1. Overview: For the Enterprise Administrator
Fulcrum for Intune is our dedicated mobile application for organizations that leverage Microsoft Intune to manage devices and enforce data protection policies.
While our standard mobile app can be deployed via Intune, Fulcrum for Intune is required to fully support:
App Protection Policies: Enforce granular security controls, such as requiring a PIN to open the app, restricting copy/paste to unmanaged applications, and blocking app use on non-compliant devices.
Conditional Access: Ensure that only users on compliant, managed devices can access your organization's Fulcrum data.
This application ensures that all field data collection and management activities within Fulcrum adhere to your corporate security and compliance standards.
Prerequisites
A Fulcrum Enterprise plan with Single Sign-On (SSO) configured.
A Microsoft Intune subscription.
Users must be licensed for Intune.
The 'Fulcrum for Intune' app must be added to your Intune app catalog.
High-Level Deployment Steps
Add the App: In the Intune admin center, add the "Fulcrum for Intune" app (with the briefcase icon) to your app library from the managed Google Play Store or Apple App Store.
Create an App Protection Policy or Edit an Existing One: Define your desired security controls (e.g., "Require PIN for access," "Block screen capture") and apply this policy to the Fulcrum for Intune app.
Add as a Custom App: Select custom apps and add the app with this package name
com.spatialnetworks.fulcrum.intunems.
Allow Sending and Receiving Data from Other Apps: The Fulcrum SSO process passes users through a browser in order to authenticate. To facilitate this process, the policy needs to allow data to pass to and from Fulcrum to the browser app. This can be set under the "Data protection" section with the "Send org data to other apps" and "Receive data from other apps" rules.
On iOS specifically, this step also requires a redirect exemption — see the iOS section under "Common Platform-Specific Policy Requirements" below for details. This is not typically needed on Android.
Assign the App: Assign the app and protection policy to your target user or device groups.
Notes:
For non-enrolled devices using App Protection Policies, you will need to enable API permissions in Entra ID.
Microsoft Authenticator Limitations on Intune-Managed Devices
Currently, Fulcrum for Intune may prompt users for credentials each time they sign in, even if Microsoft Authenticator is installed and the user is already authenticated in other Intune-managed apps. This behavior is due to Azure AD tenant or device configuration limitations, not a limitation in the Fulcrum app itself.
If your users experience frequent credential prompts:
Verify the device is properly registered in Azure AD as compliant
Check with your IT administrator about Primary Refresh Token (PRT) issuance and SSO policies in your Azure AD tenant
Confirm device compliance policies are correctly configured in Intune
Common Platform-Specific Policy Requirements
Based on real-world enterprise deployments, here are the most common App Protection Policy adjustments needed per platform. If your SSO sign-in is failing after browser authentication, check these first — and feel free to reach out to [email protected] if you need help working through them.
iOS
On iOS, the SSO flow hands off from Fulcrum for Intune to your organization's designated browser to complete authentication, then must redirect back into Fulcrum. If your Conditional Access / App Protection Policy doesn't explicitly allow this redirect, users will see an error after signing in via the browser (e.g., "Something went wrong. The application couldn't be opened.").
Fix: There are two ways to configure this — choose whichever fits your existing policy structure:
Option A — Configure in the Fulcrum for Intune policy: In the App Protection Policy applied to Fulcrum for Intune (the policy from Step 2 above), add exemptions under Data protection → Select apps to exempt for
fulcrumappandmsauthv2, and add your organization's designated browser as a Public app allowed to exchange data with this policy under the "Send org data to other apps" and "Receive data from other apps" rules.Option B — Configure in the browser's policy: Alternatively, if the browser used in your SSO process has its own App Protection Policy, you can add exemptions there instead under Data protection → Select apps to exempt for
fulcrumappandmsauthv2.
Either option should resolve the redirect issue; you generally only need to configure one of them, not both.
Android
On Android, a browser install requirement (needed for SSO) can cause a temporary sign-in loop until the browser is detected. This is expected behavior tied to Conditional Access, and usually resolves once the browser is installed — no policy change needed for this specific step.
If you're using "Policy managed apps" for the "Send org data to other apps" rule, you may need to explicitly specify
com.spatialnetworks.fulcrum.intunemsas an exception for sending data.Separately, Fulcrum for Intune hands off to your device's native photo viewer (or an installed app like Google Photos) when viewing images, rather than using an in-app viewer. This is intentional — it gives users access to native capabilities (e.g., Google Lens) and offloads maintenance/security updates to the OS vendor.
If your App Protection Policy restricts app-to-app data sharing, this handoff will be blocked and users will see an error when trying to view a photo.
Fix: If you want to preserve this native viewing experience, add an exemption under Data protection → Send org data to other apps (or your equivalent "allow app-to-app transfer" setting) for the photo viewer app(s) your users rely on. Alternatively, users can use the Markup option within Fulcrum, which uses Fulcrum's built-in image viewer and does not require this exemption.
2. End-User Guide: Installation & Sign-In
How to Install the App
Your company's IT administrator will make the app available to you. Based on your organization's setup, this will happen in one of three ways:
Automatic Installation: The app may be automatically "pushed" to your device and will appear on your home screen or in your work folder.
Company Portal (iOS & Android): Open the Intune Company Portal app on your device. Search for "Fulcrum for Intune" and tap Install.
Managed App Stores:
Android: Open the Play Store with the briefcase icon (your Work Profile Play Store). You will find the app under the "Work" tab.
iOS: If your company uses Apple Business Manager, the app may appear as a "Required" app in the standard App Store under your managed account.
Please look for the Fulcrum for Intune app, which has a small briefcase icon on it. If you cannot find it, please contact your IT department.
Signing In for the First Time
Open the Fulcrum for Intune app.
Tap the Secure Sign In button.
You will be prompted to sign in to your Microsoft account. Select or enter your corporate credentials.
You will then be taken to the Fulcrum login screen. Your SSO domain may already be filled in. If not, please enter your company's Fulcrum SSO domain (the same one you use on the web) and tap Sign In.
If your company uses app protection policies, you will need to restart the app before finishing sign-in so the policies take effect. You'll see a prompt to restart, and the app will close — this step is required, not optional. Just reopen the Fulcrum for Intune app on your device and sign in again.
3. Frequently Asked Questions (FAQ) & Troubleshooting
Q: Why are there two Fulcrum apps? Which one do I use?
A: The standard "Fulcrum" app is for general use. The "Fulcrum for Intune" app (with the briefcase) is specifically for companies that require enhanced Microsoft security. Your IT administrator will tell you which one you must use. If your company uses Intune, the regular app will likely be blocked.
Q: I'm getting an error about "Conditional Access" or my device being "non-compliant."
A: This is a security message from your company. It means your device does not meet your organization's security requirements (e.g., the OS is outdated, the device is jailbroken, or a PIN is not set). You must contact your internal IT help desk for assistance.
Q: The app is asking for my "SSO Domain." What is that?
A: This is your company's unique identifier for logging into Fulcrum. It should be the same one you use to log in to the Fulcrum website. If it's not pre-filled, please contact your IT administrator or manager to get the correct domain.
Q: What happens if I log out before syncing my records?
A:If you log out of Fulcrum for Intune without first syncing any pending or draft records, those records are lost and cannot be recovered.
Always sync before logging out. Check that all pending and draft records have synced successfully before you log out of the app.
The Intune version of Fulcrum mobile is a highly secure fork of the standard Fulcrum mobile app, built to meet your organization's device management and security requirements. Because it operates under Intune's app protection policies, logging out behaves differently than in the standard app, so confirming a full sync first is especially important.


