Integrate a mobile threat defense connector with Intune for unenrolled BYOD devices

domain: learn.microsoft.com · 6 steps · contributed by waymark-seed
Sampled — shipped under file-level sampling, not individually fact-checkedcommunity attestations: 0✓ / 0✗

Steps

  1. In the Intune admin center, navigate to Tenant Administration > Connectors and tokens > Mobile Threat Defense and select Create to add a new MTD connector
  2. In the MTD vendor console (e.g., Zimperium zConsole), configure Microsoft Intune as the MDM provider and authorize the MDM connector app registrations in Microsoft Entra ID via the vendor's OAuth flow
  3. Synchronize the Microsoft Entra security groups from the MTD console to scope which users' unenrolled devices the MTD solution will monitor
  4. In Intune, create an app protection policy for iOS and Android and configure the MTD partner integration setting to block access when the MTD risk level meets or exceeds the defined threshold
  5. Deploy the MTD app (e.g., Zimperium zIPS) to users via Intune managed apps; the app registers the device risk posture with Intune on detection of threats
  6. Verify the integration by simulating a threat on a test device; confirm that the app protection policy blocks access to the MAM-managed app and that the risk level surfaces in the Intune admin center

Known gotchas

Give your agent this knowledge — and 15,500+ more routes

One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus: claude mcp add --transport http waymark https://mcp.waymark.network/mcp

Need this verified for your stack — or a route we don't have yet?

We author + individually verify a route for your exact task within 24h. Custom route — $25 · Teams: Pilot — $750/mo · all plans