Claude for Intune is a managed version of Claude for iOS for organizations that use Microsoft Intune. This article explains how Intune admins add Claude for Intune in the Microsoft Intune admin center and which app to tell employees to install.
What is Claude for Intune?
Claude for Intune is built for organizations that manage mobile devices with Microsoft Intune, including organizations that let employees work from personal iPhones and iPads.
Claude for Intune is a separate app from the standard Claude app. Both are listed on the App Store.
IT teams can apply Intune app-protection policies to Claude for Intune on company-owned and employee-owned iPhones and iPads.
It signs in with Microsoft only.
It supports Intune app-protection policies and Microsoft Entra Conditional Access.
Requirements
Before you set up Claude for Intune, check that you meet these requirements:
You have an Enterprise plan.
Your organization uses Microsoft Intune, and you have access to the Microsoft Intune admin center.
Employees sign in to Claude for Intune with Microsoft. Other sign-in methods aren't available in Claude for Intune.
You’re using iOS or iPadOS version 18.0 or later.
Anthropic has enabled Microsoft sign-in for your organization's email domains.
If you use Conditional Access, Claude for Intune is registered in your Microsoft Entra tenant.
Get your organization ready
1. Ask Anthropic to enable Microsoft sign-in
Before employees can sign in to Claude for Intune, Anthropic needs to enable Microsoft sign-in for your organization's email domains. Contact your Anthropic account team or support, and tell them which email domains your employees use to sign in.
2. Register Claude for Intune in your Entra tenant
If you want to use Conditional Access with Claude for Intune, the app has to be registered in your Microsoft Entra tenant first. Until it is, Claude for Intune doesn't appear in the list of apps you can select in a Conditional Access policy.
Claude for Intune is registered the first time someone who is authorized to consent on behalf of the organization signs in with Microsoft. Choose one of these options:
Have a user sign in. Go to claude.ai and select “Continue with Microsoft.” One successful sign-in is enough.
Grant admin consent. A tenant admin opens the following URL, replacing {organization} with your tenant ID or domain:
https://login.microsoftonline.com/{organization}/adminconsent?client_id=bb747f0e-002b-4882-9960-916fe00a2b90
After either option, Claude for Intune appears in Microsoft Entra and your Conditional Access admin can target it in a policy.
To require app protection at sign-in, target the Conditional Access rule at “All resources” with Grant = Require app protection policy. A rule that names only Office 365 or Claude SSO does not cover Claude for Intune. Microsoft Authenticator must be installed on the device.
Add Claude for Intune in the Microsoft Intune admin center
1. Add Claude for Intune to your managed apps and make it available to BYOD devices.
In the Microsoft Intune admin center, select “Apps” from the left side navigation panel:
Under Platforms, select “iOS/iPadOS”:
Click “+ Create.” For the App type, select the “iOS store app,” and click the “Select” button on the bottom:
Search “Claude for Intune” and click the “Select" button on the bottom.
In App Information, set Minimum operating system to iOS 18, then click the “Next” button:
For Assignments, add a group of users to make it available in their device’s Company Portal:
Click “Next,” review and create.
Users have to download the app from Company Portal on their devices for access.
2. Apply an app-protection policy to Claude for Intune.
In the Microsoft Intune admin center, select “Apps” from the left side navigation panel:
Under Manage apps, select “Protection”:
Click “+ Create” and then select “iOS/iPadOS”:
Enter Name in the Basics tab, then click “Next” to Apps. Set Target policy to “Selected apps.” Click “+ Select custom apps”:
Type in the bundle ID
com.anthropic.claudeforintune. Select it so it appears under Selected Apps before clicking “Select”:In Apps, confirm the bundle ID now appears under Custom apps before clicking “Next”:
Configure the Data protection, Access requirements, and Conditional launch settings as needed.
In the Assignments tab, add a user group to assign the policy to them.
Review and create.
The app only becomes "managed" after the user signs in with org credentials post-install (may require a restart).
Tell employees which app to install
Claude for Intune and the standard Claude app are separate apps. Your Intune app-protection policies apply to Claude for Intune.
Wherever your organization requires Intune protection, tell employees on managed or employee-owned iPhones and iPads to install Claude for Intune, not the standard Claude app.
Before Microsoft lists Claude for Intune as a protected app
Claude for Intune doesn't yet appear in Microsoft's list of protected apps, so you can't search for it when you create an app-protection policy. Until it's listed, add it to your policy by entering its bundle ID manually:
Follow the steps in Apply an app-protection policy to Claude for Intune.
When you select apps, choose “Select custom apps” and enter the bundle ID
com.anthropic.claudeforintune.
After Microsoft adds Claude for Intune to its protected apps list, you'll select it from the list of public apps instead of using “Select custom apps.”
