Microsoft Intune Integration for Cornerstone Mobile App
The Cornerstone mobile app now integrates directly with Microsoft Intune, letting IT teams apply existing organizational security policies to the app. Employees can sign in with their Microsoft credentials, eliminating separate passwords, while organizations gain enterprise-grade controls including data protection, copy/paste restrictions, and selective remote wipe of corporate learning data. The feature launches in open beta with the July 2026 release.
What's New
- Sign in with Microsoft credentials (Azure AD / Microsoft Entra ID) to eliminate separate Cornerstone passwords
- Direct integration with Microsoft Intune to apply existing organizational security and compliance policies
- Enterprise security controls including copy/paste restrictions, screenshot blocking, and selective remote wipe of corporate data without affecting personal content
- Silent sign-in support for users with active Microsoft sessions in apps like Outlook
- Support for multi-tenant Azure AD environments and policies such as MFA, device compliance checks, and location restrictions
- Flexible admin configuration at the root OU or specific sub-OU level
Details
Description
This release introduces direct integration between the Cornerstone mobile app and Microsoft Intune, available in open beta as part of the July 2026 release. The integration allows IT teams to automatically apply their existing organizational security policies to the mobile learning app, bringing it in line with other managed enterprise applications.
Employees can sign in using their Microsoft credentials (Azure AD / Microsoft Entra ID), removing the need for a separate Cornerstone password. On the security side, organizations can control copy and paste behavior, restrict screenshots, and selectively wipe corporate learning data from a device without touching personal content. Silent sign-in support means users with an active Microsoft session in apps like Outlook can open the app and access it without re-authenticating.
Business Need
Organizations managing mobile applications through Microsoft Intune previously could not bring the Cornerstone app under the same security standards as their other managed apps. This created a compliance gap and made it harder for IT security teams to confidently roll out mobile learning across the enterprise.
By integrating with Intune, Cornerstone allows the mobile app to fully participate in existing mobile security and compliance policies. This reduces password duplication for end users, simplifies enablement for admins, and gives IT security teams the control they need — including the ability to selectively remove corporate data when an employee leaves, without affecting personal information.
Key Features
- Microsoft credential sign-in: Users authenticate with their existing Azure AD / Microsoft Entra ID credentials, eliminating the need for a separate Cornerstone ID or password.
- Direct Intune integration: The app applies an organization's existing security and compliance policies managed through the Microsoft Intune Admin Center.
- Enterprise security controls: Organizations can restrict copy/paste, block screenshots, and selectively remote-wipe corporate learning data without affecting personal content on the device.
- Silent sign-in: Users with an active Microsoft session in apps such as Outlook can open the app and access it automatically, with no additional authentication.
- Multi-tenant and policy support: The integration supports multiple Azure AD tenants and works seamlessly with policies such as multi-factor authentication, device compliance checks, and location restrictions.
- Flexible admin configuration: Admins can enable the experience at the root OU level or for specific sub-OUs depending on organizational needs.
Deployment & Considerations
This feature will be available in Stage starting with the July 2026 release and will launch in open beta for production environments in the same time frame. To enable the experience, organizations need Microsoft Entra ID and Intune configuration in place, and must work with Global Customer Support (GCS) to activate the required security object and related configuration.
Administrators must first enable MSAL authentication within the Cornerstone Mobile Preferences, which includes enabling the required security object and configuring the organization's Microsoft Tenant ID. Once enabled, Intune app protection policies are managed directly through the Microsoft Intune Admin Center. No additional permissions are required from learners. Detailed enablement documentation, including a setup guide and customer-facing integration guide, is provided to support successful configuration.