The user installs the app, signs in with their Microsoft work account and the policy applies to the app only.
Which Claude plan is required?
Anthropic's help article states an Enterprise plan, enabled through your Anthropic account team or support. The App Store listing mentions Team and Enterprise plans: check with Anthropic for the Team plan.
Why are my users signed out a few seconds after signing in?
That's the symptom of missing Entra admin consent. A tenant admin must grant consent to the “Claude for Intune (Public)” application, then users delete, reinstall the app and sign in again.
Why can't I find Claude for Intune in the app protection policy app list?
Microsoft hasn't added it to its protected apps list yet. In the meantime, choose “Select custom apps” and enter the bundle ID com.anthropic.claudeforintune.
Is Claude for Intune available on Android?
For now, Anthropic only documents iOS and iPadOS (version 18 or later).


