Enable Microsoft Intune on Managed iOS Devices The Emburse Enterprise mobile app supports Microsoft Intune for Mobile Application Management (MAM) on iOS devices. This integration enables your organization to apply Microsoft Intune app protection and compliance policies when the app runs on company-managed devices, helping protect corporate data while maintaining a seamless user experience.Only managed iOS devices are supported at this time. Support for personal-device configuration (BYOD) will be added in a future release.Users: Enroll Your Managed iOS Device in IntuneYour organization’s IT team uses Microsoft Intune to manage certain aspects of the Emburse Enterprise mobile app to help protect company data. You do not need to configure anything manually—setup is handled by your IT administrator.However, the first time you open the Emburse Enterprise mobile app on a managed device, you will be prompted to follow these steps to enroll the app under your organization’s Intune policies. Open the Emburse Enterprise app on a managed iOS device that has your company portal app installed. Sign in with your Microsoft Entra ID account to enroll your device in Intune. Close the app. Reopen the Emburse Enterprise app and sign in. What Intune DoesYour company’s Intune policies may automatically: Prevent copying or pasting sensitive data outside the app. Encrypt or securely store company data on your device. Require company-managed authentication for access. Policies vary by organization and are controlled by your company's IT team.You can still use the app if your device is not managed through Intune, but corporate data protection policies will not apply.Need Help?If you experience issues signing in or see such messages as “Admin approval required” or “This app must be managed by your organization,” contact your company’s IT department for assistance.IT Administrators: Configure Intune Integration for Managed iOS DevicesBelow are the basic steps for setting up your organization’s Intune integration. For detailed instructions on each step, see the Microsoft Intune Help Center.1. Add the Emburse Enterprise Mobile App to Intune Open the Microsoft Intune Admin Center and select Apps in the menu on the left. Under Manage Apps By Platform, select iOS/iPadOS > Create. Search for and select Emburse Enterprise Mobile. Confirm the Bundle ID is com.emburse.mobile. Assign Emburse Enterprise to the appropriate user or device groups. 2. Grant Admin Consent for the Emburse Enterprise Mobile AppUse this link to automatically grant admin consent for the required permissions described below.Required Microsoft Permissions API Permission Description Microsoft Graph User.Read Standard user profile access Microsoft Mobile Application Management DeviceManagementManagedApps.ReadWrite.All Enables Intune MAM integration If users see the message “Admin approval required” during Emburse Enterprise mobile app login, admin consent has not yet been granted.3. Add an App Configuration Policy for Managed Devices Open the Microsoft Intune Admin Center and select Apps in the menu on the left. Navigate to App Configuration Policies > Add Policy > Managed Devices. Under Configuration Settings, add the following key/value pair: Key Value Type Value IntuneMAMUPN String {{userprincipalname}} Associate the policy with Bundle ID com.emburse.mobile. Assign the policy to the same user or device groups assigned in Step 1. If the key is missing or misconfigured, the Emburse Enterprise app will launch in unmanaged mode and Intune policies will not apply.4. Add an App Protection Policy Open the Microsoft Intune Admin Center and select Apps in the menu on the left. Navigate to App Protection Policies > Add policy (iOS/iPadOS). Define your organization’s protection settings (e.g., encryption, cut/copy/paste restrictions). Assign the policy to the same user or device groups assigned in Step 1. Validation Checklist Admin consent granted in Microsoft Entra ID IntuneMAMUPN = {{userprincipalname}} configured App protection policy applied and verified App and policies assigned to the correct groups Users complete Emburse login successfully Admin Troubleshooting Issue Cause Resolution “Admin approval required” message during login Admin consent not granted A Microsoft Global Admin must grant permissions App launches unmanaged App configuration key missing or misconfigured Verify key and policy assignment Copy/paste still allowed Policy not yet synced Wait for Intune sync or reassign the policy App missing from company portal App not assigned properly Ensure app is assigned and set to Available for enrolled devices Was this article helpful? Yes No