Overview macOS is the operating system that powers every MacBook. As per Apple,it lets you do things you can't do with other computers. Yeah, it's a never ending argument but not let's get into it and get those Macs managed with Intune. Although
macOS is the operating system that powers every MacBook. As per Apple,it lets you do things you can't do with other computers. Yeah, it's a never ending argument but not let's get into it and get those Macs managed with Intune.
Although most laptops/desktops we manage daily are PCs, there will still be a few Macs in your inventory that you want to manage. With Microsoft Intune, you can easily streamline device management for your macOS devices.
Over the coming days, we will explore all the possibilities of enrolling personal and company-owned MacBooks with industry-standard policies; restrictions. Let's get started, then.
A few prerequisites must be met before any Apple device can be enrolled in Intune. I have covered them in my previous posts - but let's revisit them again.
After you enable enrollment, you can also enrol user-owned macOS devices as BYOD in Intune.
Company-owned macOS devices
Intune supports the following enrollment methods for company-owned macOS devices
1. Automated Device Enrollment (ADE)
2. Device Enrollment Manager (DEM)
3. Direct Enrollment
User-approved enrollment
All Mac enrollments in Intune are considered user-approved. User-approved enrollment lets you manage macOS devices that aren't part of Apple Business Manager and provides the same level of controlas supervised macOS. Intune automatically turns on supervision for user-approved devices. The only major difference is that the user signs in to the Company Portal app to initiate enrollment.
You need an Apple MDM Push certificate to manage your iOS/iPadOS and macOS devices in Microsoft Intune. This token enables devices to enrol via Intune Comp Portal or ADE/ASM/AC2.
Sign in to Intune Portal, choose Devices > Enroll devices > Apple enrollment > Apple MDM Push Certificate, and follow these steps:
So the pre-requisite is done, but before you can enrol macOS devices, you would need an Apple Server Token (.p7m) file from Apple. This token syncs information from Intune to ADE devices that your corporation owns. It also allows Intune to assign enrollment profiles to Apple and to assign devices to those profiles.
Follow the steps below to create & upload the ADE token:
In Apple Business Manager, click your account name at the bottom of the sidebar, then choose Preferences from the pop-up menu
.You’ll be informed that download a new server token will reset any existing tokens. This is OK since we are creating a new connection so click the Download Server Token button.
Once you’ve installed your token, the next step is creating an enrollment profile for devices. A device enrollment profile defines the settings that will be applied to the devices in this profile.
The advantage of using modern authentication with setup assistance is that until & unless the user signs in to the Company Portal using his/her Azure AD credentials, the device:
With locked enrollment, you make the device more secure as it disables macOS settings that allow the management profile to be removed from the System Preferences menu or through the Terminal. After device enrollment, the user cannot change this setting without wiping the device.
Sync managed devices
Now that Intune has permission to manage your devices, we have to synchronize Intune with Apple to see your managed devices in Intune portal.
Sync managed devices
Now that Intune has permission to manage your devices, we have to synchronize Intune with Apple to see your managed devices in Intune portal.
We have everything in place. Should we now distribute the devices to users? No..wait! This was just the initial part; before you roll out any device to your end users, ensure compliance policies, restrictions & mandatory apps are configured in Intune. So, let us move to the next part of the series with configuring compliance policies & enforcing restrictions and pushing the mandatory apps to the users/devices.
Stay In(tuned) 👩💻👩💻 and be #intuneinspired
Edit