Deploy the Microsoft Authenticator SSO Payload and Application (Android)

Deploy the Microsoft Authenticator SSO payload and required apps to enable seamless sign-in on Android devices.

Before you begin

Ensure that you have completed the following configuration steps:
  1. Add a Microsoft Authenticator SSO Payload (Android).
  2. Connect Microsoft Entra ID for Microsoft Authenticator SSO (Android).
  3. Configure Conditional Access for Microsoft Authenticator SSO (Android).

About this task

This is the fourth step in configuring Microsoft Authenticator Single Sign-On (SSO) for Android devices. See Configuring Microsoft Authenticator SSO (Android).

In this step, you assign the configured SSO payload and deploy the Microsoft Authenticator app, along with any Microsoft Authentication Library (MSAL) apps that require SSO support.

Procedure

  1. After configuring the Microsoft Authenticator SSO payload, assign the profile to your target Android devices. See Assigning a Profile.
    A prompt asks you to deploy the Microsoft Authenticator application.
    The Microsoft Authenticator prompt appears upon deploying the Microsoft SSO configuration.
  2. Create an Android Enterprise app policy that includes the Microsoft Authenticator app and any MSAL apps that will use SSO. See Using App Policies for instructions.
  3. In the app policy settings for the Microsoft Authenticator application, configure the following:
    • Set the deployment type to Mandatory.
    • Enable Prevent removal of app by device user.
    Making the Microsoft Authenticator application mandatory and preventing users from uninstalling the Microsoft Authenticator application's advanced configuration options.

Results

The Microsoft Authenticator SSO configuration and the required applications successfully deploy to your Android devices.

What to do next

Complete the configuration by registering devices with Microsoft Authenticator SSO. See Register Devices for Microsoft Authenticator SSO (iOS/ iPadOS).