# Welcome

Community Guides, Tools and Best Practices for macOS admins who manage their devices with Microsoft Intune.

A community hub for sharing and learning from real-world macOS experiences — guides, scripts, tools, and best practices, all in one place. Continuously improved and updated by experts.

{% hint style="info" %}
New here? Start with the [Getting Started guide](/home/getting-started), or jump straight to the [Baseline Settings](/baseline-settings-for-intune/import) to configure your tenant fast.
{% endhint %}

## Our Sponsors ❤️

A big thank you to our sponsor for supporting the community and helping keep these resources free.

[![Devote](/files/HVxkpSSRwvZhHzeYi7E5)](https://www.devote.com)

[Visit Devote →](https://www.devote.com)

## Get started

### Jumpstart with our Baseline Settings

Quickly manage your macOS devices with curated settings from the Open Intune Baseline (OIB) project. [Import the Baseline Settings →](/baseline-settings-for-intune/import)

## Other resources

* [Official Microsoft Docs for macOS Management](https://learn.microsoft.com/en-us/mem/intune/fundamentals/deployment-guide-enrollment-macos)
* [Microsoft Mac Admins Group on LinkedIn](https://www.linkedin.com/groups/13007354/)
* [Mac Admins Slack](https://join.slack.com/t/macadmins/shared_invite/zt-2li6s6akl-ZaR7ZVwg6Tj~8XPSUgFQ~Q)

***

* [**Community Contributors ❤️**](/home/contributors) — thank you to everyone helping improve IntuneMacAdmins.
* [**Contribute on GitHub**](https://github.com/ugurkocde/IntuneMacAdmins) — add your name to the list of contributors.


# Changelog

A transparent record of what changed across IntuneMacAdmins, when it changed, where it was published, and which sources support it.

Every meaningful documentation change, in one place. Each entry shows what was added or corrected, the page that changed, and the authoritative source behind it.

<a href="/pages/ffPag4g5dcdAnhoEJuut" class="button primary">See the Latest Intune Updates</a> <a href="/pages/BagiTFkNdkWuo0orOqVi" class="button secondary">Contribute a Change</a>

{% hint style="info" %}
**Transparent by design.** Content updates and verified corrections are written here by the same automation that updates the docs. A changelog entry is included in the pull request and passes the same validation and preview checks before publication.
{% endhint %}

## August 3, 2026

### Corrected Install the Company Portal app for MacOS as a MacOS LOB app

**Documentation correction** · Automatically published

The page says to select the app type without mentioning selecting the macOS platform first; the source states you select the macOS platform and then Line-of-business app.

* **Published to:** [Install the Company Portal app for MacOS as a MacOS LOB app](/complete-guide-macos-deployment/install-the-company-portal-app-for-macos-as-a-macos-lob-app)
* **Source:** [Microsoft Learn](https://learn.microsoft.com/intune/app-management/deployment/add-lob-macos)

***

### Custom compliance settings for macOS

**Content update** · Automatically published

Microsoft Intune now supports custom compliance settings for macOS, allowing admins to define compliance checks using scripts and JSON rules, similar to existing support for Windows and Linux. This capability can evaluate device configuration, security posture, and other custom attributes not covered by built-in settings. Results appear alongside standard compliance reporting in the Intune admin center.

* **Published to:** [What's New for macOS Management](/home/whats-new), [Custom Compliance Settings for macOS](/complete-guide-macos-deployment/custom-compliance-settings)
* **Source:** [Microsoft Learn](https://learn.microsoft.com/en-us/intune/whats-new/#custom-compliance-settings-for-macos)

## July 27, 2026

### Corrected Configure Await Final Configuration

**Documentation correction** · Automatically published

The page refers to distinguishing it from other enrollment "profiles", but the source describes creating an enrollment "policy" and distinguishing it from other enrollment "policies".

* **Published to:** [Configure Await Final Configuration](/await-final-configuration/configure-await-final-configuration)
* **Source:** [Microsoft Learn](https://learn.microsoft.com/intune/device-enrollment/apple/setup-automated-macos)

***

### Corrected Antivirus Configuration

**Documentation correction** · Automatically published

The page lists 'Scanning inside archive files' without qualification, but the source states this setting applies to on-demand antivirus scans only.

* **Published to:** [Antivirus Configuration](/baseline-settings-for-intune/settingsoverview/antivirusconfiguration)
* **Source:** [Microsoft Learn](https://learn.microsoft.com/defender-endpoint/mac-preferences)

***

### Corrected Configure MacOS Platform SSO

**Documentation correction** · Automatically published

The page lists only Microsoft Edge, Google Chrome, and Safari as supported browsers, but the source also lists Firefox as a supported browser.

* **Published to:** [Configure MacOS Platform SSO](/complete-guide-macos-deployment/configure-macos-platform-sso)
* **Source:** [Microsoft Learn](https://learn.microsoft.com/intune/device-configuration/settings-catalog/configure-platform-sso-macos)

***

### Corrected Script to get the last reboot time formatted

**Documentation correction** · Automatically published

The page says the navigate is Devices > macOS > Custom Attributes; the current source describnavnavpath shthe settings are Devices > By platform > macOS > Manage devices > Scripts.

* **Published to:** [Script to get the last reboot time formatted](/custom-attributes/create-custom-attributes)
* **Source:** [Microsoft Learn](https://learn.microsoft.com/intune/device-management/tools/run-shell-scripts-macos)

## July 14, 2026

### Plan for change: Intune is moving to support macOS 15 and higher later this year

**Content update** · Automatically published

Microsoft Intune, the Company Portal app, and the Intune mobile device management agent will move to support macOS 15 and later, with the change occurring shortly after Apple's expected release of macOS 27 later in calendar year 2026. Devices already enrolled on macOS 14.x or below will remain enrolled, but new devices running macOS 14.x or below will be unable to enroll. Administrators can review Intune reporting under Devices and All devices, filter by macOS, and ask users to upgrade to a supported OS version.

* **Published to:** [What's New for macOS Management](/home/whats-new)
* **Source:** [Microsoft Intune important notices](https://learn.microsoft.com/en-us/intune/whats-new/#plan-for-change-intune-is-moving-to-support-macos-15-and-higher-later-this-year)

***

### The changelog moved to the main website

**Site update** · Maintainer published

Published the source-linked changelog at `www.intunemacadmins.com/changelog`, added a Changelog button to the main landing page that opens in a new tab, and connected the static page to the same automated changelog source used by the documentation workflows.

* **Published to:** [Main website changelog](https://www.intunemacadmins.com/changelog/), [IntuneMacAdmins landing page](https://www.intunemacadmins.com/)
* **Source:** [Documentation repository](https://github.com/ugurkocde/intunemacadmins)

***

### A transparent changelog moved to center stage

**Site update** · Maintainer published

Redesigned the old release list as a source-first timeline at `/changelog`, added a landing-page call to action, preserved the historical archive, and connected both documentation workflows so future content and corrections log themselves automatically.

* **Published to:** [Changelog](/changelog), [IntuneMacAdmins home](/)
* **Source:** [Documentation repository](https://github.com/ugurkocde/intunemacadmins)

***

### macOS PKG apps can update automatically

**Content update** · Automatically published

Added Microsoft’s new behavior for available macOS PKG apps. When an admin uploads a newer version with the same bundle ID, previously installed available apps can update without another Company Portal action. The behavior requires Intune management agent version 2606.013 or later.

* **Published to:** [What’s New in Intune](/home/whats-new)
* **Source:** [Microsoft Intune release notes](https://learn.microsoft.com/en-us/intune/whats-new/#available-macos-pkg-apps-update-automatically-when-you-upload-a-new-version)

***

### Documentation updates became set-and-forget

**Site update** · Maintainer published

Rebuilt the content and freshness workflows so verified changes update existing pages first, create a well-placed page only when necessary, validate the exact pull request revision, merge automatically, and confirm GitBook and Vercel publication.

* **Published to:** [Documentation repository](https://github.com/ugurkocde/intunemacadmins)
* **Source:** [Automation implementation](https://github.com/ugurkocde/intunemacadmins/commit/607ef62289a5b4827b8b1b4d302a0838b7874da6)

***

### Community Pulse and Core Contributors were retired

**Site update** · Maintainer published

Removed the Community Pulse category, its generated pages and source collectors, plus the Core Contributors table. Community resources, tools, and the complete contributor list remain available in their established sections.

* **Published to:** [IntuneMacAdmins home](/), [Community resources](/community/community-resources), [Contributors](/home/contributors)
* **Source:** [Site cleanup](https://github.com/ugurkocde/intunemacadmins/commit/607ef62289a5b4827b8b1b4d302a0838b7874da6)

## Earlier releases

### Version 2.0 · September 2, 2024

**Content update** · Maintainer published

Introduced the Baseline Settings for Intune catalog, covering account security, antivirus, Defender, Edge, FileVault, Gatekeeper, Microsoft AutoUpdate, Office, OneDrive, Platform SSO, restrictions, and software updates.

### Version 1.7 · August 27, 2024

Added Microsoft Defender enrollment, Declarative Device Management, and Rapid Security Response guidance to the Complete Guide to macOS Deployment.

### Version 1.6 · August 23, 2024

Added Troubleshooting Guides, the Enrollment Error page, and Intune Uploader resources.

### Version 1.5 · August 19, 2024

Added page-level feedback, Company Portal LOB deployment guidance, and the managed-device user experience guide.

### Version 1.4 · August 8, 2024

Launched the Complete Guide to macOS Deployment with Apple Business Manager, Intune integration, device enrollment, Platform SSO, and FileVault setup guidance.

### Version 1.3 · August 2, 2024

Added the Snippets catalog with Packaging and Shortcuts.

### Version 1.2 · July 30, 2024

Expanded the FAQ with practical answers covering APNs, device lifecycle, migration, enrollment, Defender, certificates, custom settings, policy timing, local inspection, monitoring, and release tracking.

### Version 1.1 · July 29, 2024

Added the Intune Getting Started Guide, prerequisites, and basic tenant setup.

### Version 1.0.2 · July 25, 2024

Added the What’s New in Intune page and guidance for enrolling a Mac without Apple Business Manager.

### Version 1.0.1 · July 17, 2024

Corrected navigation and page titles and added the Root3 Support App.

### Version 1.0 · July 15, 2024

Published the first guides for Await Final Configuration, Custom Attributes, Declarative Device Management, FileVault, OneDrive Known Folder Move, Platform SSO, file deployment, and Microsoft app updates.


# Getting Started

Begin your journey with easy navigation and comprehensive guides for macOS administration.

Starting is pretty easy. Just navigate the sidebar menu on the left and scroll through the content you are interested in. But let's see how you can get the most value out of the guides.

{% hint style="info" %}
IntuneMacAdmins.com is not here to replace any other Community Project, LinkedIn Group, or Slack Channel. The only goal is to provide macOS-related content in a single place.
{% endhint %}

## Get the Most out of the Content

As you can see on the left, there are multiple topics around macOS. The goal is to add a short overview, a guide to configure the setting or script, as well as delivering insights based on real-world experiences that are not documented anywhere else, e.g., Microsoft Docs.

This list is growing, and we want you to help us improve and add more content. Check out [How to Contribute](/home/how-to-contribute).

## Navigating the Site

* **Sidebar Menu**: Use the sidebar menu on the left to quickly find the topics you are interested in.
* **Search Functionality**: Use the search bar at the top to find specific guides, tools, or best practices.

## Types of Content Available

* **Guides**: Step-by-step instructions on how to set up and configure various macOS settings and tools.
* **Scripts**: Ready-to-use scripts to automate common tasks and improve your workflow.
* **Best Practices**: Recommendations based on industry standards and real-world experiences.
* **Insights**: Unique insights and tips that you won't find in official documentation, shared by community members.

## Contributing to the Site

We encourage community contributions to keep the content up-to-date and comprehensive. Whether it's a new guide, a script, or an insight, your contribution is valuable. Visit the [How to Contribute](/home/how-to-contribute) page to learn more about the process.

## Thank You!

Thank you for being a part of the IntuneMacAdmins community. Together, we can make macOS administration with Microsoft Intune easier and more efficient.


# How to Contribute

Contribute to IntuneMacAdmins by forking the repo, making changes, and submitting a pull request.

We welcome contributions from the community to help improve the content on IntuneMacAdmins. Whether it's a new guide, a script, or an insight, your contribution is valuable.

{% hint style="success" %}
The easiest way is to use the "Edit page" button that you can find at the bottom of every page. If you edit more than one page, we recommend using forks and creating a pull request using the method described below.
{% endhint %}

### Steps to Contribute

1. **Fork the Repository**: Start by forking the [IntuneMacAdmins GitHub repository](https://github.com/ugurkocde/IntuneMacAdmins).
2. **Clone the Repository**: Clone your forked repository to your local machine.

   ```
   git clone https://github.com/your-username/IntuneMacAdmins.git
   ```
3. **Create a New Branch**: Create a new branch for your changes.

   ```
   git checkout -b my-new-branch
   ```
4. **Make Your Changes**: Make the necessary changes or additions to the content.
5. **Commit Your Changes**: Commit your changes with a descriptive message.

   ```
   git commit -m "Add new guide on XYZ"
   ```
6. **Push Your Changes**: Push your changes to your forked repository.

   ```
   git push origin my-new-branch
   ```
7. **Create a Pull Request**: Go to the original repository and create a pull request from your forked repository.


# Contributors ❤️

Share feedback by creating an issue on our GitHub repository to discuss with the community.

## Our Community Contributors

*Thank you to all our contributors for helping us to improve IntuneMacAdmins. Your support is greatly appreciated!*

***

* [\*\*Matthias Choules \*\*](https://github.com/choules) — Consultant @wycomco GmbH
* [**Jordy Witteman**](https://github.com/jordywitteman) — Managing Apple devices @root3nl
* [**Vigneshwaran**](https://github.com/app2pack) — Senior System Engineer @Elsevier
* [**Tobias Almén**](https://github.com/almenscorner) — macOS & MDM Architect @ASSAABLOY


# Our Sponsors ❤️

A thank you to the sponsors who help keep IntuneMacAdmins free for the community.

A big thank you to our sponsor for supporting the Intune Mac Admins community and helping keep these guides, tools, and resources free for everyone.

[![Devote](/files/HVxkpSSRwvZhHzeYi7E5)](https://www.devote.com)

[Visit Devote →](https://www.devote.com)

***

Interested in sponsoring? Reach out on [X](https://x.com/ugurkocde) or [LinkedIn](https://www.linkedin.com/in/ugurkocde/).


# Feedback

Share feedback by creating an issue on our GitHub repository to discuss with the community.

If you have feedback, questions, or suggestions, please create a Issue on the GitHub repository. This way we can track and discuss the feedback with the community.

Here is the link to create a new Issue: [Create Issue](https://github.com/ugurkocde/intunemacadmins/issues)


# What's New in Intune

The released Microsoft changes and important notices that matter for macOS management, with links to the authoritative sources.

We track [released Microsoft Intune changes](https://learn.microsoft.com/en-us/intune/whats-new/), important macOS notices, and substantive Microsoft Defender for Endpoint releases. Each entry links to the authoritative Microsoft source.

## Important macOS notices

Actionable support, enrollment, and service changes that macOS administrators should prepare for.

* **Plan for change: Intune is moving to support macOS 15 and higher later this year** — Microsoft Intune, the Company Portal app, and the Intune mobile device management agent will move to support macOS 15 and later, with the change occurring shortly after Apple's expected release of macOS 27 later in calendar year 2026. Devices already enrolled on macOS 14.x or below will remain enrolled, but new devices running macOS 14.x or below will be unable to enroll. Administrators can review Intune reporting under Devices and All devices, filter by macOS, and ask users to upgrade to a supported OS version. [Details](https://learn.microsoft.com/en-us/intune/whats-new/#plan-for-change-intune-is-moving-to-support-macos-15-and-higher-later-this-year)

## Released Microsoft Intune updates

## Week of July 27, 2026 (Service release 2607)

### Device security

* **Custom compliance settings for macOS** — Microsoft Intune now supports custom compliance settings for macOS, allowing admins to define compliance checks using scripts and JSON rules, similar to existing support for Windows and Linux. This capability can evaluate device configuration, security posture, and other custom attributes not covered by built-in settings. Results appear alongside standard compliance reporting in the Intune admin center. [Details](https://learn.microsoft.com/en-us/intune/whats-new/#custom-compliance-settings-for-macos)

## Week of June 29, 2026 (Service release 2606)

### App management

* **Available macOS PKG apps update automatically when you upload a new version** — Available macOS PKG apps now update automatically on devices when an existing available app policy is edited with a newer app version that uses the same bundle ID, without users needing to select Install or Reinstall in Company Portal. Automatic updates apply when an updated app version is uploaded to Intune and the user has already installed the app. This behavior requires the Microsoft Intune management agent for macOS version 2606.013 or later. [Details](https://learn.microsoft.com/en-us/intune/whats-new/#available-macos-pkg-apps-update-automatically-when-you-upload-a-new-version)

## Week of June 15, 2026

### Device enrollment

* **Enrollment time grouping for new Apple ADE enrollment policies generally available** — Enrollment time grouping is now generally available for Apple automated device enrollment (ADE) on iOS, iPadOS, and macOS. It allows a device's Microsoft Entra security group to be identified during enrollment so policies, apps, and settings can be applied earlier in the setup process. The feature is supported in new Apple ADE enrollment policies. [Details](https://learn.microsoft.com/en-us/intune/whats-new/#enrollment-time-grouping-for-new-apple-ade-enrollment-policies-generally-available)

## Week of June 8, 2026 (Service release 2605)

### Custom top bar elements on Managed Home Screen \<!-- 25008744 -->

* **Disable MAC address randomization on macOS Wi-Fi profiles** — Microsoft Intune now offers a Disable MAC address randomization setting for macOS Wi-Fi profiles, allowing administrators to turn off MAC address randomization on managed macOS devices. Randomized MAC addresses support privacy but can break functionality that relies on a static MAC address, including network access control. The setting applies to macOS 15 and later. [Details](https://learn.microsoft.com/en-us/intune/whats-new/#disable-mac-address-randomization-on-macos-wi-fi-profiles)
* **Use DDM to manage Apple Intelligence settings on devices running 26.4 and later** — With Apple's 26.4 release, several intelligence-related settings in the MDM restrictions payload were deprecated, and Microsoft directs admins to use DDM configurations released in March 2026 instead. The deprecated items include numerous Restrictions in the settings catalog such as Allow Assistant, Allow Dictation, Allow Writing Tools, and Allow Genmoji, along with device restrictions template settings for Siri, keyboard, and dictionary. The changes apply to iOS, iPadOS, and macOS. [Details](https://learn.microsoft.com/en-us/intune/whats-new/#use-ddm-to-manage-apple-intelligence-settings-on-devices-running-26-4-and-later)

## Week of May 11, 2026

### Device enrollment

* **Complete Platform SSO registration during macOS Automated Device Enrollment** — Microsoft documented support for running Platform Single Sign-On during macOS Automated Device Enrollment. Configuration requires creating an Intune settings catalog policy with the Enable Registration During Setup setting, deploying Company Portal 5.2604.0 or newer as a line-of-business app, and setting the ADE policy to use Setup Assistant with modern authentication and await final configuration. When enabled, users gain access to Microsoft Entra ID resources upon arriving at the desktop, and the feature applies to macOS 26 and newer. [Details](https://learn.microsoft.com/en-us/intune/whats-new/#complete-platform-sso-registration-during-macos-automated-device-enrollment)

## Week of April 27, 2026 (Service release 2604)

### Device enrollment

* **Access management for Apple services** — Apple access management settings in Apple Business Manager and Apple School Manager can now be used to configure service access for Apple accounts on organization-owned devices. These controls determine which devices users can sign in to and which apps and services are available to them. The feature applies to iOS, iPadOS, and macOS. [Details](https://learn.microsoft.com/en-us/intune/whats-new/#access-management-for-apple-services)

***

Full source histories: [Microsoft Intune archive](https://learn.microsoft.com/en-us/intune/whats-new-archive) and [Microsoft Defender for Endpoint releases](https://learn.microsoft.com/en-us/defender-endpoint/microsoft-defender-endpoint-releases).


# Community Resources

A list of resources that the community has shared.

We have highlighted a few key resources below and expect this list to grow as more people shift their interest to macOS management in Intune.

We highly recommend joining the [MacAdmins Slack](https://www.macadmins.org/), where you can start discussions with other Intune admins who work with macOS devices.

## Discussion Platforms

* [**MacAdmins Slack**](https://www.macadmins.org/) — The MacAdmins Slack is a community open to anyone, where members can discuss issues they encounter with Apple devices.
* [**Microsoft Mac Admins Group on LinkedIn**](https://www.linkedin.com/groups/13007354/) — This is the Microsoft Mac Admins community! A place for Microsoft Mac Admins who are working with M365 to connect, share, and learn from each other.
* [**Modern Endpoint Management Group on LinkedIn**](https://www.linkedin.com/groups/8761296/) — The Modern Endpoint Management (MEM) group is the official community for Endpoint technologies. This group allows members to share their experiences and knowledge related to the technology discussed within the group.

## Others

* [**Ugur Koc - Personal Blog**](https://ugurkoc.de/)
* [**Somesh Pathak - Personal Blog**](https://www.intuneirl.com/)


# Community Tools and Scripts

A list of tools and scripts that the community has shared.

Here are a couple of tools that we found worth checking out. Please feel free to add your own tool or script repository to this list by editing it on GitHub.

### Privileges (LAPS)

![Privileges](https://raw.githubusercontent.com/SAP/macOS-enterprise-privileges/main/readme_images/privileges_banner.gif)

Privileges for macOS is designed to allow users to work as a standard user for day-to-day use, by providing a quick and easy way to get administrator rights when needed. When you do need admin rights, you can get them by clicking on the Privileges icon in your Dock.

[Download](https://github.com/SAP/macOS-enterprise-privileges)

### Intune macOS Shell Script Samples

This repository is for macOS Intune sample scripts and custom configuration profiles. There are many cases where it is necessary to use a custom profile or shell script to accomplish a task.

[Shell Script Samples on GitHub](https://github.com/microsoft/shell-intune-samples/tree/master/macOS)

### MISA (macOS Intune Support Assistant)

MISA (macOS Intune Support Assistant) is a comprehensive tool designed to streamline and enhance your macOS Intune management experience. It provides a variety of features to assist with device management, software updates, user accounts, and much more, all in an intuitive and user-friendly interface.

[Download](https://github.com/pathaksomesh06/MISA)

### Support Companion

Support Companion is a macOS helper application, designed to empower end-users by providing them with quick and easy access to crucial information and actions. This application is built to streamline a variety of tasks, eliminating the need for extensive searching and complex navigation. Support Companion is equipped with a range of features that enhance user productivity.

[Download](https://github.com/macadmins/SupportCompanion)

### Support App

The Support app is a macOS menu bar app built for users to see basic diagnostic information at a glance and proactively notify them to easily fix small issues. It offers shortcuts to easily access support channels, company resources such as websites, apps or file servers. Natively built with SwiftUI for a modern and native macOS look and feel and customizable to style with your corporate identity.

[Download](https://github.com/root3nl/SupportApp)

### Intune Uploader

Set of AutoPkg processors for uploading and updating apps in Intune.

[Download](https://github.com/almenscorner/intune-uploader)

Recipes for the Intune Uploader can be found here: [almenscorner-recipes](https://github.com/autopkg/almenscorner-recipes)


# ESP for macOS - Swift Dialog

ESP for macOS - Swift Dialog

Here is a screenshot of the Swift Dialog:

![Swift Dialog](/files/W4IdQCX6GXmJsqgE1pye)

Download the PKG from [GitHub](https://github.com/ugurkocde/Intune/blob/main/MacOS/macOS_ESP.pkg)


# FAQ

Find answers to frequently asked questions about macOS management with Intune. Learn about VPP tokens, enrollment, device assignments, updates, and more.

## 1. What happens if my VPP Token expires?

If your VPP (Volume Purchase Program) token expires, the following issues will occur:

* App Deployment Stops: You won't be able to deploy new apps or updates to existing apps to devices enrolled in Intune.
* App Licenses Unavailable: The existing VPP app licenses won't be available for reallocation, and you might encounter issues with app installations.
* Managed Distribution Stops: Managed distribution of apps purchased through Apple Business Manager will cease to function.
* Reporting and Synchronization Issues: Reporting on app installations and synchronization between Intune and Apple Business Manager might fail.

## 2. What happens if my Enrollment Token expires?

If your Apple Device Enrollment Program (DEP) token expires, the following issues will occur:

* Device Enrollment Stops: You won't be able to enroll new devices into Intune using Apple Business Manager. Any devices that need to be enrolled through DEP will not be able to complete the enrollment process.
* Profile Assignment Fails: You won't be able to assign or push configuration profiles, policies, and apps to newly enrolled devices.
* Device Management Issues: Newly added devices in Apple Business Manager won't synchronize with Intune, leading to management and compliance issues.
* Communication Break: There will be a break in communication between Intune and Apple Business Manager, affecting any actions that require syncing, like device information updates.

## 3. User vs Device Assignments

When should you assign a policy to a user versus a device?

### Device groups

If you want to apply settings on a device, regardless of who's signed in, then assign your policies to a devices group. Settings applied to device groups always go with the device, not the user.

### User groups

Policy settings applied to user groups always go with the user, and go with the user when signed in to their many devices.

Source: [User groups vs. device groups](https://learn.microsoft.com/en-us/mem/intune/configuration/device-profile-assign#user-groups-vs-device-groups)

## 4. What are the best practices for managing macOS updates through Intune?

To make use of the newest features that Apple releases for better User experience and increased Device Security (e.g. PSSO with Secure Enclave) it is recommended to be atleast at MacOS Sonoma (Version 14.0) or even better stay current.

There are multiple options to setup updates, Update Policies and Declarative Device Management, for MacOS in Intune and currently its best to combine them.

1. You can setup a default configuration with a "macOS updates policy" where you can define the update behavior (e.g. Download and Install Critical Updates) and setup a schedule.
2. There will be cases where you want to roll out a new update that patches some vulnerabilities in the OS. In those situations better add a new Update Profile with Declarative Device Management to the above setting. You have to create a new configuration profile with the settings catalog where you can configure DDM - Software Updates. In this profile we are able to select a target date time for the update as well as the OS Version we want to install. The user experiences a couple of notifications to save their work before finally the device force reboots at that configured target date and time.

Note:

* Setting up both Profiles will not cause errors in the assignments as both are different payloads.
* Not setting the OS Version in the DDM Profile will automatically install the newest available version for that Mac Device (this depends on the hardware and the OS it supports).

## 5. How can I deploy and manage third-party applications on macOS devices using Intune?

Most vendors offer a .dmg or .pkg file to install the application. Both extensions are supported in Intune and can be uploaded and assigned to Devices and Users.

There could be cases where you have to package your own application e.g. licence files and in those cases you can use some of the steps we provide here: [How to deploy Files](/deploy-files-on-a-mac/how-to-deploy-files)

## 6. Can I enroll a MacOS Device in Intune without ABM?

Yes, you can enroll a MacOS Device in Intune without ABM. You can use the Company Portal App to do so. Devices added this way will have the "Personal" Ownership Type in Intune. The enrollment could therefore be blocked by your device enrollment restrictions.

BUT: Not having the device in ABM means the device is not supervised and therefore the user could wipe a machine and/or remove your MDM profile.

## 7. What happens if my Apple Push Notification service (APNs) Token expires?

The APNs token must be renewed yearly. If you miss the renewal and the grace period, you must re-enroll all devices. Personally-owned devices must re-trigger the enrollment process in Company Portal to get a new management profile, but for corporate-owned device enrolled with Apple Automated Device Enrollment, where the profile is usually non-removable, you must wipe and re-enroll all devices. Make sure you monitor the expiration of the APNs token.

## 8. Which steps do I need to take when a Mac reaches end-of-life?

First of all, you should ensure that the system is properly wiped and all data is deleted. From Intune you can send a wipe request. The device object will get deleted with the wipe sent from Intune, but if start the wipe on the device itself, you need to delete the Intune object. Make sure the corresponding Entra ID object was also deleted. If not, do so manually. If your Mac was registered in your Apple Business or School Manager, you should also delete it from there.

## 9. Do I need to reset my Mac to enroll it in Intune?

No, that is not needed by default. You can start the enrollment on an operating Mac with enrollment through Company Portal. However, if you want the device to be completely corporate-owned and managed, you should consider a reset and import to Apple Business or School Manager and choose Apple Automated Device Enrollment for the provisioning.

## 10. Can I add my Mac to my Apple or Business or School Manager after I ordered it?

Usually your vendor or supplier registers your MacOS devices in your instance of ABM/ASM. If that is not the case, you can manually add the Mac. The simplest way to achieve Automated Device Enrollment, is to reset the Mac and start the setup process until you get to the region selection. From there you can add the Mac by scanning the shape with your iPhone and the Apple Configurator App. [Apple Guide](https://support.apple.com/guide/apple-configurator/add-a-new-mac-apd65c9ff558/ios)

## 11. We are considering switching our existing MDM to Intune to manage macOS, how should we plan this?

Switching from an alternate MDM to Intune for macOS is worth trying! Most often you already have an Intune license and maybe even use Intune to manage other operating systems. Planning a switch includes multiple steps, but can be broken down into the most crucial: 1. Do a Proof-of-Concept (POC) and verify if all your desired features are given 2. Check process compatibility, to see if Intune supports your established organizational processes 3. Plan the Intune deployment and define which configurations should be done. Orientate with frameworks and best practices. This community is a great start to do so :)

## 12. MacOS and Apple security - where do I get information?

Different operating systems and vendors offer different security technologies, features and services. Apple published their [Platform Security Guide](https://support.apple.com/guide/security/welcome/web) with all you need to know about macOS and Apple security.

## 13. Can I onboard my Mac to Defender for Endpoint?

Of course! Defender for Endpoint supports macOS and onboarding can be achieved with Intune configuration profiles and a Defender onboarding package.

## 14. Does Intune support certificate deployment to macOS?

Yes, Intune supports trusted certificate deployment, or PKCS, or SCEP certificates to be deployed to managed Macs. All you need is Cloud PKI from Intune Suite or the Intune Certificate Connector to deploy certificates from your internal PKI to the Mac.

## 15. Some settings are not covered by Intune (UI), what do I do?

There are multiple things you can do, if settings are not reflected in Settings Catalog or via a Template in Intune. Of course you can always create a shell script to configure any setting on the system. But the preferred way may be, to create a Intune custom .mobileconfig file and deploy it to your Macs.

## 16. The profiles of Intune are applied too slow to my managed Macs. What can I do?

First of all, you should identify potential misconfiguration in the profiles. Make sure there are no errors, conflicts or misconfigurations. To speed up the processing of Intune, it is recommended to use Intune filters instead of Entra dynamic or static groups.

## 17. Where can I see which profiles of Intune were applied locally on my Mac?

Go to Settings > Privacy & Security. There you should see all profiles and policies applied by the management system.

## 18. How do I monitor my managed Macs in Intune?

You can see all enrolled Macs in the platform page of Intune under macOS. You can choose any device and see hardware information, Intune metadata and the status of applied profiles, policies and apps. Additionally, under Devices > Monitoring you have multiple built-in Intune reports in different categories.

## 19. How do I stay up to date with new Intune macOS features?

The best way to stay up to date with new Intune macOS features is to follow communites and the official Microsoft blogs. Visiting events is another crucial part to meet the latest & greatest new features and experts on the field. Of course, also this community is a great place to learn more and get updates.

## 20. How do I get an Apple Business or School Manager?

You need to register at [Apple Business](https://support.apple.com/guide/apple-business-manager/sign-up-axm402206497/web), get a D-U-N-S number and let Apple verify your request. Afterwards, it is possible to configure the various connections to Intune and use all services.


# Importing Baseline Settings into Intune

Step-by-step guide to importing baseline settings into your Intune tenant.

Following these steps, you will be able to import the baseline settings into your Intune tenant.

1. Download the JSON files from the [OpenIntuneBaseline](https://github.com/SkipToTheEndpoint/OpenIntuneBaseline/tree/main/MACOS/NativeImport) repository.
2. Go to the [Intune Portal](https://intune.microsoft.com/#home) and select **Devices**.
3. Select **macOS** then **Configuration profiles** and click on **Import profile**. ![Intune Import Profile](/files/kqOJbnCg4MP3ckMoAGNh)
4. Drag and drop the **JSON file** into the window and choose a **name** for the profile. ![Drag and Drop JSON File](/files/yk9oJS0nbqYN5JLCSp2C)
5. Click on **Save** and wait for the profile to be created.
6. Repeat steps 3-5 for each JSON file.

{% hint style="info" %}
**Tips**

* Ensure you have the necessary permissions to import profiles in Intune.
* Double-check the JSON files for any errors before importing.
* Consider creating a test profile first to ensure the settings are applied correctly.
  {% endhint %}

{% hint style="info" %}
**Troubleshooting**

* If you encounter an error during import, verify the JSON file format.
* Check your network connection and try again.
* Ensure that the JSON file is not corrupted or incomplete.
* Consult the [Intune troubleshooting guide](https://docs.microsoft.com/en-us/mem/intune/configuration/device-profile-troubleshoot) for more help.
  {% endhint %}


# Contributing to the Baseline Settings

A guide on contributing to the baseline settings.

If you want to contribute to the baseline settings, you can do so by following these steps:

## Prerequisites

* A GitHub account
* Git installed on your local machine

1. Fork the repository [OpenIntuneBaseline](https://github.com/SkipToTheEndpoint/OpenIntuneBaseline/tree/main)
2. Clone your forked repository to your local machine

   ```bash
   git clone https://github.com/your-username/OpenIntuneBaseline.git
   ```
3. Create a new branch

   ```bash
   git checkout -b your-branch-name
   ```
4. Make your changes
5. Commit your changes

   ```bash
   git add .
   git commit -m "Description of your changes"
   ```
6. Push your changes to your forked repository

   ```bash
   git push origin your-branch-name
   ```
7. Create a pull request from your forked repository to the main repository

All changes will be reviewed and merged into the main branch. Please ensure your code follows the project's coding standards and includes appropriate documentation.

{% hint style="info" %}
If you have any questions or need help, feel free to open an issue in the repository.
{% endhint %}


# Settings Overview

Overview of all settings with best practices for Intune.

## Overview of all settings

* [**Platform SSO**](/baseline-settings-for-intune/settingsoverview/platformsso) — How to configure Platform SSO for your Intune tenant.
* [**Antivirus Configuration**](/baseline-settings-for-intune/settingsoverview/antivirusconfiguration) — How to configure Antivirus Configuration for your Intune tenant.
* [**MDE Configuration**](/baseline-settings-for-intune/settingsoverview/mdeconfiguration) — How to configure MDE Configuration for your Intune tenant.
* [**Accounts and Login**](/baseline-settings-for-intune/settingsoverview/accountsandlogin) — How to configure Accounts and Login for your Intune tenant.
* [**Restrictions**](/baseline-settings-for-intune/settingsoverview/restrictions) — How to configure Restrictions for your Intune tenant.
* [**FileVault**](/baseline-settings-for-intune/settingsoverview/filevault) — How to configure FileVault for your Intune tenant.
* [**Gatekeeper**](/baseline-settings-for-intune/settingsoverview/gatekeeper) — How to configure Gatekeeper for your Intune tenant.
* [**MAU Configuration**](/baseline-settings-for-intune/settingsoverview/mauconfiguration) — How to configure MAU for your Intune tenant.
* [**Microsoft Edge Password Management**](/baseline-settings-for-intune/settingsoverview/edgepasswordmanagement) — How to configure Microsoft Edge Password Management for your Intune tenant.
* [**Microsoft Edge Security**](/baseline-settings-for-intune/settingsoverview/edgesecurity) — How to configure Microsoft Edge Security for your Intune tenant.
* [**Microsoft Edge Extensions**](/baseline-settings-for-intune/settingsoverview/edgeextensions) — How to configure Microsoft Edge Extensions for your Intune tenant.
* [**Microsoft Edge Profiles and Sign-in Sync**](/baseline-settings-for-intune/settingsoverview/edgeprofilessigninsync) — How to configure Microsoft Edge Profiles and Sign-in Sync for your Intune tenant.
* [**Microsoft Edge Updates**](/baseline-settings-for-intune/settingsoverview/edgeupdates) — How to configure Microsoft Edge Updates for your Intune tenant.
* [**Microsoft Office Configuration**](/baseline-settings-for-intune/settingsoverview/officeconfiguration) — How to configure Microsoft Office Configuration for your Intune tenant.
* [**OneDrive Service and Access**](/baseline-settings-for-intune/settingsoverview/onedriveserviceandaccess) — How to configure OneDrive Service and Access for your Intune tenant.
* [**OneDrive Known Folder Move**](/baseline-settings-for-intune/settingsoverview/onedriveknownfoldermove) — How to configure OneDrive Known Folder Move for your Intune tenant.
* [**Software Updates**](/baseline-settings-for-intune/settingsoverview/updates) — How to configure Software Updates for your Intune tenant.


# Platform SSO

How to configure Platform SSO for your Intune tenant.

{% hint style="info" %}
Click on the link to download the JSON file from [GitHub](https://github.com/SkipToTheEndpoint/OpenIntuneBaseline/blob/main/MACOS/NativeImport/MacOS%20-%20OIB%20-%20Authentication%20-%20D%20-%20Platform%20SSO%20-%20v1.0.json)
{% endhint %}

## Platform SSO

| Setting                            | Value                                                                                         | Description                                                                                                                                                                                                                                                                                                                                                                              |
| ---------------------------------- | --------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Authentication Method (Deprecated) | UserSecureEnclaveKey                                                                          | The Platform SSO authentication method the extension uses. Requires that the SSO Extension also supports the method. Available in macOS 13 and later.                                                                                                                                                                                                                                    |
| Screen Locked Behavior             | Do Not Handle                                                                                 | When set to Do Not Handle, the request continues without SSO. Available in iOS 15 and later and macOS 12 and later.                                                                                                                                                                                                                                                                      |
| Registration Token                 | DEVICEREGISTRATION                                                                            | The token this device uses for registration with Platform SSO. Use it for silent registration with the Identity Provider. Requires that 'AuthenticationMethod' isn't empty. Available in macOS 13 and later.                                                                                                                                                                             |
| Authentication Method              | UserSecureEnclaveKey                                                                          | The Platform SSO authentication method to be used with the extension. Requires that the SSO Extension also support the method.                                                                                                                                                                                                                                                           |
| Enable Authorization               | Enabled                                                                                       | Enables using identity provider accounts at authorization prompts. Requires 'UseSharedDeviceKeys' is true. The account will be assigned groups using the 'AdministratorGroups', 'AdditionalGroups', or 'AuthorizationGroups'.                                                                                                                                                            |
| Enable Create User At Login        | Enabled                                                                                       | Enables creating new users at the login window with either Passwords or SmartCards. Requires 'UseSharedDeviceKeys' is true.                                                                                                                                                                                                                                                              |
| New User Authorization Mode        | Standard                                                                                      | This setting affects the permissions for accounts created at login by Platform SSO. It is only used when the account is created. Use of the following: Standard, Admin, Groups.                                                                                                                                                                                                          |
| Team Identifier                    | UBF8T346G9                                                                                    | The team identifier of the app extension. This key is required on macOS and ignored elsewhere.                                                                                                                                                                                                                                                                                           |
| Extension Identifier               | com.microsoft.CompanyPortalMac.ssoextension                                                   | The bundle identifier of the app extension that performs SSO for the specified URLs.                                                                                                                                                                                                                                                                                                     |
| Type                               | Redirect                                                                                      | The type of SSO.                                                                                                                                                                                                                                                                                                                                                                         |
| URLs                               | <https://login.microsoftonline.com>, <https://login.microsoft.com>, <https://sts.windows.net> | An array of URL prefixes of identity providers where the app extension performs SSO. Required for Redirect payloads. Ignored for Credential payloads. The URLs must begin with http\:// or https\://, the scheme and host name are matched case-insensitively, query parameters and URL fragments are not allowed, and the URLs of all installed Extensible SSO payloads must be unique. |

## Token To User Mapping

| Setting                 | Value               | Description                                                                                                                                                           |
| ----------------------- | ------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Account Name            | preferred\_username | The claim name to use for the user's account name.                                                                                                                    |
| Full Name               | name                | The claim name to use for the user's full name.                                                                                                                       |
| Use Shared Device Keys  | Enabled             | If set to true, Platform SSO will use the same signing and encryption keys for all users.                                                                             |
| User Authorization Mode | Standard            | This setting affects the permissions after authentication by Platform SSO. It is applied each time user authenticates. Use of the following: Standard, Admin, Groups. |

## Extension Data

| Setting | Value                              | Description                                                                                                                                 |
| ------- | ---------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------- |
| Type    | Integer                            | Keys and values to pass to the app extension.                                                                                               |
| Value   | 1                                  | Keys and values to pass to the app extension.                                                                                               |
| Key     | disable\_explicit\_app\_prompt     | Additional extension-specific data to pass to the app extension.                                                                            |
| Type    | Integer                            | Keys and values to pass to the app extension.                                                                                               |
| Value   | 1                                  | Keys and values to pass to the app extension.                                                                                               |
| Key     | browser\_sso\_interaction\_enabled | Additional extension-specific data to pass to the app extension.                                                                            |
| Type    | String                             | Keys and values to pass to the app extension.                                                                                               |
| Value   | com.microsoft.,com.apple.          | Keys and values to pass to the app extension.                                                                                               |
| Key     | AppPrefixAllowList                 | An array of bundle identifiers of apps that don't use SSO provided by this extension. Available in iOS 15 and later and macOS 12 and later. |


# Antivirus Configuration

How to configure Antivirus Configuration for your Intune tenant.

{% hint style="info" %}
Click on the link to download the JSON file from [GitHub](https://github.com/SkipToTheEndpoint/OpenIntuneBaseline/blob/main/MACOS/NativeImport/MacOS%20-%20OIB%20-%20Defender%20Antivirus%20-%20D%20-%20Antivirus%20Configuration%20-%20v1.0.json)
{% endhint %}

## Antivirus engine

| Setting                                              | Value                              |
| ---------------------------------------------------- | ---------------------------------- |
| Disallowed threat actions                            | allow, restore                     |
| Enforcement level                                    | real\_time                         |
| Exclusions merge                                     | admin\_only                        |
| Run a scan after definitions are updated             | Enabled                            |
| Scanning inside archive files (on-demand scans only) | True                               |
| Threat type (1)                                      | potentially\_unwanted\_application |
| Action to take (1)                                   | block                              |
| Threat type (2)                                      | archive\_bomb                      |
| Action to take (2)                                   | block                              |
| Threat type settings merge                           | admin\_only                        |

## Cloud delivered protection preferences

| Setting                                       | Value    |
| --------------------------------------------- | -------- |
| Automatic security intelligence updates       | Enabled  |
| Cloud Block Level                             | normal   |
| Diagnostic collection level                   | optional |
| Enable / disable automatic sample submissions | Enabled  |
| Enable / disable cloud delivered protection   | Enabled  |

## Endpoint Detection and Response (EDR) preferences

| Setting                        | Value    |
| ------------------------------ | -------- |
| Enable / disable early preview | Disabled |

## Features

| Setting               | Value   |
| --------------------- | ------- |
| Use System Extensions | enabled |

## Network protection

| Setting           | Value |
| ----------------- | ----- |
| Enforcement level | block |

## Tamper protection

| Setting                      | Value                                                                     |
| ---------------------------- | ------------------------------------------------------------------------- |
| Enforcement level            | block                                                                     |
| Process's TeamIdentifier     | UBF8T346G9                                                                |
| Process path                 | /Library/Intune/Microsoft Intune Agent.app/Contents/MacOS/IntuneMdmDaemon |
| Process's Signing Identifier | IntuneMdmDaemon                                                           |

## User interface preferences

| Setting                             | Value    |
| ----------------------------------- | -------- |
| Control sign-in to consumer version | disabled |
| Show / hide status menu icon        | Disabled |


# Defender for Endpoint (MDE) Configuration

How to configure Defender for Endpoint (MDE) Configuration for your Intune tenant.

{% hint style="info" %}
Click on the link to download the JSON file from [GitHub](https://github.com/SkipToTheEndpoint/OpenIntuneBaseline/blob/main/MACOS/NativeImport/MacOS%20-%20OIB%20-%20Defender%20Antivirus%20-%20D%20-%20MDE%20Configuration%20-%20v1.0.json)
{% endhint %}

## Login Service Management - Managed Login Items

| Setting    | Value                |
| ---------- | -------------------- |
| Rule Value | com.microsoft.dlp    |
| Rule Type  | Label Prefix         |
| Rule Value | com.microsoft.fresno |
| Rule Type  | Label Prefix         |

## Microsoft AutoUpdate (MAU)

| Setting                           | Value           |
| --------------------------------- | --------------- |
| Microsoft Defender Application ID | WDAV00          |
| Microsoft Defender LCID           | 1033            |
| Update channel override           | Current Channel |

## Privacy Preferences Policy Control

| Setting          | Value                                                                                                                                                                                                                                                |
| ---------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Allowed          | True                                                                                                                                                                                                                                                 |
| Authorization    | Allow                                                                                                                                                                                                                                                |
| Static Code      | False                                                                                                                                                                                                                                                |
| Code Requirement | identifier "com.microsoft.wdav" and anchor apple generic and certificate 1\[field.1.2.840.113635.100.6.2.6] /\* exists */ and certificate leaf\[field.1.2.840.113635.100.6.1.13] /* exists \*/ and certificate leaf\[subject.OU] = UBF8T346G9        |
| Identifier Type  | bundle ID                                                                                                                                                                                                                                            |
| Identifier       | com.microsoft.wdav                                                                                                                                                                                                                                   |
| Allowed          | True                                                                                                                                                                                                                                                 |
| Authorization    | Allow                                                                                                                                                                                                                                                |
| Static Code      | False                                                                                                                                                                                                                                                |
| Code Requirement | identifier "com.microsoft.wdav.epsext" and anchor apple generic and certificate 1\[field.1.2.840.113635.100.6.2.6] /\* exists */ and certificate leaf\[field.1.2.840.113635.100.6.1.13] /* exists \*/ and certificate leaf\[subject.OU] = UBF8T346G9 |
| Identifier Type  | bundle ID                                                                                                                                                                                                                                            |
| Identifier       | com.microsoft.wdav.epsext                                                                                                                                                                                                                            |
| Allowed          | True                                                                                                                                                                                                                                                 |
| Authorization    | Allow                                                                                                                                                                                                                                                |
| Static Code      | False                                                                                                                                                                                                                                                |
| Code Requirement | identifier "com.microsoft.dlp.daemon" and anchor apple generic and certificate 1\[field.1.2.840.113635.100.6.2.6] /\* exists */ and certificate leaf\[field.1.2.840.113635.100.6.1.13] /* exists \*/ and certificate leaf\[subject.OU] = UBF8T346G9  |
| Identifier Type  | bundle ID                                                                                                                                                                                                                                            |
| Identifier       | com.microsoft.dlp.daemon                                                                                                                                                                                                                             |

## System Extensions

| Setting                   | Value                                                |
| ------------------------- | ---------------------------------------------------- |
| Team Identifier           | UBF8T346G9                                           |
| Allowed System Extensions | com.microsoft.wdav.epsext, com.microsoft.wdav.netext |

## Notifications

| Setting                     | Value                   |
| --------------------------- | ----------------------- |
| Show In Notification Center | True                    |
| Notifications Enabled       | True                    |
| Show In Lock Screen         | False                   |
| Bundle Identifier           | com.microsoft.wdav.tray |
| Badges Enabled              | True                    |
| Alert Type                  | Temporary Banner        |
| Sounds Enabled              | True                    |
| Critical Alert Enabled      | False                   |

## Web Content Filter

| Setting                                     | Value                                                                                                                                                                                                                                                |
| ------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Filter Data Provider Bundle Identifier      | com.microsoft.wdav.netext                                                                                                                                                                                                                            |
| User Defined Name                           | Microsoft Defender Content Filter                                                                                                                                                                                                                    |
| Filter Grade                                | inspector                                                                                                                                                                                                                                            |
| Filter Sockets                              | True                                                                                                                                                                                                                                                 |
| Filter Packets                              | False                                                                                                                                                                                                                                                |
| Plugin Bundle ID                            | com.microsoft.wdav                                                                                                                                                                                                                                   |
| Filter Data Provider Designated Requirement | identifier "com.microsoft.wdav.netext" and anchor apple generic and certificate 1\[field.1.2.840.113635.100.6.2.6] /\* exists */ and certificate leaf\[field.1.2.840.113635.100.6.1.13] /* exists \*/ and certificate leaf\[subject.OU] = UBF8T346G9 |
| Organization                                | JAMF Software                                                                                                                                                                                                                                        |


# Accounts and Login

How to configure Accounts and Login for your Intune tenant.

{% hint style="info" %}
Click on the link to download the JSON file from [GitHub](https://github.com/SkipToTheEndpoint/OpenIntuneBaseline/blob/main/MACOS/NativeImport/MacOS%20-%20OIB%20-%20Device%20Security%20-%20D%20-%20Accounts%20and%20Login%20-%20v1.0.json)
{% endhint %}

## Accounts

| Setting               | Value |
| --------------------- | ----- |
| Disable Guest Account | True  |

## Login

| Setting                         | Value    |
| ------------------------------- | -------- |
| Admin Host Info                 | HostName |
| Disable Console Access          | True     |
| Hide Admin Users                | False    |
| Disable Login Items Suppression | True     |


# Restrictions

How to configure Restrictions for your Intune tenant.

{% hint style="info" %}
Click on the link to download the JSON file from [GitHub](https://github.com/SkipToTheEndpoint/OpenIntuneBaseline/blob/main/MACOS/NativeImport/MacOS%20-%20OIB%20-%20Device%20Security%20-%20D%20-%20Restrictions%20-%20v1.0.json)
{% endhint %}

## System Preferences

| Setting                   | Value                                                                                                                                                                                                                                                                                                                                |
| ------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Disabled Preference Panes | com.apple.AirDrop-Handoff-Settings.extension, com.apple.Family-Settings.extension, com.apple.Game-Center-Settings.extension, com.apple.Siri-Settings.extension, com.apple.Startup-Disk-Settings.extension, com.apple.Time-Machine-Settings.extension, com.apple.WalletSettingsExtension, com.apple.systempreferences.AppleIDSettings |

## Restrictions

| Setting                              | Value    |
| ------------------------------------ | -------- |
| Allow Bluetooth Sharing Modification | False    |
| Allow Password Sharing               | False    |
| Allow File Sharing Modification      | False    |
| Allow Erase Content And Settings     | False    |
| Allow Air Play Incoming Requests     | Disabled |
| Allow Cloud Private Relay            | False    |
| Allow Cloud Photo Library            | False    |
| Allow Cloud Document Sync            | False    |
| Allow Activity Continuation          | False    |
| Allow Cloud Bookmarks                | False    |
| Allow Cloud Freeform                 | False    |
| Allow Cloud Calendar                 | False    |
| Allow Assistant                      | False    |
| Allow Game Center                    | False    |
| Allow Auto Unlock                    | False    |
| Allow Startup Disk Modification      | False    |
| Allow Device Name Modification       | False    |
| Allow Find My Device                 | False    |
| Allow Internet Sharing Modification  | False    |
| Allow Find My Friends                | False    |
| Allow AirDrop                        | False    |
| Allow Cloud Notes                    | False    |
| Allow Multiplayer Gaming             | False    |
| Allow Local User Creation            | False    |
| Allow Apple Personalized Advertising | False    |
| Allow Printer Sharing Modification   | False    |
| Allow Account Modification           | False    |
| Safari Allow Autofill                | False    |
| Allow Cloud Reminders                | False    |
| Allow Password Proximity Requests    | False    |
| Allow Cloud Mail                     | False    |
| Allow Cloud Address Book             | False    |
| Allow Adding Game Center Friends     | False    |
| Allow Cloud Desktop And Documents    | False    |
| Allow iTunes File Sharing            | False    |
| Allow Cloud Keychain Sync            | False    |


# FileVault

How to configure FileVault for your Intune tenant.

{% hint style="info" %}
Click on the link to download the JSON file from [GitHub](https://github.com/SkipToTheEndpoint/OpenIntuneBaseline/blob/main/MACOS/NativeImport/MacOS%20-%20OIB%20-%20Disk%20Encryption%20-%20D%20-%20FileVault%20-%20v1.0.json)
{% endhint %}

## FileVault

| Setting                         | Value    |
| ------------------------------- | -------- |
| Recovery Key Rotation In Months | 6 months |
| Enable                          | On       |
| Force Enable In Setup Assistant | True     |

## FileVault Options

| Setting                               | Value |
| ------------------------------------- | ----- |
| Prevent FileVault From Being Disabled | True  |

## FileVault Recovery Key Escrow

| Setting  | Value                                                                                                                                                                                                                                           |
| -------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Location | You can retrieve the personal recovery key for your macOS device from the Microsoft Intune app, Company Portal website, or Company Portal apps for Android and iOS/iPadOS. Support cannot access recovery keys that belong to personal devices. |


# Gatekeeper

How to configure Gatekeeper for your Intune tenant.

{% hint style="info" %}
Click on the link to download the JSON file from [GitHub](https://github.com/SkipToTheEndpoint/OpenIntuneBaseline/blob/main/MACOS/NativeImport/MacOS%20-%20OIB%20-%20Firewall%20-%20D%20-%20Gatekeeper%20-%20v1.0.json).

Note: the above JSON file does not currently include the **System Policy Managed** > **Disable Override** payload.
{% endhint %}

## FireWall

| Setting             | Value |
| ------------------- | ----- |
| Enable Stealth Mode | True  |
| Enable Logging      | True  |
| Enable Firewall     | True  |
| Block All Incoming  | False |

## System Policy Control

| Setting                        | Value    |
| ------------------------------ | -------- |
| Enable XProtect Malware Upload | Disabled |
| Allow Identified Developers    | True     |
| Enable Assessment              | True     |

## System Policy Managed

| Setting          | Value |
| ---------------- | ----- |
| Disable Override | True  |


# Microsoft AutoUpdate (MAU) Configuration

How to configure Microsoft AutoUpdate (MAU) for your Intune tenant.

{% hint style="info" %}
Click on the link to download the JSON file from [GitHub](https://github.com/SkipToTheEndpoint/OpenIntuneBaseline/blob/main/MACOS/NativeImport/MacOS%20-%20OIB%20-%20Microsoft%20AutoUpdate%20-%20D%20-%20MAU%20Configuration%20-%20v1.0.json)
{% endhint %}

## Service Management - Managed Login Items

| Setting    | Value                     |
| ---------- | ------------------------- |
| Comment    | MAU                       |
| Rule Value | com.microsoft.autoupdate2 |
| Rule Type  | Bundle Identifier         |

## Microsoft AutoUpdate (MAU)

| Setting                                          | Value                                                                                                           |
| ------------------------------------------------ | --------------------------------------------------------------------------------------------------------------- |
| Automatically acknowledge data collection policy | Acknowledge - send required data                                                                                |
| Days before forced updates                       | 14                                                                                                              |
| Deferred updates                                 | Defer 3 days                                                                                                    |
| Disable Office Insider membership                | True                                                                                                            |
| Enable AutoUpdate                                | True                                                                                                            |
| Enable check for updates                         | True                                                                                                            |
| Guard against app modification                   | Enabled                                                                                                         |
| Register app on launch                           | True                                                                                                            |
| Update cache server                              | <https://res.public.onecdn.static.microsoft/mro1cdnstorage/C1297A47-86C4-4C1F-97FA-950631F94777/MacAutoupdate/> |
| Update channel                                   | Current Channel (Monthly)                                                                                       |
| Updater optimization technique                   | Lower processor overhead                                                                                        |


# Microsoft Edge Password Management

How to configure Microsoft Edge Password Management for your Intune tenant.

{% hint style="info" %}
Click on the link to download the JSON file from [GitHub](https://github.com/SkipToTheEndpoint/OpenIntuneBaseline/blob/main/MACOS/NativeImport/MacOS%20-%20OIB%20-%20Microsoft%20Edge%20-%20D%20-%20Password%20Management%20-%20v1.0.json)
{% endhint %}

## Microsoft Edge

| Setting                                         | Value                                                      |
| ----------------------------------------------- | ---------------------------------------------------------- |
| Allow Microsoft Edge to monitor user passwords  | Allowed                                                    |
| Configure password protection warning trigger   | Password protection warning is triggered by password reuse |
| Enable saving passwords to the password manager | Enabled                                                    |


# Microsoft Edge Security

How to configure Microsoft Edge Security for your Intune tenant.

{% hint style="info" %}
Click on the link to download the JSON file from [GitHub](https://github.com/SkipToTheEndpoint/OpenIntuneBaseline/blob/main/MACOS/NativeImport/MacOS%20-%20OIB%20-%20Microsoft%20Edge%20-%20D%20-%20Security%20-%20v1.0.json)
{% endhint %}

## Microsoft Edge

| Setting                                                                                | Value                                                                                                                      |
| -------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------- |
| Ads setting for sites with intrusive ads                                               | Block ads on sites with intrusive ads. (Default value)                                                                     |
| Allow download restrictions                                                            | Block dangerous downloads                                                                                                  |
| Allow importing of browser settings                                                    | Disabled                                                                                                                   |
| Allow importing of browsing history                                                    | Disabled                                                                                                                   |
| Allow importing of home page settings                                                  | Disabled                                                                                                                   |
| Allow importing of payment info                                                        | Disabled                                                                                                                   |
| Allow importing of saved passwords                                                     | Disabled                                                                                                                   |
| Allow importing of search engine settings                                              | Disabled                                                                                                                   |
| Allow managed extensions to use the Enterprise Hardware Platform API                   | Disabled                                                                                                                   |
| Allow personalization of ads, search and news by sending browsing history to Microsoft | Disabled                                                                                                                   |
| Allow queries to a Browser Network Time service                                        | Enabled                                                                                                                    |
| Allow user-level native messaging hosts (installed without admin permissions)          | Disabled                                                                                                                   |
| Automatically import another browser's data and settings at first run                  | Disables automatic import, and the import section of the first-run experience is skipped                                   |
| Block tracking of users' web-browsing activity                                         | Balanced (blocks harmful trackers and trackers from sites user has not visited; content and ads will be less personalized) |
| Clear browsing data when Microsoft Edge closes                                         | Disabled                                                                                                                   |
| Clear cached images and files when Microsoft Edge closes                               | Disabled                                                                                                                   |
| Configure Microsoft Defender SmartScreen                                               | Enabled                                                                                                                    |
| Configure Microsoft Defender SmartScreen to block potentially unwanted apps            | Enabled                                                                                                                    |
| Control communication with the Experimentation and Configuration Service               | Disable communication with the Experimentation and Configuration Service                                                   |
| DNS interception checks enabled                                                        | Enabled                                                                                                                    |
| Enable AutoFill for addresses                                                          | Disabled                                                                                                                   |
| Enable AutoFill for credit cards                                                       | Disabled                                                                                                                   |
| Enable Google Cast                                                                     | Disabled                                                                                                                   |
| Enable Proactive Authentication                                                        | Disabled                                                                                                                   |
| Hide the First-run experience and splash screen                                        | Enabled                                                                                                                    |
| Minimum TLS version enabled                                                            | TLS 1.2                                                                                                                    |
| Prevent bypassing Microsoft Defender SmartScreen prompts for sites                     | Enabled                                                                                                                    |
| Prevent bypassing of Microsoft Defender SmartScreen warnings about downloads           | Enabled                                                                                                                    |
| Supported authentication schemes                                                       | ntlm,negotiate                                                                                                             |


# Microsoft Edge Extensions

How to configure Microsoft Edge Extensions for your Intune tenant.

{% hint style="info" %}
Click on the link to download the JSON file from [GitHub](https://github.com/SkipToTheEndpoint/OpenIntuneBaseline/blob/main/MACOS/NativeImport/MacOS%20-%20OIB%20-%20Microsoft%20Edge%20-%20U%20-%20Extensions%20-%20v1.0.json)
{% endhint %}

## Microsoft Edge

| Setting                                         | Value                                                              |
| ----------------------------------------------- | ------------------------------------------------------------------ |
| Allow specific extensions to be installed       | odfafepnkmbhccpbejgmiehpchacaeak                                   |
| Blocks external extensions from being installed | Enabled                                                            |
| Control which extensions are installed silently | nkbndigcebkoaejohleckhekfmcecfja, ofefcgjbeghpigppfmkologfjadafddi |
| Control which extensions cannot be installed    | \*                                                                 |


# Microsoft Edge Profiles and Sign-in Sync

How to configure Microsoft Edge Profiles and Sign-in Sync for your Intune tenant.

{% hint style="info" %}
Click on the link to download the JSON file from [GitHub](https://github.com/SkipToTheEndpoint/OpenIntuneBaseline/blob/main/MACOS/NativeImport/MacOS%20-%20OIB%20-%20Microsoft%20Edge%20-%20U%20-%20Profiles%2C%20Sign-In%20and%20Sync%20-%20v1.0.json)
{% endhint %}

## Microsoft Edge

| Setting                                                                       | Value                                     |
| ----------------------------------------------------------------------------- | ----------------------------------------- |
| Browser sign-in settings                                                      | Force users to sign-in to use the browser |
| Enable profile creation from the Identity flyout menu or the Settings page    | Disabled                                  |
| Enable use of ephemeral profiles                                              | Disabled                                  |
| Force synchronization of browser data and do not show the sync consent prompt | Enabled                                   |


# Microsoft Edge Updates

How to configure Microsoft Edge Updates for your Intune tenant.

{% hint style="info" %}
Click on the link to download the JSON file from [GitHub](https://github.com/SkipToTheEndpoint/OpenIntuneBaseline/blob/main/MACOS/NativeImport/MacOS%20-%20OIB%20-%20Microsoft%20Edge%20-%20U%20-%20Updates%20-%20v1.0.json)
{% endhint %}

## Service Management - Managed Login Items

| Setting    | Value                     |
| ---------- | ------------------------- |
| Comment    | Edge Updater              |
| Rule Value | com.microsoft.EdgeUpdater |
| Rule Type  | Label Prefix              |

## Microsoft Edge

| Setting                                                                             | Value                                                                                |
| ----------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------ |
| Enable component updates in Microsoft Edge                                          | Enabled                                                                              |
| Notify a user that a browser restart is recommended or required for pending updates | Required - Show a recurring prompt to the user indicating that a restart is required |


# Microsoft Office Configuration

How to configure Microsoft Office Configuration for your Intune tenant.

{% hint style="info" %}
Click on the link to download the JSON file from [GitHub](https://github.com/SkipToTheEndpoint/OpenIntuneBaseline/blob/main/MACOS/NativeImport/MacOS%20-%20OIB%20-%20Microsoft%20Office%20-%20D%20-%20Office%20Configuration%20-%20v1.0.json)
{% endhint %}

## Service Management - Managed Login Items

| Setting    | Value                                   |
| ---------- | --------------------------------------- |
| Comment    | Office Licensing Helper                 |
| Rule Value | com.microsoft.office.licensingV2.helper |
| Rule Type  | Bundle Identifier                       |

## Microsoft Office

| Setting                         | Value             |
| ------------------------------- | ----------------- |
| Enable automatic sign-in        | True              |
| Office Activation Email Address | userprincipalname |


# OneDrive Service and Access

How to configure OneDrive Service and Access for your Intune tenant.

{% hint style="info" %}
Click on the link to download the JSON file from [GitHub](https://github.com/SkipToTheEndpoint/OpenIntuneBaseline/blob/main/MACOS/NativeImport/MacOS%20-%20OIB%20-%20Microsoft%20OneDrive%20-%20D%20-%20Service%20and%20Access%20-%20v1.0.json)
{% endhint %}

## Service Management - Managed Login Items

| Setting    | Value                          |
| ---------- | ------------------------------ |
| Comment    | OneDrive Launcher              |
| Rule Value | com.microsoft.OneDriveLauncher |
| Rule Type  | Bundle Identifier Prefix       |

## Privacy Preferences Policy Control

| Setting          | Value                                                                                                                                                                                                                                               |
| ---------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Allowed          | True                                                                                                                                                                                                                                                |
| Authorization    | Allow                                                                                                                                                                                                                                               |
| Static Code      | False                                                                                                                                                                                                                                               |
| Code Requirement | identifier "com.microsoft.OneDrive" and anchor apple generic and certificate 1\[field.1.2.840.113635.100.6.2.6] /\* exists \*/ and certificate leaf\[field.1.2.840.113635.100.6.1.13] /\* exists \*/ and certificate leaf\[subject.OU] = UBF8T346G9 |
| Identifier Type  | bundle ID                                                                                                                                                                                                                                           |
| Identifier       | com.microsoft.OneDrive                                                                                                                                                                                                                              |

## System Extensions

| Setting                   | Value                             |
| ------------------------- | --------------------------------- |
| Team Identifier           | UBF8T346G9                        |
| Allowed System Extensions | com.microsoft.OneDrive.FinderSync |


# OneDrive Known Folder Move

How to configure OneDrive Known Folder Move for your Intune tenant.

{% hint style="info" %}
Click on the link to download the JSON file from [GitHub](https://github.com/SkipToTheEndpoint/OpenIntuneBaseline/blob/main/MACOS/NativeImport/MacOS%20-%20OIB%20-%20Microsoft%20OneDrive%20-%20U%20-%20Known%20Folder%20Move%20-%20v1.0.json)
{% endhint %}

## Microsoft OneDrive

| Setting                                                                         | Value                          |
| ------------------------------------------------------------------------------- | ------------------------------ |
| Automatically and silently enable the Folder Backup feature (Known Folder Move) | %OrganizationId%               |
| Block external sync                                                             | True                           |
| Disable automatic sign in                                                       | False                          |
| Disable personal accounts                                                       | True                           |
| Disable tutorial                                                                | True                           |
| Display a notification to users once their folders have been redirected         | False                          |
| Enable Files On-Demand                                                          | True                           |
| Enable simultaneous edits for Office apps                                       | True                           |
| Force users to use the Folder Backup feature (Known Folder Move)                | True                           |
| Hide dock icon                                                                  | True                           |
| Ignore named files                                                              | \*.lnk, \*.pst, \*.pkg, \*.dmg |
| Include \~/Desktop in Folder Backup (Known Folder Move)                         | True                           |
| Include \~/Documents in Folder Backup (Known Folder Move)                       | True                           |
| Open at login                                                                   | True                           |
| Prompt users to enable the Folder Backup feature (Known Folder Move)            | %OrganizationId%               |


# Software Updates

How to configure Software Updates for your Intune tenant.

{% hint style="info" %}
Click on the link to download the JSON file from [GitHub](https://github.com/SkipToTheEndpoint/OpenIntuneBaseline/blob/main/MACOS/NativeImport/MacOS%20-%20OIB%20-%20Updates%20-%20D%20-%20Update%20Configuration%20-%20v1.0.json)
{% endhint %}

## Software Update

| Setting                                           | Value |
| ------------------------------------------------- | ----- |
| Automatically Install App Updates                 | True  |
| Config Data Install                               | True  |
| Automatically Install Mac OS Updates              | True  |
| Automatic Check Enabled                           | True  |
| Critical Update Install                           | True  |
| Restrict Software Update Require Admin To Install | False |
| Automatic Download                                | True  |


# Troubleshooting

Troubleshooting guides for common macOS management issues in Microsoft Intune, including enrollment errors and their fixes.

This section collects troubleshooting guides for common problems administrators hit when managing macOS devices with Microsoft Intune. Each guide describes the symptom and walks through the fix. It is aimed at IT administrators diagnosing enrollment and configuration issues on Mac.

Browse the available guides below.

* [**Enrollment Error**](/troubleshooting-guides/enrollment-error) — Fix the macOS enrollment error caused by Apple device platform restrictions.


# Enrollment Error

Fix the "Your IT support doesn't allow OSX devices" macOS enrollment error in Intune by adjusting Apple device platform restrictions.

When attempting to enroll a macOS device in Intune after creating an Apple MDM push certificate, you may encounter the following error in the Company Portal app:

*"Couldn't add your device. Your IT support doesn't allow OSX devices to be added to management."*

![IntuneSetup](/files/qzw3sVgzbohwaPeCYGZ4)

To resolve this issue, follow these steps:

**Step 1: Check Enrollment Failures in Intune**

1. Navigate to the Intune portal.
2. Go to Devices > Enrollment > Monitor > Enrollment failures.
3. Look for any entries related to the affected user.

![IntuneSetup](/files/pEfJMf7gE43BrsaQW1my)

**Step 2: Verify Device Type Restrictions**

The error may be caused by device type restrictions that block macOS devices from enrolling. To check and modify these settings:

1. In the Intune portal, go to Devices > Enrollment.
2. Click on Apple.
3. Select Device platform restrictions and switch to the macOS restrictions tab.

**Step 3: Adjust Restrictions**

1. Review the existing device restrictions to ensure that macOS devices are allowed to enroll.
2. If multiple restrictions exist, examine each one to confirm that the macOS platform is permitted.
3. To modify a restriction, go to its Properties and check the Platform settings.
4. Ensure that macOS devices are not blocked and are allowed to enroll.

By following these steps, you can identify and resolve the issue preventing macOS device enrollment in Intune. This process ensures that your device type restrictions are appropriately configured to support macOS devices.


# Snippets

A collection of handy macOS management snippets for Intune admins, including packaging commands and useful shortcuts.

This section gathers short, reusable snippets that speed up everyday macOS management with Intune, from packaging commands to handy shortcuts. It is aimed at administrators who want quick reference material they can copy and adapt.

Browse the snippet collections below.

* [**Packaging**](/snippets/packaging) — Short commands and steps for packaging apps and payloads.
* [**Shortcuts**](/snippets/shortcuts) — A collection of useful shortcuts for day-to-day work.


# Packaging

Collection of snippets like short commands or steps for packaging.

Collection of snippets like short commands or steps for packaging.

## Convert .app to .pkg

1. Download and install latest [quickpkg release](https://github.com/scriptingosx/quickpkg/releases/latest).
2. Make quickpkg file executable: chmod 755 ./quickpkg
3. Build pkg: `quickpkg /Applications/MyApp.app --output MyApp.pkg`

## Convert .app to .dmg

1. Create an empty folder and copy the .app file into it.
2. Start Disk Utility and choose File > New Image > Image from Folder.
3. Select the newly created folder.
4. Enter a name for your .dmg file and save it.

## Start app from unverified publisher

1. Start app. Error message appears.
2. Go to System Preferences > Security & Privacy > General.
3. Application should be visible and can be added as exception.

## Get Bundle IDs

... from native apps (like Mail: com.apple.mail) and third-party

Via Finder:

1. Open Applications via Finder.
2. Right-click on the required application and select "Show Packaged Contents".
3. Open the contents folder of application.
4. Open the info.plist file and search for bundle ID (called "CFbundleIdentifier").

Via Terminal:

1. Run `osascript -e 'id of app "Google Drive"'`.


# Shortcuts

Collection of useful shortcuts.

Collection of useful shortcuts.

## macOS Cloud Recovery

Intel-based Mac:

1. Restart resp. start the Mac.
2. Hold the following keys until you see the startup screen: Option + Command + R
3. Perform recovery.

Mac with Apple silicon:

1. Restart resp. start the Mac.
2. Press and hold the power button for a few seconds until you see "Loading startup options".
3. Perform recovery.


# Intune Getting Started Guide

Get started with Microsoft Intune for macOS, covering the prerequisites and the basic tenant setup needed to begin managing Mac devices.

This guide covers the groundwork for managing macOS devices with Microsoft Intune: the prerequisites you need in place and the basic tenant configuration to get started. It is written for administrators who are new to Intune or setting up a tenant for Mac management for the first time.

Begin with the prerequisites, then complete the basic tenant setup.

* [**Prerequisites**](/intune-getting-started-guide/prerequisites) — What you need in place before managing macOS with Intune.
* [**Basic Tenant Setup**](/intune-getting-started-guide/basic-tenant-setup) — Set up a basic Intune tenant for macOS devices.


# Prerequisites

Learn about the prerequisites for macOS management with Intune.

## Goals 🎯

In this section it is described how to easily set up the core management of macOS with Microsoft Intune. We will walk through:

* Preparing the setup and plan for macOS management
* Setting up the Intune tenant
* Implementing policies for configuration, compliance and security

## Prerequisites

When aiming for macOS management with Intune, you need to verify the following technical subjects as prerequisite:

* MDM user scope set to ‘all’

![IntuneSetup](/files/9IDOyFUCPH1bZVPXOSqc)

* Intune administrator role
* Intune plan 1 license
* Enrollment device limit restrictions > default value
* Enrollment device platform restrictions > depending on which platform to enroll (corporate or personal)

![IntuneSetup](/files/H0kTtRA4Tz6Ydst51TlC)

* Apple Certificates and Tokens
  * [APNS](https://learn.microsoft.com/en-us/mem/intune/enrollment/apple-mdm-push-certificate-get) (required)
    * Used for communication between Intune and the device
    * Not needing Apple Business Manager

![IntuneSetup](/files/WGq39tVeib6NCaVuXliL) - [Enrollment program token](https://learn.microsoft.com/en-us/mem/intune/enrollment/macos-enroll?ref=oceanleaf.ch#enable-enrollment-in-microsoft-intune) (optional) - Used for Automatic Device Enrollment from ABM to Intune - Requires Apple Business Manager - [VPP](https://learn.microsoft.com/en-us/mem/intune/apps/vpp-apps-ios) (optional) - Used to deploy apps from ABM via Volume Purchase Program - Requires Apple Business Manager

### Before you start

It is not just about the technical! Be sure to also have the organizational prerequisites met. Some of the considerations include:

* Approval by security responsible to use Macs for organizational use
* Define your Mac management strategy
  * Which devices are supported? personal/corporate
  * Which identities are used? no Apple ID, personal Apple ID, managed Apple ID
  * Choose user accounts + single-sign on (SSO) type: Enterprise SSO plug-in/platform SSO
  * Define macOS policies, compliance and security requirements
* Define project goals for stakeholders
* Plan project initiative
* Project budget and sponsors


# Basic Tenant Setup

Learn how to set up a basic tenant in Intune for macOS devices.

## Overview

After meeting the [Prerequisites](/intune-getting-started-guide/prerequisites) we turn over to the setup of the tenant and equipment of policies & apps.

1. Create groups & filters
2. Create compliance policy
3. Create configuration policies
4. Evaluate updating
5. Deploy apps
6. Create scripts (optional)
7. Create custom attributes (optional)

### Introduction

All management tasks can be done within Intune > Devices > macOS - here you can configure and monitor everything: ![IntuneSetup](/files/UEf5hV0RFAR65MbgIgbs)

## 1. Groups & filters

First, let's create a group/filter where your Macs are automatically added to target policies and other contents.

**Entra dynamic group query**

```
(device.deviceOSType -eq "macMDM")
```

**Intune filter query**

```
(device.model -contains "Mac")
```

{% hint style="info" %}
It is recommended to use Intune filters, since the processing is faster than groups.
{% endhint %}

## 2. Compliance policy

A compliance policy is the fundamental part of the Intune management, because it determines if the Mac is fullfilling basic requirements in order to access corporate resources. Let's start with a basic version of it:

![IntuneSetup](/files/NNb8Ij3ZphJZjeVyLUYv)

## 3. Create configuraiton policies

Configuration is a wide area and offers a lot of options. You can configure nearly every aspect of the system to get your desired look & feel. Some recommended policies are found [here](https://github.com/thenikk/Oceanleaf/tree/main/Intune%20-%20macOS)

{% hint style="info" %}
It is recommended to use Settings Catalog whenever possible.
{% endhint %}

![IntuneSetup](/files/MNlpnYmXqYUrOOoqX15O)

## 4. Evaluate updating

When it comes to OS updating, you have to main built-in options:

* macOS updates policy in Intune (less control options)
* Settings Catalog DDM update configuration (recommended)

## 5. Deploy apps

Intune supports app deployment to:

* Deploy apps from different repositories/stores
* Configure apps and monitor the status
* Provide apps as available from Company Portal

There are different sources with different behaviors to get apps from:

* Built-in in Intune: Microsoft 365 Apps, Edge, Defender for Endpoint
* Web clip or link (just a shortcut to a URL)
* Apple Volume Purchase Program (VPP), requires Apple Business Manager - apps are 'aquired' there and synced to Intune
* macOS types:
  * DMG = Disk Image, basically just an application file
  * PKG = Package, more configuration options (insatller behavior)

## 6. Create scripts (optional)

macOS scripts are based on shell and can be deployed to managed endpoints. [Here](https://github.com/microsoft/shell-intune-samples/tree/master/macOS) you can find a repo with some inspiration.

## 7. Create custom attributes (optional)

Custom attributes are shell scripts that read out a system value in a string, integer or date. This is practical for custom inventory data or retrieving a status on the system.


# Complete Guide to macOS Deployment

An end-to-end guide to deploying and enrolling macOS devices with Microsoft Intune, from Apple Business Manager to FileVault, Platform SSO, and Microsoft Defender.

This section walks through a full macOS deployment with Microsoft Intune, in the order you would build it: connecting Apple Business Manager, enrolling devices, and layering on the configuration and security policies that make up a production-ready setup. It is written for IT administrators standing up automated device enrollment (ADE) for Mac for the first time, as well as those refining an existing deployment.

Follow the pages below in sequence for a complete deployment, or jump to a specific step you are working on.

* [**Apple Business Manager**](/complete-guide-macos-deployment/apple-business-manager) — Set up and use Apple Business Manager for efficient device management.
* [**Integrate Apple Business Manager with Intune**](/complete-guide-macos-deployment/integrate-apple-business-manager-with-intune) — Create an Apple MDM Push certificate and set up the ADE token.
* [**Add a device to Apple Business Manager**](/complete-guide-macos-deployment/add-a-device-to-apple-business-manager) — Add devices with Apple Configurator and sync them to Intune.
* [**Configure MacOS Platform SSO**](/complete-guide-macos-deployment/configure-macos-platform-sso) — Configure Platform SSO with a Secure Enclave key during enrollment.
* [**Enable FileVault during the Setup Assistant**](/complete-guide-macos-deployment/enable-filevault-during-the-setup-assistant) — Turn on FileVault disk encryption as part of device setup.
* [**Install the Company Portal app as a macOS LOB app**](/complete-guide-macos-deployment/install-the-company-portal-app-for-macos-as-a-macos-lob-app) — Download, add, and assign Company Portal as a line-of-business app.
* [**User Experience on a MacOS Device**](/complete-guide-macos-deployment/user-experience-on-a-macos-device) — A screenshot walkthrough of the end-user enrollment experience.
* [**Enroll MacOS in Microsoft Defender**](/complete-guide-macos-deployment/enroll-macos-in-microsoft-defender) — Onboard macOS devices to Microsoft Defender for Endpoint via Intune.
* [**Declarative Device Management (DDM)**](/complete-guide-macos-deployment/declarative-device-management) — Apply settings and report status asynchronously with DDM.
* [**Rapid Security Response**](/complete-guide-macos-deployment/rapid-security-response) — Deliver critical security fixes to Mac between full updates.


# Apple Business Manager

Learn how to set up and use Apple Business Manager for efficient device management in your organization. This guide covers the benefits, application process, and integration with MDM solutions.

## Intro

I always recommend the use of Apple Business Manager. Why you could say, well Apple Business Manager is a free service provided by Apple that allows organizations to manage three things: devices, apps, and accounts. Simply put, if your organization owns Apple devices, you should be using Apple Business Manager (or its education-sector equivalent, Apple School Manager). There’s literally no downside to it. Apple Business manager offers many benefits—some well-known, others less so—and it doesn’t cost a thing.

First to define what we’re talking about: Apple Business Manager is an all-in-one portal designed to help organizations deploy Apple devices, manage organization-owned Apple IDs, and acquire apps and other content in volume. It coordinates closely with mobile device management solutions to automatically enroll and manage devices. Apple Business Manager is not an MDM solution itself, this just to be clear.

To use Apple Business Manager, your organization must first have an account. Applying is simple, and although it can take a couple of days for your application to be approved, it typically happens much faster. It just requires some basic information, including your DUNS number and contact information for someone at your company—not an IT admin, more likely someone higher up—who can vouch for you. Apple will then verify everything and, if it all checks out, confirm your account. More information on all this can be found in [Apple’s Getting Started guide](https://www.apple.com/business/docs/site/Apple_Business_Manager_Getting_Started_Guide.pdf).

Why use Apple Business Manager, well some configuration can only be applied for supervised devices, only devices from Apple Business Manager are supervised devices, check table below.

![SupervisedVSPersonal](/files/2N9bEORRVblkmcdlJYeo)

In the different Intune configuration profiles you will also notice that some settings only apply on supervised devices.

![IntuneDeviceRestrictions](/files/OskhLfkYiewccu0Hh0aA)

{% hint style="info" %}
This can be a lenghty process because you need to request the number and also Apple needs to do some verification. If you are planning to use Apple Business Manager and you have a deadline for your project please start early for the admin stuff that you cannot control.
{% endhint %}

## Applying for Apple Business Manager

Go to <https://business.apple.com/> and let’s assume you do not have an account here yet, click sign up now.

![ABM-Signup](/files/vS4ZboKIt2f6h5O80ch2)

Click Get Started.

![ABM-GetStarted](/files/9SPHChfxI4f6DJ746P1F)

Fill in the necessary details and click continue.

![ABM-GetStarted](/files/mDrldvycXNPO0gRX4x34)

Create a password and enter a phone number for verification and click continue.

![ABM-GetStarted](/files/yx2ET4Y7TkRZrLC3XFjd)

A verification code will be sent to your email address. Enter it and click continue.

![ABM-GetStarted](/files/IzDbeRPbaJMEOVZOPoUf)

Now a code will be sent to your mobile device, enter it and click continue.

![ABM-GetStarted](/files/F88lbYOvRRvEA8WATfAu)

Accept the Terms and Conditions (You can always download them and read all the info, somebody has spent an aweful amount of time writing these down, so you would do him/her a big favor 😉)

![ABM-GetStarted](/files/nbCXkzrFvCDhVCW2tZo0)

You will be presented with this screen, click Get Started.

![ABM-GetStarted](/files/qFZHMGZ0bL4VqqKGn7Mi)

{% hint style="info" %}
Now you have 59 days left to verify your business and you will now have to request your D-U-N-S Number, first do a look up [here](https://developer.apple.com/enroll/duns-lookup/#!/search). If your organization was not found you can submit your information to request the number. I got my number in 48hrs
{% endhint %}

![ABM-GetStarted](/files/W8QlkQDmqmWuZUo48uxy)

After you submit you request you will see this:

![ABM-GetStarted](/files/M7HfOyBF3234Yv5dBcK0)

From now on you have to wait for your number to be received. After a few minutes you will receive an email like this:

![ABM-GetStarted](/files/scLucG5SxDippWFM6pjg)

When you receive your D-U-N-S number click verify.

![ABM-GetStarted](/files/C45ghzKJUCduM40F4BV2)

Enter your details and click submit.

![ABM-GetStarted](/files/mJBxYabFXfgEZ2vxe5Eg)

Now your verification is pending.

![ABM-GetStarted](/files/dUhV07LoiWtrM17lHL3z)

You will also receive an e-mail regarding this:

![ABM-GetStarted](/files/VlzbuHoACm8lGd6Z8vt6)

{% hint style="info" %}
This can take up to 5 business days to complete. In this case it took 48hrs
{% endhint %}

Once your Apple Business Manager account has been approved you will get an email:

![ABM-GetStarted](/files/c7acsO23LjZo1bkUS96w)

Now your company is enrolled with Apple Business Manager. Let’s proceed to integrate this with Intune.


# Integrate Apple Business Manager with Intune

Step-by-step guide on integrating Apple Business Manager with Microsoft Intune. Learn how to create an Apple MDM Push certificate and set up the Apple Automated Device Enrollment Token.

## Create the push certificate

You need an Apple MDM Push certificate to manage your iOS/iPadOS and macOS devices in Microsoft Intune. This token enables devices to enroll via Intune Comp Portal or ADE/ASM/AC2. Follow the steps below to create the Apple MDM push certificate and upload it to the Intune Portal. [I’ve written a post on the renewal of the certificate](https://intunestuff.com/2023/11/12/how-to-renew-the-mdm-push-certificate-on-intune-for-apple-devices/), you can use this post also for the creation of the certificate. It it not that different and pretty easy to do.

## Create the Apple Automated Device Enrollment Token

So the pre-requisite is done, but before you can enroll iOS/iPadOS devices, you would need an Apple Server Token (.p7m) file from Apple. This token syncs information from Intune to ADE devices that your corporation owns. It also allows Intune to assign enrollment profiles to Apple and to assign devices to those profiles.

Follow the steps below to create & upload the ADE token:

In Intune portal, select Devices – Device onboarding – Enrollment – macOS tab – Bulk Enrollment Methods – Enrollment program tokens

![Enrollment Token](/files/cTTr2vsnBR6RYA7ehfxo)

Click Add, tick the I agree box, click download your public key and save this key on your device. The .pem file is used to request a trust-relationship certificate from the Apple Business Manager portal.

![Enrollment Token](/files/YC7xlqabbjpc1koXlyKi)

Click on Create a token via Apple Business Manager to open the Apple Business Manager portal for creating your ADE token (MDM server). Sign in with your company’s Apple ID in Apple Business Manager.

Click your name at the bottom of the sidebar – Preferences.

![Enrollment Token](/files/33Xr6u5i02MwQ2MDHd9D)

Then click “Add” to add MDM Server.

![Enrollment Token](/files/paWbkiKVudFPeab7Sd9K)

Name your MDM Server, tick the box Allow this MDM Server to release devices and upload the public key file you just downloaded and click save.\_createMdxContent

![Enrollment Token](/files/h2YYpVxiEwfoXtx5h1OC)

Now download your MDM Server Token.\_createMdxContent

![Enrollment Token](/files/VHEEfzjVSjqEfdjKKX8P)

You will get a warning, you can ignore this because this is our first token, just click Download MDM Server Token and save this on your device.\_createMdxContent

![Enrollment Token](/files/JiaDCwcfkFeya1EmIOCm)

Now back to the Intune Portal, fill in your apple ID, upload the newly downloaded token, click next and create.\_createMdxContent

![Enrollment Token](/files/gm2g6zOCJjHxis3aVy8L)

When this is done you will get this screen.

![Enrollment Token](/files/ME0gx8Nmuz3R3sAVXsFQ)

Now your Apple Business Manager is connected to Intune.


# Add a device to Apple Business Manager

Detailed instructions on adding devices to Apple Business Manager using Apple Configurator. Learn how to create enrollment profiles and sync devices with Intune for seamless management.

## Add a device to Apple Business Manager

To add devices to Apple Business Manager you have some options. You Apple reseller can add them for you when you order a device. You can also add a device yourself by using the Apple Configurator app on your phone, i’m going to explain this method. If you want your reseller to add the devices you can read this article: [Manage device suppliers in Apple Business Manager – Apple Support](https://support.apple.com/guide/apple-business-manager/manage-device-suppliers-axmef1c47493/web)

You can add the following devices using Apple Configurator to Apple Business Manager, even if they weren’t purchased directly from Apple or from an Apple Authorized Reseller or cellular carrier:

* iPhone, iPad, and Apple TV devices using Apple Configurator for Mac.
* iPhone, iPad, and Mac computers (running macOS 12.0.1 or later) with Apple silicon or the Apple T2 Security Chip using Apple Configurator for iPhone.

![AddToABM](/files/VXWiuXFh5FIgObqXAAM5)

After you’ve set up the device or devices, they behave like any other device already in Apple Business Manager, with mandatory supervision and mobile device management (MDM) enrollment. The device can then be shut down and stored until needed or sent to the user. If the device is given to a user, they have a 30-day provisional period to release the device from Apple Business Manager, supervision, and MDM. This 30-day provisional period begins after the device is successfully assigned to and enrolled in:

* A third-party MDM server linked to Apple Business Manager.

## Create the Enrollment Profile

First you will have to create an enrollment profile. Go to the Intune portal – Devices – Device onboarding – Enrollment – macOS – Enrollment program tokens – click token name – click Enrollment policies – Create policy – macOS – name you profile e.g MacOS

![AddToABM](/files/wq0njlsUZTh1wqc4e3tz)

Click next and fill in the details, click next again.

![AddToABM](/files/W8wqLcaP29Tl9gGTYpTe)

Now you can alter the setup assistant, you can choose which screens appear during the setup, this is totally up to you. Fill in the department and department phone.

![AddToABM](/files/w4KQ4q2FBjNI6JIqrV6Q)

Click next and fill in the details.

![AddToABM](/files/iUj41Lf5QHRLkwooYEPF)

Click next and create. Now you enrollment profile has been created, we will add a device to it later on.

![AddToABM](/files/r4umx3m0emd8gyUppfXI)

## Install Apple Configurator on iPhone and configure it

Now it is time to add our device to Apple Business Manager with the use of the Apple configurator app on our iPhone. Download the app from the store and install it on your phone. I already got mine so i choose to open the app.

![AddToABM](/files/uvDXK7FRKQpuUuZ4CGal)

Open the configurator app and tap continue.

![AddToABM](/files/n7pxxC52YGXj5pyA2kXJ)

Sign in with your apple id you used for Apple Business Manager and fill in the MFA code.

![AddToABM](/files/rHoLtwckXpre1SIvPyhi)

In the network configuration section make sure that Share Wifi is selected and at the MDM Server Management your MDM server that you configured in Apple Business Manager is selected by selecting specific and selecting your MDM server.

![AddToABM](/files/36X5yhbiQb2NeTem2sj6)

Tap Done

{% hint style="info" %}
Your Mac device needs to be factory reset in order to add it to Apple Business manager. **If you continue past the Country or Region setup pane, you will need to restart your Mac.**
{% endhint %}

Now your Apple Configurator will look like this.

![AddToABM](/files/8JbZHqtPZiodjOvZO4fI)

## Add your MacOS device to Apple Business Manager with Apple Configurator (iPhone)

Hold your iPhone with Apple Configurator open close to the Mac. You should see a screen that says “Assign this Mac to your Organization”.

![AddToABM](/files/SWK4wMq0DEg21rQsl64z)

From this screen, you have two options:

* Use the iPhone camera (with the Apple Configurator app open) to scan the image on the screen.
* Select “Pair Manually” on the iPhone and click “Pair Manually” on your Mac. You will be shown a 6-digit code and be prompted to enter it.

I will use the scan option, you will now see your device being added to Apple Business Manager. When it is finished you will be presented by this screen.

![AddToABM](/files/c5AXf3c9AdWXD12Vdv2b)

Leave you Mac now for what it is and go to the [Apple Business Manager](https://business.apple.com/) and login. Click on the left hand side on devices and your device should appear. Click on it for the details.

![AddToABM](/files/QY7xqvPEjpBzPX1DhUPm)

## Sync Apple Business Manager device to Intune

Now go back to the Intune portal – Devices – enrollment – Apple – Enrollment program tokens – click on your token name – click devices – click sync.

![AddToABM](/files/mDLkYHTo7XcGgpF7QZMb)

Now the devices in your Apple Business Manager will be synced to Intune. You can click refresh a few times to check if the device appears, after a few seconds my device is there. If you have a lot of devices to syn the time will increase.

![AddToABM](/files/C58FXjdhizxIt1RgyhQC)

Now we can add this device to our enrollment profile. so go to the Intune Portal – Devices – Enrollment – Apple – Enrollment program tokens – click on your token name – click profiles – click on your profile name – click assign devices and click add devices – select your device to add it.

![AddToABM](/files/A4lqppi4pISZpxnBGuvU)

{% hint style="info" %}
After you add your device don’t forget to click **save**!!!
{% endhint %}

![AddToABM](/files/9L3KjOsmtN1HFyVP3K5K)

When all went good you will get this notification.

![AddToABM](/files/13ruTpGHIPygx5YLmqwG)

Now you have added a device into Apple Business Manager and synced it to Intune and assigned it to the Enrollment profile. Now it is time to configure our Mac. But wait, i still want to configure the MacOS Platform SSO so let’s do this first. If you don’t want to use Platform SSO you can skip these steps.


# Configure MacOS Platform SSO

Comprehensive guide on configuring MacOS Platform SSO (Single Sign-On) with Secure Enclave Key. Learn about prerequisites, policy creation, and important considerations for implementation.

## What is MacOS Platform SSO

Platform single sign-on (SSO) is a replacement for binding to directory services. It builds on enterprise SSO capabilities so SSO extensions can also perform single sign-on for apps and websites. It integrates with macOS and doesn’t use JavaScript or render webpages for authentication.

The system stores the SSO tokens in the keychain and only shares them with the SSO extension. The SSO extension then uses the SSO tokens to authenticate the user to their on-premises apps and on websites as needed. If the SSO tokens are missing, expired, or more than four hours old, platform SSO attempts to refresh or retrieve new tokens from the IdP.

Platform SSO supports the following authentication methods with an identity provider (IdP):

* Password and encrypted password The IdP uses the local account password and keeps it in sync, including password updates from the login window and screensaver unlock.
* Password with WS-Trust A federated IdP, meaning an IdP that facilitates federated authentication across multiple security domains, can use the local account password for authentication.
* User secure enclave key A secure enclave-backed key can authenticate with the IdP without a password and without changing the local account password.
* SmartCard High-security customers can use a SmartCard to authenticate with the IdP. Platform SSO can create new local user accounts on demand at the login window using IdP credentials, and also integrate IdP group membership with macOS. You can use network accounts for authorization, and groups can also authorize network accounts.

Use Device Management to securely configure platform SSO, including device and user registration, configuring groups, and managing account permissions.

The system can also retrieve Kerberos ticket-granting tickets (TGTs), import them to a credential cache, and optionally share them with the Kerberos SSO extension.

I will describe the config for **Secure Enclave Key** and will add **Password authentication** at a later time.

{% hint style="info" %}
**You cannot use Enterprise Application SSO together with Platform SSO**
{% endhint %}

## Configure Platform SSO With Secure Enclave Key

**Prerequisites**

* Devices must be macOS 13.0 and newer devices. –> For the best results upgrade to MacOS 14.x

-Microsoft Intune Company Portal app version 5.2404.0 and newer.

* Supported web browsers: Microsoft Edge Google Chrome with the Microsoft Single Sign On extension Safari Firefox

## Create the Platform SSO policy

Go to Intune portal – Devices – MacOS – Configuration profiles – Create – New Policy – Platform MacOS – Profile type Settings Catalog – Name your policy e.g. MacOS – Platform SSO – Select Add Settings – Expand Authentication – Select Extensible Single Sign On (SSO).

{% hint style="info" %}
If you have a mix of macOS 13 and macOS 14+ devices in your environment, then configure the Platform SSO Authentication Method and the Authentication Method (Deprecated) authentication settings in the same profile.
{% endhint %}

![PSSO](/files/6Jiue4MOPW9NzzkzjwWz)

Configure the profile for at the below keys: (these are minimum required settings for PSSO to work)

* Authentication Method (Deprecated) (only if you are deploying profile to macOS 13.x devices)
* Extension Identifier
* Authentication Method (macOS 14+)
* Use Shared Device Keys
* Registration Token
* Account Display Name
* Screen Locked Behavior
* Team Identifier
* Type
* URLs
* Token To User Mapping: Account Name
* Token To User Mapping: Full Name

Here you can find all the info that you need to fill in: [Configure Platform SSO for macOS devices | Microsoft Learn](https://learn.microsoft.com/en-us/mem/intune/configuration/platform-sso-macos#step-2---create-the-platform-sso-policy-in-intune?wt.mc_id=MVP_377186)

**As there is apparently some confusion on the use of the URL’s needed in the PSSO profile see here (although this is stated in de Microsoft docs – see link above) here just to clarify:**

**These URL prefixes are the identity providers that do SSO app extensions. The URLs are required for redirect payloads and are ignored for credential payloads.**

* <https://login.microsoftonline.com>
* <https://login.microsoft.com>
* <https://sts.windows.net>

**If your environment needs to allow sovereign cloud domains, then also add the following URLs:**

* <https://login.partner.microsoftonline.cn>
* <https://login.chinacloudapi.cn>
* <https://login.microsoftonline.us>
* <https://login-us.microsoftonline.com>

For more information on these URLs, go to [Microsoft Enterprise SSO plug-in for Apple devices.](https://learn.microsoft.com/en-us/entra/identity-platform/apple-sso-plugin?wt.mc_id=MVP_377186)

Your profile will look like this.

![PSSO](/files/9nyB8hp8CuSxCM2mvM0R)

Assign the profile to your desired **device or user** group.

{% hint style="info" %}
When you configure Platform SSO with the Password authentication method instead of Secure Enclave Key, users sign in to the device with their Microsoft Entra ID user account password instead of their local account password. This option enables SSO across apps that use Microsoft Entra ID for authentication. With the Password authentication method:

* The Microsoft Entra ID password replaces the local account password, and the two passwords are kept in sync.
* The local account username isn’t changed and stays as-is.
* End users can use Touch ID to sign in to the device.
* There are fewer passwords for users and admins to remember and manage.​ -Users must enter their Microsoft Entra ID password after a device reboots. After this initial machine unlock​, Touch ID can unlock the device.
* After the unlock, the device gets the hardware-bound Primary Refresh Token (PRT) credential for Microsoft Entra ID SSO.​ The local account machine password isn’t completely removed from the device. This behavior is by design due to Apple’s FileVault disk encryption, which uses the local password as the unlock key.

**Any Intune password policy you configure also affects this setting. For example, if you have a password policy that blocks simple passwords, then simple passwords are also blocked for this setting. Make sure your Intune password policy and/or compliance policy matches your Microsoft Entra password policy. If the policies don’t match, then the password might not sync and end users are denied access. See the warning box below!**
{% endhint %}

{% hint style="warning" %}
**Warning**

**!!Important update!!** Now i have been playing around with PSSO for a while and what i’ve found out is the following, if you have set a compliance policy with password settings, or a device restrictions policy with password settings configured scoped to a device group you will not be able to do the registration, it will break PSSO **(see the bold text in the info box above, this is again very vague MS doc)** unless you change you local user’s password 1st, I have tried all different scenario’s regard so it is very important to scope your policies like this:

* Compliance policy – no password settings specified – User group assigned
* Device restrictions Policy – password settings specified – Device group assigned
* PSSO Policy – Device group or user group assigned
  {% endhint %}

If you want to enable smart card login you will also need to enable FIDO as an authentication method in Entra ID:

![PSSO](/files/BTz9qqqPb5VpzauwNuJH)


# Enable FileVault during the Setup Assistant

Learn how to enable FileVault encryption during the MacOS Setup Assistant. This guide covers the necessary steps to configure FileVault policies in Intune for enhanced device security.

## Enable FileVault during the Setup Assistant

To enable FileVault encryption during the setup assistant do the following. Go to Devices – Macos – Enrollment – Enrollment progtam tokens – your token name – profiles – your profile name – properties. Here make sure to show FileVault.

![FileVault](/files/JlKH2iL6MO0xVr3aqm2X)

Now we need to create a policy, to do this go to Devices – By platform – Macos – Manage devices – Configuration – create – new policy – settings catalog – name your policy – Add settings – Full Disk Encryption – FileVault. You can take the settings from the screenshot. You can of course play around with the rotation.

![FileVault](/files/VKTDWkHh1CO0EtnRYxdc)

That is it, now your device will be encrypted during the setup.


# Install the Company Portal app for MacOS as a MacOS LOB app

Step-by-step instructions on installing the Company Portal app for MacOS as a Line-of-Business (LOB) app. Learn how to download, add, and assign the app in Intune for seamless device management.

## Install the Company Portal app for MacOS as a MacOS LOB app

Company Portal for macOS can be downloaded and installed using the macOS LOB apps feature. The version downloaded is the version that will always be installed and may need to be updated periodically to ensure users get the best experience during initial enrollment.

Download Company Portal for macOS from [here](https://go.microsoft.com/fwlink/?linkid=853070)

Add the app by going to the Intune portal – Apps – All Apps – Create – App Type – select the macOS platform, then Line-of-business app – select

Browse to your downloaded CompanyPortal-installer.pkg file and fill in the empty required fields

![CompanyPortal](/files/FnTqau5DwAKAqbbAoHBz)

Assign it to your desired group

For macOS devices running 10.15 and later, when creating an Automated Device Enrollment profile, you can now choose a new authentication method: Setup Assistant with modern authentication, what we have done. The user has to authenticate using Microsoft Entra credentials during the setup assistant screens. This will require an additional Microsoft Entra login post-enrollment in the Company Portal app to gain access to corporate resources protected by Conditional Access and for Intune to assess device compliance.

Users must sign into the Company Portal to complete Microsoft Entra authentication and gain access to resources protected by Conditional Access. User affinity is established when users complete the enrollment and reach the home screen of the macOS device. If the tenant has multi-factor authentication turned on for these devices or users, the users will be asked to complete multi-factor authentication during enrollment during Setup Assistant. Multi-factor authentication is not required, but it is available for this authentication method within Conditional Access if needed.


# User Experience on a MacOS Device

A screenshot walkthrough of the macOS Setup Assistant enrollment experience into Intune with Platform SSO, as seen by the end user.

## User Experience on a MacOS Device

Remember that we left our Mac device after we enrolled it in Apple Business Manager, reboot it. Now just follow the setup assistant to continue onboarding you Mac into Intune With Platform SSO. These are the screenshots during enrollment. Apparently there is a limit on the screenshots you can make during the setup assistant so i missed some. But i think you will get the complete overview of what is going on. My apologies for this.

Select Country or region

![UX](/files/6oi6mNHdgSJ0jpNrqkFE)

Click Continue

![UX](/files/JGG8EC9kJkrApsp0sLP7)

Click not now

![UX](/files/T7JajjIk4evH5iTBRByG)

Connect to Wifi

![UX](/files/Lu4cDGdhluQxY2xqBsnF)

Click Continue

![UX](/files/FpLgZJLVETUWhSB8aXnV)

Now you can see that your device has got the Company enrollment profile, click enroll

![UX](/files/ShSPVRzLtx08E0E159sP)

Sign in with your Entra ID credentials and accept the MFA request if needed

![UX](/files/QmTKFql3iaTeinDWvvhj)

Now all Intune profiles are being installed, just watch the progress

![UX](/files/ArAoMUfPvH3UeY6T0HNJ)

![UX](/files/tjqn0rUUvist8dgJ1cZE)

Now i had to take a picture with my phone, pretty amateuristic i know…. 🙂

![UX](/files/Xm7rsOLv6J6T9dDW4Tc0)

From now on you will go to the desktop of the Mac, check the message in the top right corner, click it

![UX](/files/BHkqbSPu3ns2UwlTPBoV)

Now enter your local user password or use touch id![UX](/files/VKLLcVMuf6ZbLmD1r7b0)

Enter your Entra ID credentials and approve MFA if needed

![UX](/files/Png4LFNsWKTXLhZ1SFdI)

Preparing your device

![UX](/files/3V8QbSiX1Dg7yQsdthiX)

Toggle on Company Portal and click open System Settings

![UX](/files/17ODpAlfDv7F9OctIF9r)

Toggle on Company Portal and click close

![UX](/files/w4q8DpopVenx2dgsAnZQ)

Go to Finder – Applications – Company Portal – Click sign in

![UX](/files/GRos8rObldh7Pvc9ZfKT)

Check the SSO page, this is what we want to see, click continue

![UX](/files/XZ13iRsFhPM7KfRPOQ8I)

Now all is configured

![UX](/files/osNC5Sl1O7dm1mkQYC1Y)

You can check if all is OK by going to settings – users & groups and clicking on the Entra ID user

![UX](/files/bULLB4NkUBPv0WYTpbyg)

In the next window you can see that everything is ok

![UX](/files/jUtzXYPkqLfjoISzezwV)


# Enroll MacOS in Microsoft Defender

Learn how to enroll MacOS devices in Microsoft Defender for Endpoint. This guide provides step-by-step instructions on setting up the necessary configurations and policies in Intune to integrate MacOS

## Prerequisites

To successfully enroll your MacOS (or any other OS for that mater) you will need to setup all connections between Intune and Defender. You can read about it here. Of course you will need the correct licenses:

* Defender for Endpoint Plan 1 and Plan 2 (standalone or as part of other Microsoft 365 plans)
* Microsoft Defender for Business (for small and medium-sized businesses)

To onboard servers to the standalone versions of Defender for Endpoint, server licenses are required. You can choose from:

* Microsoft Defender for Servers Plan 1 or Plan 2 (as part of the Defender for Cloud) offering
* Microsoft Defender for Endpoint for Servers
* Microsoft Defender for Business servers (for small and medium-sized businesses only)

## Enable Microsoft Defender in Intune

Sign in to the Microsoft Intune admin center. Select Endpoint security – Microsoft Defender for Endpoint, and toggle the Allow Microsoft Defender for Endpoint to enforce Endpoint Security Configurations box to On.

![Defender](/files/KOOw2OCVFeY6Ey3hwYGN)

Select Endpoint security > Microsoft Defender for Endpoint, and then select Open the Microsoft Defender Security Center.

![Defender](/files/cC8IJIfdgs0jmJIOHBhY)

In Microsoft Defender portal (previously the Microsoft Defender Security Center) Select Settings (at the bottom of the left column) – Endpoints – Advanced features.

For Microsoft Intune connection, choose On and click Save preferences.

![Defender](/files/wQUr0lF43nq73P8cqw5G)

Go back to the Microsoft Intune admin center. Select Endpoint security – Microsoft Defender for Endpoint and you will see that the connection status is set to enabled. (this can take a few minutes, please refresh periodically)

![Defender](/files/f2RvZ8msuvLtsKUjhsVO)

Now on the same screen toggle both Connect Windows devices version 10.0.15063 and above to Microsoft Defender for Endpoint and Block unsupported OS versions to the On state.

![Defender](/files/g4cpJUojIkdIaIhepz0b)

Now you have enabled the connection between Microsoft Defender and Intune. Now let’s continue to create the different configuration profiles needed.

## Create system configuration profiles

**The System Extensions Policy**

The next step is to create system configuration profiles that Microsoft Defender for Endpoint needs. In the Microsoft Intune admin center, go to Devices, and under Manage Devices, select Configuration. We will need a lot of policies configured for this so make sure you have some spare time for this 😉

On the Policies tab, select Create > New Policy.

* Under Platform, select macOS.
* Under Profile type, select Settings catalog.
* Select Create.
* Name your policy e.g MacOS – Defender Extensions
* On the Configuration settings tab, expand System Extensions and add the following entries in the Allowed system extensions section:

**Bundle identifier**

* com.microsoft.wdav.epsext
* com.microsoft.wdav.netext

**Team identifier**

* UBF8T346G9

![Defender](/files/hVHsriZzxeyklJ8OSPeX)

Select Next. On the Assignments tab, assign the profile to a group where the macOS devices and/or users are located, or select the Add all users and Add all devices options. Then select Next. Review the configuration profile. Select Create.

**The Network Filter Policy**

As part of the Endpoint Detection and Response capabilities, Microsoft Defender for Endpoint on macOS inspects socket traffic and reports this information to the Microsoft 365 Defender portal. The following policy allows the network extension to perform this functionality.

First we need to download the [netfilter.mobileconfig file](https://intunestuff.com/wp-content/uploads/2024/05/netfilter.zip) – Unzip the file somewhere on your PC.

To configure network filter:

* Under Configuration profiles, select Create Profile.
* Under Platform, select macOS.
* Under Profile type, select Templates.
* Under Template name, select Custom.
* Select Create.
* On the Basics tab, Name the profile e.g. MacOS – Network Filter
* On the Configuration settings tab, enter a Custom configuration profile name e.g. Network Filter
* Deployment Channel: Device Channel (we are going to scope all Defender policies on device groups)
* Configuration profile file: Browse for the downloaded file

![Defender](/files/ZieJDRCC4g9A2CPlRJjM)

Select Next. On the Assignments tab, assign the profile to a group where the macOS devices and/or users are located, or select the Add all users and Add all devices options. Then select Next. Review the configuration profile. Select Create.

## The Full Disk Access Policy

Starting with macOS Catalina (10.15) or newer, in order to provide privacy for the end-users, it created the FDA (Full Disk Access). Enabling TCC (Transparency, Consent & Control) through a Mobile Device Management solution such as Intune, will eliminate the risk of Defender for Endpoint losing Full Disk Access Authorization to function properly.

This configuration profile grants Full Disk Access to Microsoft Defender for Endpoint. If you previously configured Microsoft Defender for Endpoint through Intune, we recommend you update the deployment with this configuration profile.

First we need to download the [Fulldisk.mobileconfig file](https://intunestuff.com/wp-content/uploads/2024/05/FullDisk.zip) – Unzip the file somewhere on your PC.

To configure Full Disk Access:

* In the Intune admin center, under Configuration profiles, select Create Profile.
* Under Platform, select macOS.
* Under Profile type, select Templates.
* Under Template name, select Custom. Then select Create
* Select Create.
* On the Basics tab, Name the profile e.g. MacOS – Full Disk Access
* Select Next.
* On the Configuration settings tab, enter a Custom configuration profile name
* Deployment Channel: Device Channel (we are going to scope all Defender policies on device groups)
* Configuration profile file: Browse for the downloaded file

![Defender](/files/LBr3vrVqQYyZpxB70Ww6)

Select Next. On the Assignments tab, assign the profile to a group where the macOS devices and/or users are located, or select the Add all users and Add all devices options. Then select Next. Review the configuration profile. Select Create.

## The Background Services Policy

macOS 13 (Ventura) contains new privacy enhancements. Beginning with this version, by default, applications cannot run in background without explicit consent. Microsoft Defender for Endpoint must run its daemon process in background. This configuration profile grants Background Service permissions to Microsoft Defender for Endpoint. If you previously configured Microsoft Defender for Endpoint through Microsoft Intune, we recommend you update the deployment with this configuration profile.

First we need to download the [BackgroundServices.mobileconfig file](https://intunestuff.com/wp-content/uploads/2024/05/BackgroundServices.zip) – Unzip the file somewhere on your PC.

To configure background services:

* Under Configuration profiles, select Create Profile.
* Under Platform, select macOS.
* Under Profile type, select Templates.
* Under Template name, select Custom, and then select Create.
* On the Basics tab, Name the profile e.g. MacOS – Background Services
* Select Next.
* On the Configuration settings tab, enter a Custom configuration profile name e.g. Background Services
* Deployment Channel: Device Channel (we are going to scope all Defender policies on device groups)
* Configuration profile file: Browse for the downloaded file

![Defender](/files/0IvviotHxIxtE09z3Pzi)

Select Next. On the Assignments tab, assign the profile to a group where the macOS devices and/or users are located, or select the Add all users and Add all devices options. Then select Next. Review the configuration profile. Select Create.

## The Notifications Policy

This profile is used to allow Microsoft Defender for Endpoint on macOS and Microsoft AutoUpdate to display notifications in UI.

First we need to download the [Notifications.mobileconfig file](https://intunestuff.com/wp-content/uploads/2024/05/Notifications.zip) – Unzip the file somewhere on your PC.

To turn off notifications for the end users, you can change Show NotificationCenter from true to false in the file.

![Defender](/files/cKLyVi1ZX1hgMitDHIjm)

To configure background services:

* Under Configuration profiles, select Create Profile.
* Under Platform, select macOS.
* Under Profile type, select Templates.
* Under Template name, select Custom, and then select Create.
* On the Basics tab, Name the profile e.g. MacOS – Notifications
* Select Next.
* On the Configuration settings tab, enter a Custom configuration profile name e.g. Notifications
* Deployment Channel: Device Channel (we are going to scope all Defender policies on device groups)
* Configuration profile file: Browse for the downloaded file

![Defender](/files/zXA52pUfcrUMlLzhZVns)

Select Next. On the Assignments tab, assign the profile to a group where the macOS devices and/or users are located, or select the Add all users and Add all devices options. Then select Next. Review the configuration profile. Select Create.

## The Accessibility Settings Policy

This profile is used to allow Microsoft Defender for Endpoint on macOS to access the accessibility settings on Apple macOS High Sierra (10.13.6) and newer.

First we need to download the [Accessibility.mobileconfig file](https://intunestuff.com/wp-content/uploads/2024/05/Accessibility.zip) – Unzip the file somewhere on your PC.

To configure background services:

* Under Configuration profiles, select Create Profile.
* Under Platform, select macOS.
* Under Profile type, select Templates.
* Under Template name, select Custom, and then select Create.
* On the Basics tab, Name the profile e.g. MacOS – Accessibility Settings
* Select Next.
* On the Configuration settings tab, enter a Custom configuration profile name e.g. Accessibility Settings
* Deployment Channel: Device Channel (we are going to scope all Defender policies on device groups)
* Configuration profile file: Browse for the downloaded file

![Defender](/files/nKhQo1MNQhNzBmlaWApE)

Select Next. On the Assignments tab, assign the profile to a group where the macOS devices and/or users are located, or select the Add all users and Add all devices options. Then select Next. Review the configuration profile. Select Create.

## The Bluetooth Permissions Policy

macOS 14 (Sonoma) contains new privacy enhancements. Beginning with this version, by default, applications cannot access Bluetooth without explicit consent. Microsoft Defender for Endpoint uses it if you configure Bluetooth policies for Device Control.

Bluetooth granted through Apple MDM Configuration Profile is not reflected in System Settings => Privacy & Security => Bluetooth.

First we need to download the [Bluetooth.mobileconfig file](https://intunestuff.com/wp-content/uploads/2024/05/Bluetooth.zip) – Unzip the file somewhere on your PC.

To configure background services:

* Under Configuration profiles, select Create Profile.
* Under Platform, select macOS.
* Under Profile type, select Templates.
* Under Template name, select Custom, and then select Create.
* On the Basics tab, Name the profile e.g. MacOS – Bluetooth Permissions
* Select Next.
* On the Configuration settings tab, enter a Custom configuration profile name e.g. Bluetooth Permissions
* Deployment Channel: Device Channel (we are going to scope all Defender policies on device groups)
* Configuration profile file: Browse for the downloaded file

![Defender](/files/bZ1EHEIPz983ZknRoW19)

Select Next. On the Assignments tab, assign the profile to a group where the macOS devices and/or users are located, or select the Add all users and Add all devices options. Then select Next. Review the configuration profile. Select Create.

## The Microsoft Auto Update Policy

This profile is used to update the Microsoft Defender for Endpoint on macOS via Microsoft AutoUpdate (MAU). If you’re deploying Microsoft Defender for Endpoint on macOS, you have the options to get an updated version of the application (Platform Update) that are in the different channels mentioned here:

* Beta (Insiders-Fast)
* Current channel (Preview, Insiders-Slow)
* Current channel (Production)

First we need to download the [AutoUpdate.mobileconfig file](https://intunestuff.com/wp-content/uploads/2024/05/AutoUpdate.zip) – Unzip the file somewhere on your PC.

To configure background services:

* Under Configuration profiles, select Create Profile.
* Under Platform, select macOS.
* Under Profile type, select Templates.
* Under Template name, select Custom, and then select Create.
* On the Basics tab, Name the profile e.g. MacOS – Auto Update
* Select Next.
* On the Configuration settings tab, enter a Custom configuration profile name e.g. Auto Update
* Deployment Channel: Device Channel (we are going to scope all Defender policies on device groups)
* Configuration profile file: Browse for the downloaded file

![Defender](/files/Ukn56Roi88Pj9jhOr3an)

Select Next. On the Assignments tab, assign the profile to a group where the macOS devices and/or users are located, or select the Add all users and Add all devices options. Then select Next. Review the configuration profile. Select Create.

## Microsoft Defender for Endpoint Configuration Settings

**Set the Microsoft Defender Portal Onboarding Policy**

Go through Configure Microsoft Defender for Endpoint in Intune before setting the security policies using Microsoft Defender for Endpoint Security Settings Management.

In the Intune portal, go to Endpoint Security – Endpoint Detection and Response

* Click Create policy
* Choose MacOS as platform
* Choose Endpoint Detection and Response
* Click Create
* Name your policy e.g. MacOS – Endpoint Detection and Response, click next
* Add your Device Tags

![Defender](/files/2ifChv5fARY2UZU3uJag)

Select Next. On the Assignments tab, assign the profile to a group where the macOS devices and/or users are located, or select the Add all users and Add all devices options. Then select Next. Review the configuration profile. Select Save.

## Set the Microsoft Defender Antivirus Policy

In this policy you will configure the settings of Microsoft Defender itself. These settings are not carved in stone and you can set these for your own needs.

In the Intune portal, go to Endpoint Security – Antivirus

* Click Create policy
* Choose MacOS as platform
* Choose Microsoft Defender Antivirus
* Click Create
* Name your policy e.g. MacOS – Microsoft Defender Antivirus , click next

![Defender](/files/I2dTFbN4BRuJJoTtoOBe)

![Defender](/files/Fo3z4C4Lq3FqQpzFoOT8)

![Defender](/files/srxFnilW2f5vpzXBrzKz)

Select Next. On the Assignments tab, assign the profile to a group where the macOS devices and/or users are located, or select the Add all users and Add all devices options. Then select Next. Review the configuration profile. Select create.

## User Experience Enrolling a device in Intune & Defender (The manual way)

**Dynamic Group**

In this part i will show you how to enroll you MacOS device into Intune and Defender by using the Company portal app. I have created a dynamic device group for MacOS devices, this group is assigned to all different policies and configurations.

![Defender](/files/9qf0vJK2mAyDBR4pliyH)

**Get the Microsoft Defender ATP app for MacOS**

![Defender](/files/31gGXgnCr2VaxWpD8l1B)

Click Select – Next – Assign the app to your desired group(s) – Create

![Defender](/files/iNswAKkLa6OdW44E1XAK)

You will see the app in the list op apps for your Mac

![Defender](/files/N1dXnX8PJN3KSm1wInwQ)

**Get the Microsoft Defender onboarding package for MacOS**

To download the onboarding packages from Microsoft 365 Defender portal:

* In the Microsoft 365 Defender portal, go to Settings > Endpoints > Device management > Onboarding.
* Set the operating system to macOS and the Connectivity type to standard and the deployment method to Mobile Device Management / Microsoft Intune.

![Defender](/files/ppS7QZ2KY5orr6tNRRpv)

This profile contains license information for Microsoft Defender for Endpoint.

To deploy the onboarding package:

* Under Configuration profiles, select Create Profile.
* Under Platform, select macOS.
* Under Profile type, select Templates.
* Under Template name, select Custom.
* Select Create.
* On the Basics tab, Name the profile e.g. MacOS – Onboarding Package
* Select Next.
* On the Configuration settings tab, enter a Custom configuration profile name e.g. Onboarding Package
* Deployment Channel: Device Channel (we are going to scope all Defender policies on device groups)
* Configuration profile file: Browse for the downloaded file
* On the Basics tab, Name the profile e.g. MacOS – Auto Update

**Install the Company Portal app – You can skip this if you have enrolled your device with Apple Business Manager**

Go to [Enroll My Mac](https://go.microsoft.com/fwlink/?linkid=853070?wt.mc_id=MVP_377186). and click Allow

![Defender](/files/Nu4b8dFVB1se3AxZiJ95)

* Wait while the Company Portal installer .pkg file downloads. Open the installer when it’s ready.
* On the Introduction page, select Continue.
* On the License page, read through the Microsoft Application License Terms. Select Continue.
* Select Agree to agree to the terms of the software license agreement.
* On the Installation Type page, select Install.
* Enter your device password or registered fingerprint. Then select Install Software.
* Wait for Company Portal to finish installing.

![Defender](/files/FTm2k5KSzQBAEk4sED35)

Open the Company Portal app.

{% hint style="info" %}
Microsoft AutoUpdate might open after enrollment and update your Microsoft software. After all updates are installed, open the Company Portal app. For the best setup experience, install the latest versions of Microsoft AutoUpdate and Company Portal.
{% endhint %}

**Enroll your Mac -You can skip this if you have enrolled your device with Apple Business Manager**

* Sign in to the Company Portal app with your work or school account. (Approve your MFA)
* On the Set up access page, select Begin.
* Review the privacy information. Then select Continue.
* On the Install management profile page, select Download profile.

![Defender](/files/hDYg2KBJpubnSvze75XY)

Your macOS system settings open in a new window. The management profile you just downloaded is shown. Select the profile to open it.

![Defender](/files/VgK7GNykewSn5dsbAT4l)

Select install

![Defender](/files/a2hFmjEfzbQIXnXd5TC9)

When asked to confirm installation, select Install. Enter your device password to allow the profile to enroll your device. Then select Enroll.

![Defender](/files/U2A6AmCl3FNqhIRxJ5lq)

Wait while the management profile installs and then enrolls your device.

![Defender](/files/U2A6AmCl3FNqhIRxJ5lq)

Return to the Company Portal app and verify that there’s a green checkmark next to Install management profile.

![Defender](/files/bqZfK125gIsiYksbLT7J)

Your organization may require you to update your device settings. On the Checking device settings page, review the list of settings you need to change. Select How to resolve this to view related help documentation in a web browser. After you make all changes, select Retry. Wait while Company Portal rechecks your device settings.

After some time you can check the Intune portal if your device is there, almost immediately my devices shows up as compliant.

![Defender](/files/Bz0WHLPfdJw8gCdAPAYV)

A few minutes later my device is getting al its configuration profiles which we have configured in the previous steps.

![Defender](/files/hInj6BexQlF3Hje6OC2I)

After a few minutes you will receive a pop-up and notice the Defender icon.

![Defender](/files/DRmdb3AYxncqF6ZMp8aC)

When you open the Defender app and you see this all is good.

![Defender](/files/S6EUeJ4QnUs3FktBjo7b)

Now you can go to the [security portal](https://security.microsoft.com/) – Assets – Devices and you will see your device listed in the Defender portal.

![Defender](/files/Vd0zp50kPtTiIQdP8kDv)

And that’s it, congratulations you have just enrolled your Mac in Intune and onboarded it in Defender.

This concludes the setup of Microsoft Defender for MacOS. Now let’s dive into some other cool stuff.


# Declarative Device Management (DDM)

Declarative Device Management (DDM) is an update to the existing protocol for device management that can be used in combination with the existing MDM protocol capabilities. It allows the device to asy

## Declarative Device Management (DDM)

**What is Declarative Device Management (DDM)?**

This is what apple says about DDM:

*Declarative device management is an update to the existing protocol for device management that can be used in combination with the existing MDM protocol capabilities. It allows the device to asynchronously apply settings and report status back to the MDM solution without constant polling. This is ideal for performance and scalability.*

*Declarative device management gives organizations more confidence that devices are in the desired state and that essential data is kept secure, even without internet connectivity. And from a user perspective, it provides a much more responsive experience.*

*Status reporting allows a device to share information about its current state, and if there are any changes, these can be reported to the server proactively without having to poll the device for updates. Extensibility is built into the protocol to ensure that declarative management is designed for the present and the future.*

**Prerequisites**

Before implementing Declarative Device Management (DDM), it is crucial to ensure that the devices being managed have the required hardware and software capabilities. Compatibility with the operating system, firmware, and management tools is essential for a successful implementation.

DDM necessitates devices running at least iOS/iPadOS 15 and macOS 13. These operating systems introduce the necessary features and frameworks to enable autonomous decision-making based on predefined rules and configurations. Therefore, it is important to verify that the devices in your organization meet these requirements before adopting DDM.

**Software Updates**

Declarative Device Management (DDM) facilitates the automated scheduling of software updates, ensuring that devices remain current with the latest patches and enhancements. By defining update policies and schedules, you can ensure timely and efficient software updates across your managed device fleet.

With DDM, you can set rules within the declarative data model that dictate how software updates should be managed on devices. These rules can include criteria such as update availability and scheduling preferences. Devices autonomously check for available updates based on these predefined rules and apply them accordingly.

**How does it Work**

DDM employs three key principles to enhance the software update process, surpassing traditional MDM setups:

* Firstly, for configurations, your MDM instructs the device on how to handle updates. The device then executes these guidelines while also notifying and empowering the user to initiate updates at their convenience.
* Secondly, predicates serve as the foundation for logical operations that dictate the sequence of software updates. This includes managing both seed builds and critical security patches that become available on the device.
* Lastly, real-time status reporting ensures that administrators are promptly informed of any issues, allowing for immediate action.

**Setup the Intune Policy**

Go to Intune Portal – Devices – MacOS – Configuration Profiles – Create – New Policy – Platform MacOS – Profile type Settings Catalog – Create

Name your policy e.g MacOS – Declarative Device Management and give a description if you want.

Click Add settings and browse to Declarative Device Management

![DDM](/files/9l06hrqanGlQSXcPKMFA)

Click on Software update and click select all these settings.

![DDM](/files/mB7KI0BqN8CWsblKCV1r)

Configure the settings:

* Details URL: Enter a web page URL that has more information on the update. This site has all the info regarding the MacOS versions: <https://developer.apple.com/documentation/macos-release-notes>
* Target Build Version: Enter the target build version to update the device to, like 25A354.
* Target Date Time: Select or manually enter the date and the time that specifies when to force the installation of the software update.
* Target OS Version: Enter the target OS version to update the device to. Here you can get the version numbers: <https://support.apple.com/en-us/109033>

These settings will update your MacOS device to the latest Sonoma update by 07/06/2024

![DDM](/files/61nsnE0BKQfmeA3iLmT6)

Click next, fill in scope tags if you have them, assign the policy to your desired group and click create

Your policy will look like this:

![DDM](/files/2jHqoinfnSYRYvEB9Sny)

As the policy arrives on your device you will get a pop-up like this:

![DDM](/files/m5L6cIiemgCP4uS45RBO)

*This is not a notification from my machines as they are already on 14.5, this is a screenshot i took from the internet*

![DDM](/files/C7ErK3uA2ntqvyy7sz0f)

**Delay visibility of updates**

When configuring managed software updates, you might want to hide updates from users for a specific time period. To do this, use a settings catalog policy that sets an update restriction.

A restriction period allows you to test an update before it becomes available to users. Once the restriction period ends, users will be able to see the update. If your update policies haven’t already installed it, users can then choose to install the update themselves.

To create a restrictions policy, navigate to the Settings catalog > Restrictions. Some settings you can use to defer an update include:

* Enforced Software Update Delay
* Enforced Software Update Major OS Deferred Install Delay (macOS)
* Enforced Software Update Minor OS Deferred Install Delay (macOS)
* Enforced Software Update Non OS Deferred Install Delay (macOS)

![DDM](/files/yPw9mh73vzKaQwHaMOFO)

## Settings explained:

**Enforced Software Update Delay:** Sets how many days to delay a software update on the device. With this restriction in place, the user doesn’t see a software update until the specified number of days after the software update release date. This value is used by Force Delayed App Software Updates and Force Delayed Software Updates. Requires a supervised device in iOS. Available in iOS 11.3 and later, and macOS 10.13.4 and later.

**Enforced Software Update Major OS Deferred Install Delay:** This restriction allows the admin to set how many days to delay a major software update on the device. When this restriction is in place the user sees a software update only after the specified delay after the release of the software update. This value controls the delay for Force Delayed Major Software Updates. Available in macOS 11.3 and later.

**Enforced Software Update Minor OS Deferred Install Delay:** This restriction allows the admin to set how many days to delay a minor OS software update on the device. When this restriction is in place the user see a software update only after the specified delay after the release of the software update. This value controls the delay for Force Delayed Software Updates. Available in macOS 11.3 and later.

**Enforced Software Update Non OS Deferred Install Delay:** This restriction allows the admin to set how many days to delay an app software update on the device. When this restriction is in place the user sees a non-OS software update only after the specified delay after the release of the software. This value controls the delay for Force Delayed App Software Updates. Available in macOS 11.3 and later.

**With these settings in place you can configure multiple policies to create different update rings.**

{% hint style="info" %}
A policy that reports Success only means that the configuration successfully installed on the device. Monitor the OS version of targeted devices to ensure that they update. After devices have updated to a later OS version than configured in the policy, the policy will report error as the device sees this as an attempt to downgrade. It’s recommended to remove the older OS version policy from devices in this state.
{% endhint %}

## Wrap Up

Wrap Up Declarative Device Management (DDM) is a groundbreaking approach that enables mobile devices to operate autonomously and proactively. By allowing devices to make decisions based on predefined rules, DDM enhances performance, scalability, and security.

With DDM, organizations can enjoy several advantages. Improved performance and scalability are achieved as devices function independently and efficiently, minimizing the need for constant supervision. This results in faster response times in large-scale deployments and frees up valuable resources for other strategic initiatives.

Enhanced security and compliance are also significant benefits of DDM. By enforcing predefined rules and configurations, organizations can ensure that devices adhere to established guidelines. Policies related to password complexity, encryption requirements, app installation permissions, network access controls, and more are automatically enforced by the devices themselves.

In conclusion, Declarative Device Management revolutionizes mobile device management practices by empowering devices to operate autonomously based on predefined rules.

Moving on……


# Rapid Security Response

Rapid Security Response (RSR) is a new type of software release for Mac. It delivers important security improvements between software updates – for example, improvements to the Safari web browser, the

## Rapid Security Response

**What is Rapid Security Response?**

Rapid Security Responses deliver important security improvements between software updates.

Rapid Security Responses are a new type of software release for iPhone, iPad and Mac. They deliver important security improvements between software updates – for example, improvements to the Safari web browser, the WebKit framework stack or other critical system libraries. They may also be used to mitigate some security issues more quickly, such as issues that may have been exploited or reported to exist.

New Rapid Security Responses will only be delivered for the latest versions of iOS, iPadOS and macOS, starting with iOS 16.4.1, iPadOS 16.4.1 and macOS 13.3.1.

By default, your device will apply Rapid Security Responses automatically. If necessary, you’ll be prompted to restart your device. To check your device settings:

* iPhone or iPad: go to Settings – General – Software Update – Automatic Updates, then make sure “Security Responses & System Files” is turned on.
* Mac: choose Apple menu – System Settings. Click General in the sidebar, then click Software Update on the right. Click the Show Detail button next to Automatic Updates, then make sure “Install Security Responses and system files” is turned on.

![RSS](/files/aGy4Qwx7RqWA3UDbp9j7)

The latest versions of iOS/iPadOS 16.4.1 (a) and macOS 13.3.1 (a) represent a significant shift in how Apple releases OS updates. These updates introduce Rapid Security Response (RSR) for the first time on iPhones, iPads, and Macs. This new feature enables faster delivery of security updates, allowing for more frequent and timely fixes to security vulnerabilities. RSRs are included in subsequent minor updates, not major upgrades, and on a Mac, the updated content appears on the Preboot volume.

There was considerable excitement surrounding the launch of RSR from Apple following its initial announcement. However, the actual release encountered numerous difficulties and unforeseen challenges, resulting in a tumultuous experience. Some of these challenges included:

* A completely new naming convention for the OS.
* Compliance policies in Microsoft Intune not being ready to adapt to the new naming convention.
* Issues with rules and policies configured in Microsoft Defender for Endpoint.
* Conditional Access Policies causing issues due to new iOS/iPadOS or macOS build numbers.

To navigate these changes effectively, it is essential to understand the new updates and how they can be managed on supervised devices. Knowing the installation behavior and how to control it is crucial for achieving the best results.

To fully understand the rapid security updates, I’ve broken down the information into several key points:

* Restart Requirement: Rapid Security Responses (RSRs) intended for the operating system require the device to restart.
* Automatic Updates: If enabled, these responses can occur automatically without user permission, provided the response is not for the OS.
* User Interaction: Once the device requests the RSR update, it will be downloaded, giving users only a 10-second window to click “Not Now.”
* Update Duration: The update process takes approximately 5-10 minutes from start to finish, depending on your internet connection.
* Update Size: The download size is around 85MB. While the installation takes a bit longer, the restart process is relatively quick.
* macOS Specifics: On macOS, updated operating system content can be made available to Safari and associated processes with a simple relaunch. However, a restart is required to make this content broadly available across the operating system.
* iOS & iPadOS Specifics: On iOS and iPadOS, enterprise applications in the foreground may need to be restarted, potentially leading to data loss if not managed properly.
* Uninstallation Option: By default, users have the option to uninstall or remove the responses.
* Software Update Delay: RSRs do not adhere to managed software update delays.
* Intune Software Deferral: If a software deferral policy is enforced from Microsoft Intune, the response is effectively delayed because they apply only to the latest minor operating system version.

## Setup the Intune policy

Go to Intune Portal – Devices – MacOS – Configuration Profiles – Create – New Policy – Platform MacOS – Profile type Settings Catalog – Create

Name your policy e.g MacOS – Rapid Security Response and give a description if you want.

Click Add settings and search for Rapid Security Response and Click Select all these settings:

![RSS](/files/R9TEpkFRmFqoN7LVrNcR)

{% hint style="info" %}
If your organization is not ready to install Rapid Security Response (RSR), you can disable it by toggling the “Installation” option to “False.” This will prevent RSR from being visible on end users’ devices, effectively disabling it for users. **!This is not recommended, as it will leave the device vunerable to threats!**
{% endhint %}

Click next, fill in scope tags if you have them, assign the policy to your desired group and click create

Your policy will look like this:

![RSS](/files/vFyxc42hvP4JnaW4cgr1)

{% hint style="info" %}
If your organization is not ready to install Rapid Security Response (RSR), you can disable it by toggling the “Installation” option to “False.” This will prevent RSR from being visible on end users’ devices, effectively disabling it for users. **!This is not recommended, as it will leave the device vunerable to threats!**
{% endhint %}

## Device experience

If you go to the System settings – Software Update and your screen looks like this, your RSR is not yet enabled.

![RSS](/files/BO3Nmfw8PBY06ZBAKu9J)

If you see an a behind the OS Version that means that RSR is active on your device (As my device is fully up to date, this is a random screenshot from the internet)

![RSS](/files/FSrVQaKFzMXv7OIAlHJQ)

## Wrap Up

Allowing major build upgrades on managed devices without thorough testing and user approval can lead to severe disruptions in business applications, unsatisfactory user experiences, and significant financial losses.

Therefore, it is imperative to exercise utmost caution and diligence when upgrading operating systems. To avoid these issues, responses are tailored to the minor version of the OS and provided between major updates, ensuring a smooth and seamless experience for users. However, it appears that the release of these Rapid Security Response updates was premature. MDM systems still need to adjust a few configurations on the back end before these responses can be effectively rolled out at the enterprise level.


# Custom Compliance Settings for macOS

Define custom compliance checks for macOS in Intune using scripts and JSON rules.

Microsoft Intune supports custom compliance settings for macOS. As an admin, you can define compliance checks using scripts and JSON rules, similar to the existing support for Windows and Linux.

## What custom compliance enables

This capability lets you evaluate device configuration, security posture, and other custom attributes that are not covered by the built-in compliance settings. You author a discovery script that returns values from the Mac, then define JSON rules that specify the expected values used to determine compliance.

## Reporting

Results from custom compliance checks appear alongside standard compliance reporting in the Intune admin center, so administrators can monitor them together with built-in compliance settings.

Learn more: [Microsoft Intune release notes](https://learn.microsoft.com/en-us/intune/whats-new/#custom-compliance-settings-for-macos)


# Await Final Configuration

Understand the macOS "Await Final Configuration" state and learn how to configure it with Microsoft Intune for secure, compliant device deployment.

"Await Final Configuration" is an Apple Device Management state that holds a Mac at the Setup Assistant until required policies are applied, ensuring devices reach the user only once they are secure and compliant. This section explains what the state does and how to configure it with Intune. It is aimed at administrators who want to guarantee a fully configured device before handing it to the end user.

Read the overview first, then follow the configuration steps and review the insights.

* [**What is Await Final Configuration?**](/await-final-configuration/what-is-await-final-configuration) — The Await Final Configuration state for secure, compliant setup.
* [**Configure Await Final Configuration**](/await-final-configuration/configure-await-final-configuration) — Configure the state in Intune for proper setup and compliance.
* [**Insights**](/await-final-configuration/insights) — Practical insights and considerations for Await Final Configuration.


# What is Await Final Configuration?

Explore the 'Await Final Configuration' state in Apple Device Management for secure, compliant, and user-friendly device deployment.

In the realm of Apple device management, particularly in enterprise environments, managing the configuration and deployment of devices is crucial. One of the key features to facilitate this is the “Await Final Configuration” state, which ensures that devices are properly configured before they are fully operational. This post delves into the concept of “Await Final Configuration,” its significance, and how to release a device from this state.

## What is “Await Final Configuration”?

“Await Final Configuration” is a state in Apple Device Management where a device waits for final configuration settings to be applied before it becomes fully operational. This state is particularly useful in scenarios where IT administrators need to ensure that all necessary configurations, policies, and restrictions are in place before the end-user starts using the device. This can include settings like Wi-Fi configurations, security policies, application installations, and more.

## Significance of “Await Final Configuration”

1. **Enhanced Security**: Ensuring that all security policies are enforced before the device is operational helps in protecting sensitive corporate data.
2. **Compliance**: Organizations can ensure that devices comply with corporate policies and industry regulations before they are used.
3. **User Experience**: Pre-configured devices reduce the setup burden on end-users, providing a seamless experience right from the start.
4. **Control**: IT administrators maintain greater control over the deployment and configuration process, ensuring consistency across all devices.


# Configure Await Final Configuration

Configure 'Await Final Configuration' for macOS in Intune to ensure proper device setup and compliance.

## Intune Configuration

1. In the Intune admin center, go to **Devices**, expand **Device onboarding**, and then select **Enrollment**.
2. Select the **macOS** tab.
3. Under **Bulk Enrollment Methods**, select **Enrollment program tokens**.
4. Select an enrollment program token.
5. Select **Enrollment policies** > **Create policy** > **macOS** ![Await Final Configuration](/files/a4ClIvRdi3NdUA8PTd34)
6. Enter a name and description for the policy so that you can distinguish it from other enrollment policies.
7. On the **Configuration settings** page, configure **Enrol with User Affinity & Modern Authentication.**

{% hint style="info" %}
Await Final Configuration & Managed Local Accounts can only be used with User Affinity & Modern Authentication.
{% endhint %}

8. Toggle "Yes" for Await Final Configuration and click Next ![Await Final Configuration](/files/macVDhq5INOLSR2FEl4t)
9. On the **Setup Assistant** page, configure the Setup Assistant experience as per your organisation requirements. 10 On the Account Settings page, Select **Yes** to create local managed account during enrollment. ![Await Final Configuration](/files/P0816hS9i3tfjKcVmTxQ)
10. Toggle "Yes" for blocking users to change their username details.
11. Review changes and click **Create** to finish creating the profile.

## Conclusion

The “Await Final Configuration” state is a powerful feature in Apple Device Management that ensures devices are properly configured and compliant before they are used. By using the Release Device from Await Configuration API endpoint, administrators can efficiently manage and transition devices to their operational state, maintaining security and compliance within their organization.

For more detailed information, you can refer to the [Apple Developer Documentation](https://developer.apple.com/documentation/devicemanagement/release_device_from_await_configuration).


# Insights

Insights about 'Await Final Configuration'.

### API Endpoint: Release Device from Await Configuration

To release a device from the “Await Final Configuration” state, Apple provides a specific API endpoint that allows administrators to transition the device to a fully operational state. This process involves sending a command to the device to finalize its configuration.

Apple’s Device Management API includes the Release Device from Await Configuration endpoint, which is crucial for managing devices in this state. Here’s a high-level overview of how it works:

1. **Endpoint URL**: The specific API endpoint to release a device is:

```
<https://developer.apple.com/documentation/devicemanagement/release_device_from_await_configuration>
```

2. **HTTP Method**: The request method used is POST.
3. **Parameters**:

• device\_id: The unique identifier of the device to be released.

• authorization\_token: A valid token to authenticate the request.

4. **Response**:

• A successful response indicates that the device has been released from the “Await Final Configuration” state and is now fully operational.

**Example Usage**

Here’s an example of how the API call can be made:

```
POST /v1/devices/{device_id}/release

Host: api.apple.com

Authorization: Bearer {authorization_token}

Content-Type: application/json

{

"device_id": "12345-ABCDE",

"release_type": "final"

}
```


# Platform Single Sign-On

Learn what Platform Single Sign-On (PSSO) is and how to configure it on macOS with Microsoft Intune for seamless, secure sign-in across apps and browsers.

Platform Single Sign-On (PSSO) lets macOS users sign in once with their Microsoft Entra ID credentials and gain seamless access across applications and browsers, while strengthening security through Secure Enclave or password-backed authentication. This section explains the concepts behind PSSO and provides step-by-step configuration guidance for IT administrators rolling it out with Intune.

Start with the conceptual overview, then move on to configuration, browser SSO, and field insights.

* [**What is PSSO?**](/platform-single-sign-on-psso/what-is-psso) — Authentication methods, security, and user experience explained.
* [**Configure PSSO**](/platform-single-sign-on-psso/configure-psso) — Step-by-step setup, best practices, and troubleshooting tips.
* [**Browser PSSO**](/platform-single-sign-on-psso/browser-sso) — Configure Platform SSO for Google Chrome and Mozilla Firefox.
* [**Insights**](/platform-single-sign-on-psso/insights-psso) — Security considerations and Secure Enclave vs. Password methods.


# What is PSSO?

Understand the benefits of Platform Single Sign-On (PSSO) for macOS, including authentication methods, security, and user experience.

{% hint style="info" %}
The PSSO feature was something that we have waited a long time for. Having a way for the user to use the same EntraID Password for their sign-in to the Mac is a huge win. Otherwise the user would have to live with two different passwords. With the latest PSSO release, multiple authentication methods are supported, including Secure Enclave, Password Authentication, and Smart Card.
{% endhint %}

Platform Single Sign-On (SSO) for macOS with Microsoft Intune allows users to sign into their Mac devices using their Microsoft Entra ID credentials. This integration simplifies the sign-in process, enhances security, and reduces the number of passwords users need to remember. Key Features and Benefits:

### Authentication Methods

* **Secure Enclave**: Utilizes Apple's Secure Enclave for hardware-bound cryptographic keys, enabling passwordless authentication through Touch ID.
  * This method does not support password sync but is recommended for its security in storing tokens and being phishing resistant. You can find more about the recommendation here: <https://learn.microsoft.com/en-us/mem/intune/configuration/platform-sso-macos#step-1---decide-the-authentication-method>
* **Password Authentication**: Syncs Microsoft Entra ID password with the local macOS account password.
* **Smart Card**: Uses an external smart card for authentication.

{% hint style="warning" %}
Secure Enclave is recommended for its security in storing tokens, it does not support password sync. If password sync is needed, you should use the Password Authentication method.
{% endhint %}

### Security

* Integrates with Apple's Secure Enclave for phishing-resistant, hardware-bound authentication.
* Supports Zero Trust security models by eliminating passwords as primary attack vectors.

### User Experience

* Users can log into their Mac devices and automatically gain access to business applications and websites that support SSO without re-entering credentials.
* The synchronization of local and Entra ID passwords ensures a consistent login experience.

Here is a Video by Windows IT Pro that shows the Platform Single Sign-On experience in detail:

{% embed url="<https://www.youtube.com/watch?v=goccqHf4QS4>" %}

Want to read more about PSSO? Here is the Microsoft Learn Article for it: <https://learn.microsoft.com/en-us/mem/intune/configuration/platform-sso-macos>


# Configure PSSO

Step-by-step guide to configuring Platform Single Sign-On (PSSO) on macOS. Learn best practices, troubleshooting tips, and how to optimize PSSO settings for your organization's security needs.

{% hint style="info" %}
Due to being phishing resistant and generally more secure we will show how to setup PSSO with Secure Enclave in Intune. Alternatively you can follow this guide and select one of the other authentication methods.
{% endhint %}

Before we begin, just a heads up that you can find the official guide by Microsoft here: <https://learn.microsoft.com/en-us/mem/intune/configuration/platform-sso-macos#step-1---decide-the-authentication-method>

While the article by Microsoft goes in detail about the differences of each method and what to choose when, we will focus on the configuration policy.

Here is the final configuration profile:

![PSSO Configuration Profile](/files/5zuq1lE3mcAaNzmsLDGN)

### Import the policy

1. You can [download a ready to use PSSO policy from here](https://github.com/ugurkocde/intunemacadmins/blob/main/content/.gitbook/assets/PSSO/PSSO_Configuration_Policy.json). Right click and select "Save as ..." to save it locally on your device.
2. Go to the [Intune Portal](https://intune.microsoft.com/#view/Microsoft_Intune_DeviceSettings/DevicesMacOsMenu/~/configuration) and sign in.
3. Select Create -> Import Policy and Upload the .json file that you have downloaded earlier.

### Create the policy manually

1. Go to the [Intune Portal](https://intune.microsoft.com) and sign in.
2. Go to Devices -> macOS -> Configuration or use this Link: [macOS | Configuration](https://intune.microsoft.com/#view/Microsoft_Intune_DeviceSettings/DevicesMacOsMenu/~/configuration)
3. Select Create -> New Policy -> Profile Type is Settings Catalog
4. Give the policy a name and click on next
5. You can find the Platform SSO Settings in the Settings picker at Authentication -> Extensible Single Sign On (SSO) -> Platform SSO ![PSSO Settings Picker](/files/in3dxLrVIbKG2eJl8VcP)
6. For our configuration policy please select the following settings from the list:
   1. Platform SSO:
      1. Authentication Method
      2. Use Shared Device Keys
   2. Registration Token
   3. Screen Locked Behavior
   4. Team Identifier
   5. URLs
7. After selecting the above settings your profile should look like the following screenshot: ![PSSO Configuration Profile](/files/PQpIfUdtS9nErg2pEiFi)
8. We can now configure the settings. Here is a working example: ![PSSO Configuration Profile](/files/5zuq1lE3mcAaNzmsLDGN)
9. After that, you can add scope tags and assign the policy.
10. Done :)

This video shows the user experience:

{% embed url="<https://www.youtube.com/watch?v=goccqHf4QS4>" %}


# Browser PSSO

Configuring Platform SSO for web browsers such as Google Chrome and Mozilla Firefox.

{% hint style="info" %}
Microsoft Edge and Safari will natively support Platform SSO sign-ins to Microsoft Entra ID authenticated website when a device is configured with PSSO.
{% endhint %}

After configuring PSSO with either Secure Enclave (preferred) or password synchronisation, you might want to extend the PSSO configuration to additional web browsers such as Google Chrome or Mozilla Firefox, and not just Microsoft Edge and Apple Safari.

This can be achieved in Intune using both Custom profiles (Google Chrome) and Preference files (Mozilla Firefox) to enable Entra SSO in each browser platform.

## Google Chrome

Google provide [examples](https://support.google.com/chrome/a/answer/7517624?sjid=1791799825719492891-EU) of their mobileconfig files for macOS to allow for configuration of the browser on this platform, including the forced installation of browser extensions to enable the [Microsoft Single Sign On extension](https://chromewebstore.google.com/detail/microsoft-single-sign-on/ppnbnpeolgkicgegkbkbjmhlideopiji) to support the SSO configuration.

A preconfigured mobileconfig file is available that will force the installation of the Microsoft Single Sign On extension to support PSSO in Google Chrome.

### Intune Custom Profile

To create a new **Custom** Profile in Intune to support PSSO:

1. You can [download the mobileconfig file here](https://github.com/ugurkocde/intunemacadmins/blob/main/content/.gitbook/assets/PSSO/PSSO_GoogleChrome.mobileconfig). Right click and select "Save as ..." to save it locally on your device.
2. Go to the [Intune Portal](https://intune.microsoft.com/#view/Microsoft_Intune_DeviceSettings/DevicesMacOsMenu/~/configuration) and sign in.
3. Select **Create -> New Policy**.
4. Select **Templates** from Profile type.
5. Select **Custom** from the list of templates.
6. Enter in a name for the policy e.g, `MAC-PSSO-GoogleChrome`
7. Enter in a suitable name for the profile name e.g., `Google Chrome Platform SSO Profile`
8. Select the **Device channel** for deployment channel.
9. Select **Browse** and select the mobileconfig file you downloaded in Step 1.
10. Click **Next** to select Scope Tags
11. Click Next to select your assignment targets.

The users or devices in scope of this policy, where Google Chrome is installed, will now be configured for PSSO within the Chrome browser with the required extension installed, and unable to be removed from the browser.

## Mozilla Firefox

Mozilla provides [details](https://mozilla.github.io/policy-templates/) on how to configure the Firefox browser on macOS, including enabling [Microsoft Entra SSO](https://mozilla.github.io/policy-templates/#microsoftentrasso) using a preference file.

A preconfigured preference file is available to configure PSSO within the Mozilla Firefox browser.

### Intune Preference file

To create a new **Preference file** profile in Intune to support PSSO:

1. You can [download the preference file here](https://github.com/ugurkocde/intunemacadmins/blob/main/content/.gitbook/assets/PSSO/PSSO_MozillaFirefox.plist). Right click and select "Save as ..." to save it locally on your device.
2. Go to the [Intune Portal](https://intune.microsoft.com/#view/Microsoft_Intune_DeviceSettings/DevicesMacOsMenu/~/configuration) and sign in.
3. Select **Create -> New Policy**.
4. Select **Templates** from Profile type.
5. Select **Preference file** from the list of templates.
6. Enter in a name for the policy e.g, `MAC-PSSO-MozillaFirefox`
7. Enter `org.mozilla.firefox` as the **Preference domain name**
8. Select **Browse** and select the plist file you downloaded in Step 1.
9. Click **Next** to select Scope Tags
10. Click Next to select your assignment targets.

The users or devices in scope of this policy, where Mozilla Firefox is installed, will now be configured for PSSO within the Firefox browser.


# Insights

Explore key insights on Platform Single Sign-On (PSSO) for macOS, including security considerations, user experience, and the benefits of Secure Enclave vs. Password methods.

* Before setting up PSSO you should think about your approach and communication with the enduser. While your Security Department could expect you to implement the most secure Authentication Method, in this case this is Secure Enclave, your users and the IT Department would expect to use a single password for the local and online (EntraID) accounts.
* Secure Enclave only provides this additional security layer by NOT storing the keys and tokens in the Keychain like the Password method does.
* Secure Enclave could still be the best user experience because users do not need to technically use a password when they use touch id for the sign-in. This way a missing password sync will not be that important anymore but still be phishing resistant.
* Tokens and Keys stored in the Secure Enclave are Hardware Bound (Phishing Resistant). You can not export Tokens or Sync them via iCloud which makes this the most secure way.
* Secure Enclave with PSSO and TouchID has a very similar User Experience feeling like Windows Users have with Windows Hello for Business.
* The Password Method is storing Keys in the KeyChain which is software based. Users or Attackers could export the tokens and reuse them on a different device. This is why Microsoft and Apple is recommending to use Secure Enclave.


# Declarative Device Management

Understand Declarative Device Management (DDM) on macOS and learn how to configure it with Microsoft Intune for scalable, responsive device management.

Declarative Device Management (DDM) is an evolution of Apple's MDM protocol that lets devices apply settings and report status asynchronously, without constant polling of the management server. This improves performance, scalability, and responsiveness for managed macOS fleets. This section explains how DDM works and how to enable it with Intune.

Read the concept overview first, then follow the configuration steps and review the insights.

* [**What is Declarative Device Management?**](/declarative-device-management-ddm/what-is-declarative-device-management) — Learn how DDM works on macOS and the benefits it brings.
* [**Configure Declarative Device Management**](/declarative-device-management-ddm/configure-declarative-device-management) — Step-by-step guide to enabling DDM on macOS with Intune.
* [**Insights**](/declarative-device-management-ddm/insights) — Practical insights and considerations for working with DDM.


# What is Declarative Device Management?

Learn about Declarative Device Management (DDM), its benefits, and how it works on macOS devices.

*Declarative Device Management (DDM)* is a revolutionary approach to managing mobile devices that empowers them to be autonomous and proactive. One of the key advantages of DDM is improved performance and scalability. By enabling devices to operate autonomously, devices can proactively perform tasks, make decisions, and adjust configurations based on predefined rules. This not only increases efficiency but also allows for faster response times, especially in large-scale deployments.

Another benefit of DDM is the reduced administrative burden it brings. With traditional device management approaches, administrators often have to manually configure each device individually or rely on scripts and profiles to enforce policies. This can be time-consuming and prone to errors. With DDM, administrators can define configurations once using a declarative data model, which is then applied automatically across all managed devices.

Security is another area where DDM shines. By leveraging predefined rules and configurations, DDM enhances security by ensuring devices adhere to established guidelines. Administrators can define policies related to password complexity, encryption requirements, app installation permissions, network access controls, and more. These policies are enforced automatically by the device itself without requiring constant monitoring or intervention from administrators.

## Understanding Declarative Device Management (DDM)

![Declarative Device Management](/files/LRfXiNnXISJyJXweob2s)

Declarative device management is **an update to the existing protocol for device management that can be used in combination with the existing MDM protocol capabilities**. It allows the device to asynchronously apply settings and report status back to the MDM solution without constant polling

With DDM, administrators define configurations once using the declarative data model, which is then applied automatically across all managed devices. Devices become more intelligent and self-sufficient, capable of adjusting their settings and behavior based on predefined rules. This level of autonomy allows devices to operate efficiently without requiring constant supervision or intervention from administrators.

## Benefits of Declarative Device Management

DDM brings several benefits for IT professionals and Mobile Device Management administrators:

1\. **Improved performance and scalability**: By allowing devices to operate independently and efficiently, DDM improves overall performance and scalability. Devices can proactively perform tasks, adjust configurations, and make decisions based on predefined rules. 2. **Reduced administrative burden**: With DDM, devices can make decisions and perform tasks without constant supervision from administrators. 3. **Enhanced security and compliance**: DDM enhances security by enforcing predefined rules and configurations across all managed devices. You can define policies related to password complexity, encryption requirements, app installation permissions, network access controls, and more.

### How Declarative Device Management Works

1\. **Declarations** Declarations are a fundamental aspect of Apple Declarative Device Management. They serve as the building blocks that enable devices to apply logic autonomously. A declaration is a configuration item that specifies a desired state or behavior for a device. It can include settings, restrictions, or even custom actions.

2\. **Status Channel** The status channel plays a crucial role in facilitating communication between devices and the MDM server in Declarative Device Management. It serves as a bidirectional channel through which devices can report their current state and receive updates from the server.

When a device receives declarations from the MDM server, it periodically sends status updates to inform the server about its compliance with those declarations. This continuous feedback loop ensures that administrators have real-time visibility into device status and can take appropriate actions if deviations occur.

3\. **Extensibility** Extensibility is another key pillar of Declarative Device Management, offering flexibility and customization options for organizations. It allows for integration with other systems and services, enabling administrators to leverage existing infrastructure and workflows.

The flow below shows you when a device is already enrolled in MDM and you activate Declarative Management: ![Declarative Device Management](/files/L7lfbIt7ktrmWlpoS2vH)

This flow shows you after your activation completes and a CheckIn request occurs: ![Declarative Device Management](/files/Xk9yhvuupRqRWuKSQJQa)

Declarative Device Management (DDM) is a revolutionary approach that empowers mobile devices to operate autonomously and proactively. By allowing devices to make decisions based on predefined rules, DDM improves performance, scalability, and security.


# Configure Declerative Device Management

Step-by-step guide to configuring Declarative Device Management (DDM) on macOS.

The declarations and the status channels of declarative management can co-exist with Intune commands and profiles, which means you can gradually adopt the new features, without having to update all MDM work flows at once. For example, a server might just implement status subscriptions to effectively add a status channel to the MDM protocol without having to adopt all of declarative management.

Importantly, this integration doesn’t interfere with existing Intune behavior. Declarative management has to be explicitly enabled with a new MDM command, before you can use any of its features. Without that enablement, the MDM protocol functions exactly as before.

**Enable declarative management**

Intune enables declarative management by sending a DeclarativeManagementCommand to the device through the usual Intune command processing flow. This command serves two purposes:

* It enables the declarative management features.
* It signals to the device that the server has updated declarations and the device needs synchronize the declarations with the server. In this case, the command can include a payload containing synchronization tokens to allow for an efficient synchronization flow.

Once Intune has enabled declarative management, it can’t disable it. However, the server can remove all declarations from the device to effectively disable any declarative management behavior.

If you unenroll a device, the device removes all declarative management state, including all policies applied through declarations.

Note, that on macOS and Shared iPad, you must send the management commands separately on the device and user channels to turn on declarative management on each channel. Similarly, each channel reports declarative management status separately.

**Microsoft Intune** has also enabled Declarative Management for macOS for the following capabilities:

1. Software Update
2. Passcode

Apple's declarative device management (DDM) allows you to install a specific update by an enforced deadline. The autonomous nature of DDM provides an improved user experience as the device handles the entire software update lifecycle. It prompts users that an update is available and also downloads, prepares the device for the installation, & installs the update.

Lets create a MacOS Software Update Policy that uses DDM.

## Configure the managed software updates policy

1. Sign in to the Intune admin center.
2. Select Devices > Manage devices > Configuration > Create.
3. Enter the following properties and select Create:
   1. Platform: Select macOS.
   2. Profile: Select Settings catalog.
4. In the Basics tab, enter the following information, and select Next:
   1. Name: Enter a descriptive name for the policy. Name your policies so you can easily identify them later.
   2. Description: Enter a description for the policy. This setting is optional, but recommended.
5. In Configuration settings, select Add settings > expand Declarative Device Management > Software Update.
6. Choose Select all these settings and then close the settings picker. ![Declarative Device Management](/files/KJb1SpkZRO7H0sfdXStg)
7. Configure the settings:
   1. Details URL: Enter a web page URL that has more information on the update. Typically, this URL is a web page hosted by your organization that users can select if they need organization-specific help with the update.
   2. Target Build Version: Enter the target build version to update the device to, like 25A354. The build version can include a supplemental version identifier, like 25A354a. If the build version you enter isn't consistent with the Target OS Version value you enter, then the Target OS Version value takes precedence.
   3. Target Date Time: Select or manually enter the date and the time that specifies when to force the installation of the software update. The Target Date Time setting schedules the update using the local timezone of the device. For example, an admin configures an update to install at 2PM. The policy schedules the update to happen at 2PM in the local timezone of devices that receive the policy.
   4. If the user doesn't trigger the software update before this time, then a one-minute countdown prompt is shown to the user. When the countdown ends, the device force installs the update and forces a restart.
   5. If the device is powered off when the deadline is met, when the device powers back on, there's a one hour grace period. When the grace period ends, the device force installs the update and forces a restart.
   6. Target OS Version: Select or manually enter the target OS version to update the device to. This value is the OS version number, like 26.0. You can also include a supplemental version identifier, like 26.0.1. ![Declarative Device Management](/files/Hl4RdWE9MaiVF5kzvOad)
8. Select Next.
9. In the Scope tags tab (optional), assign a tag to filter the profile to specific IT groups. For more information about scope tags, go to Use role-based access control and scope tags for distributed IT.
10. Select Next.
11. In the Assignments tab, select the users or groups that will receive your profile. For more information on assigning profiles, go to Assign user and device profiles.
12. Select Next.
13. In the Review + create tab, review the settings. When you select Create, your changes are saved, and the profile is assigned. The policy is also shown in the profiles list.


# Insights

Insights about 'Declarative Device Management'.


# Custom Attributes

Learn what custom attributes are and how to create custom attribute scripts in Microsoft Intune to collect tailored data from managed macOS devices.

Custom attributes let you collect specific information from managed macOS devices using shell scripts, extending Intune's built-in reporting and enabling richer device configuration and automation. This section explains what custom attributes are, how to build a custom attribute script, and the insights to get the most out of them. It is written for administrators who need device data beyond Intune's default inventory.

Start with the concept overview, then create your first script and review the insights.

* [**What are Custom Attributes?**](/custom-attributes/what-are-custom-attributes) — Benefits and how custom attributes enhance reporting and automation.
* [**Create a Custom Attribute Script**](/custom-attributes/create-custom-attributes) — Build a script to collect specific information from macOS devices.
* [**Insights**](/custom-attributes/insights) — Best practices, use cases, and expert tips for custom attributes.


# What are Custom Attributes?

Learn about custom attributes in macOS management, their benefits, and how they enhance device configuration, reporting, and automation in Intune.

## What are Custom Attributes in macOS?

In the world of macOS, custom attributes are a powerful feature that enables administrators to extend the management capabilities of their Mac environments. These attributes can be leveraged to track, configure, and manage various aspects of macOS devices in ways that are tailored to the specific needs of an organization. Let´s explore what custom attributes are, their benefits, and how they can be utilized in macOS management.

## Understanding Custom Attributes

Custom attributes in macOS are essentially additional fields that can be created and assigned to devices within Intune. These fields can store information that is not natively included in the macOS management schema. For example, you might want to track specific inventory details, user preferences, or custom configuration settings that are unique to your organization's requirements.

## Examples of Custom Attributes

1. **Device Inventory Information**: Track specific hardware components, such as the presence of certain peripherals or custom hardware configurations.
2. **User Preferences**: Store user-specific settings that are required for customized application configurations.
3. **Security Compliance**: Monitor and report on the status of security settings that are not covered by default macOS policies.
4. **Custom Configuration**: Apply unique configurations or scripts based on the values of these custom attributes.

## Benefits of Custom Attributes

Custom attributes provide several benefits that can enhance the management and deployment of macOS devices within an organization:

1. **Flexibility**

Custom attributes offer a level of flexibility that allows IT administrators to tailor their management approach to the specific needs of their organization. By defining attributes that are relevant to their environment, administrators can capture and utilize data that would otherwise be inaccessible.

2. **Enhanced Reporting**

With custom attributes, reporting becomes more comprehensive. Administrators can generate reports that include custom data points, providing deeper insights into the status and configuration of their macOS devices. This can be particularly useful for auditing and compliance purposes.

3. **Improved Automation**

Custom attributes can be used in conjunction with automation tools to create dynamic workflows. For example, a script can be triggered based on the value of a custom attribute, allowing for automated configuration changes or updates. This can significantly reduce the manual effort required to manage large fleets of devices.

4. **Better User Experience**

By leveraging custom attributes, administrators can ensure that users receive a more tailored and consistent experience. For instance, user-specific settings can be automatically applied based on custom attributes, ensuring that each user has the necessary configurations for their role.

Use your MDM solution's reporting features to monitor the values of custom attributes and generate reports. This will help you track the status and compliance of your devices.

## Conclusion

Custom attributes in macOS are a versatile and powerful feature that can significantly enhance the management capabilities of IT administrators. By providing the flexibility to track and utilize additional information, custom attributes enable more tailored, automated, and effective management of macOS devices. Whether you're looking to improve reporting, automate workflows, or enhance the user experience, custom attributes offer a valuable toolset to meet your organization's unique needs.

Embrace the power of custom attributes and take your macOS management to the next level!

If you have any questions or need further assistance with implementing custom attributes in your macOS environment, feel free to reach out in the comments below. Happy managing!


# Create a Custom Attribute Script

Learn how to create a custom attribute script in Intune to collect specific information from managed macOS devices.

Custom attributes in Intune allow you to collect specific information from managed macOS devices using shell scripts. One useful application is to retrieve the last reboot time of a device. This can be valuable for troubleshooting, maintenance scheduling, or ensuring compliance with reboot policies.

### Last Reboot Time Script

To get the last reboot time of macOS devices, you can use the following shell script:

```bash
#!/bin/bash
# Script to get the last reboot time formatted

# Extracting the timestamp from the sysctl command
timestamp=$(sysctl kern.boottime | awk '{print $5}' | tr -d ',')

# Converting the timestamp to a formatted date
formatted_date=$(date -r $timestamp "+%Y-%m-%d %H:%M:%S")

echo "Last Reboot Time: $formatted_date"
```

This script does the following:

1. Extracts the boot timestamp using the `sysctl` command.
2. Processes the timestamp with `awk` and `tr` to clean up the output.
3. Converts the timestamp to a human-readable date format.
4. Outputs the formatted last reboot time.

### Configuring the Custom Attribute

To use this script as a custom attribute in Intune:

1. Go to the Intune portal and navigate to Devices > By platform > macOS > Manage devices > Scripts. ![Custom Attribute](/files/qdS3tH6jGeCowPo4uwzH)
2. Click on "+ Add" to create a new custom attribute.
3. Provide a name (e.g., "Last Reboot Time") and description for the attribute. ![Custom Attribute](/files/VyBGJDAqY9YyPxcDCFdJ)
4. Upload the script and set the data type to "String". ![Custom Attribute](/files/KLRdJHyquuTBWJrtuQPr)
5. Assign the custom attribute to the devices you want to collect the data from.

After configuration, Intune will run this script on the targeted devices and collect the last reboot time information. You can then view this data in the Intune portal or use it for reporting and compliance purposes.

{% hint style="info" %}
Custom Attributes run every 8 hours by default. You can not change the frequency of the script and you can not run it on-demand.
{% endhint %}

### Viewing Results

Once the custom attribute is deployed and executed on the devices, you can view the results by:

1. Going to the Intune portal and selecting a macOS device.
2. Navigating to the "Custom Attributes" section.
3. Looking for the "Last Reboot Time" attribute in the list. ![Custom Attribute](/files/CmqookiuzxemMQFkb0QI)

The result will show the last reboot time of the device in the format: "YYYY-MM-DD HH:MM:SS".

By implementing this custom attribute, you gain valuable insights into the uptime of your managed macOS devices, helping you maintain a more secure and efficient IT environment.

[Learn more about custom attributes for macOS in Intune](https://ugurkoc.de/get-local-admins-and-last-reboot-time-on-macos-devices-using-custom-attributes/)


# Insights

Gain valuable insights into using custom attributes for macOS management. Discover best practices, use cases, and expert tips for leveraging this powerful feature.

## Insights on Custom Attributes in macOS


# FileVault

Learn what FileVault is and how to enable macOS full-disk encryption during the Setup Assistant with Microsoft Intune to protect data on managed Macs.

FileVault is macOS's built-in full-disk encryption feature, protecting data at rest so it cannot be read if a device is lost or stolen. This section covers what FileVault is, how to enable it during the Setup Assistant with Intune, and the insights you need to manage encryption and recovery keys in production. It is aimed at IT administrators responsible for endpoint security and compliance on macOS.

Begin with the overview, then follow the setup guide and review the field insights.

* [**What is FileVault?**](/filevault/what-is-filevault) — Key features and benefits of macOS built-in disk encryption.
* [**Enable FileVault in Setup Assistant**](/filevault/enable-filevault-in-setup-assistant) — Prerequisites, configuration profiles, and best practices.
* [**Insights**](/filevault/insights) — Advanced topics, troubleshooting, and expert recommendations.


# What is FileVault?

Learn about FileVault, macOS's built-in disk encryption feature. Discover its key features, benefits, and how it enhances data security on your Mac.

FileVault is a disk encryption program available in macOS, designed to protect data by encrypting the entire drive.

## Key Features of FileVault

* Full Disk Encryption: Encrypts the entire drive to ensure all data is secure.
* Strong Security: Uses XTS-AES 128-bit encryption for robust data protection.
* Seamless Integration: Built into macOS, providing a native solution without the need for third-party software.
* Recovery Key: Generates a recovery key that can be used to unlock the disk if the password is forgotten.
* Institutional Recovery Key: Organizations can create and manage an institutional recovery key for IT admin access.
* Automatic Encryption: Once enabled, encryption occurs in the background as you use your Mac, without impacting performance.

## Benefits of Using FileVault

* Enhanced Security: Protects sensitive information from unauthorized access, especially in case of theft or loss.
* Compliance: Helps meet regulatory requirements for data protection in various industries.
* Peace of Mind: Ensures that personal and corporate data remain secure at all times.


# Enable FileVault in Setup Assistant

Step-by-step guide on enabling FileVault during macOS Setup Assistant using Intune. Learn about prerequisites, configuration profiles, and best practices.

## Prerequisites

Before we start with the FileVault configuration profile in Intune, we have to complete following requirements:

1. Enable Await Final Configuration
   1. Follow the guide here to enable it: [Configure Await Final Configuration](/await-final-configuration/configure-await-final-configuration)
2. Create a Filter using the EnrollmentProfileName
   1. Follow the guide below to create the filter.

**Create a Filter using the EnrollmentProfileName**

1. Go to the [Intune Portal](https://intune.microsoft.com) and sign in.
2. Go to the Tenant Administration -> Filters -> Create -> Managed Devices
3. Give this filter a name and select macOS as the platform.
4. Now on the Rules page, select
   1. Property = EnrollmentProfileName,
   2. Operator = Equals
   3. Value is the Name of your Enrollment Profile that you can find here: [Enrollment program tokens](https://intune.microsoft.com/#view/Microsoft_Intune_Enrollment/DepTokensPagingBlade) and then select your Token to see your Enrollment Profile. If you do not have a Profile, you have to create one or else the whole Deployment and Enrollment for your macOS Devices will not work.
5. Here is an example of how it could look like: ![Intune Device Filter](/files/k4x2ZkB6QixP6IQJqdeM)

{% hint style="success" %}
Generally speaking, using a Device Filter instead of assigning your policies to a dynamic group is much faster, because Intune does not need to sync with EntraID and evaluate which devices are in the dynamic group and which are not. With the help of the above Filter, Intune knows the devices because it just checks its own inventory instead of connecting with EntraID. Only this way, your policies will arrive on a device that is in the Setup Assistant fast enough to be enabled or configured.
{% endhint %}

## Configration Profile

If you have Await Final Configuration enabled and also have created a Device Filter you are ready to create your FileVault Configration.

You can either download and import the Configuration Profile from here: [Enable FileVault during Setup Assistant](https://github.com/ugurkocde/intunemacadmins/blob/main/content/.gitbook/assets/FileVault/Enable_FileVault_during_Setup_Assistant.json)

or create your own profile following this guide:

1. Go to the [Intune Portal](https://intune.microsoft.com) and sign in.
2. Go to Devices -> By platform -> macOS -> Manage devices -> Configuration and Create a new policy.
   1. Profile type: Settings catalog
3. Give it a descriptive name and click on Next. Example: *Enable FileVault during Setup Assistant*
4. Click on Add settings and search for FileVault. ![FileVault](/files/RN9ZY7qTWwnoHZRWtsTD)
5. Select *Force Enable in Setup Assistant* (this will automatically select *Enable*)
6. Let´s also configure *Prevent FileVault From Being Disabled*. You can find it in the *FileVault Options* category. ![FileVault](/files/13MoIDyDpleZFJSJiLs1)
7. Let´s configure the settings after adding them to the profile:
   1. Force Enable In Setup Assistant = True
   2. Enable = On
   3. Prevent FileVault From Being Disabled = True
8. After assigning and saving the profile, the settings should like the following: ![FileVault](/files/O9gf5ctyW5T6m08a97Ga)


# Insights

Gain valuable insights into FileVault for macOS. Explore advanced topics, troubleshooting tips, and expert recommendations for optimal FileVault implementation.


# OneDrive Known Folder Move (KFM)

Learn what OneDrive Known Folder Move (KFM) is and how to configure it on macOS with Microsoft Intune to redirect and back up users' key folders to OneDrive.

OneDrive Known Folder Move (KFM) redirects users' Desktop, Documents, and other key folders into OneDrive, providing automatic cloud backup and continuity across devices on macOS. This section explains what KFM is, how to configure it with Intune, and the insights you need to avoid common pitfalls such as conflicts with iCloud sync. It is aimed at administrators rolling out OneDrive folder backup for Mac users.

Read the overview first, then follow the configuration steps and review the insights.

* [**What is OneDrive KFM?**](/onedrive-known-folder-move-kfm/what-is-onedrive-kfm) — Learn about KFM, its benefits, and how it works on macOS.
* [**Configure KFM**](/onedrive-known-folder-move-kfm/configure-kfm) — Step-by-step setup, best practices, and troubleshooting tips.
* [**Insights**](/onedrive-known-folder-move-kfm/insights) — Troubleshooting tips and potential conflicts with iCloud sync.


# What is OneDrive KFM?

Learn about OneDrive Known Folder Move (KFM), its benefits, and how to configure it for macOS devices.

{% hint style="info" %}
OneDrive is a cloud storage service provided by Microsoft that allows users to store files and data online.
{% endhint %}

OneDrive Known Folder Move (KFM) allows the redirection of common folders to OneDrive, ensuring they are automatically backed up and accessible from any device and browser. On macOS, KFM supports the redirection of the following folders:

```
~/Desktop
~/Documents
```

To activate KFM on macOS, multiple Intune profiles are required. The specific profiles and configuration steps are detailed on the next page: [Configure KFM](/onedrive-known-folder-move-kfm/configure-kfm)


# Configure KFM

Step-by-step guide to configuring OneDrive Known Folder Move (KFM) on macOS. Learn best practices, troubleshooting tips, and how to optimize KFM settings for your organization's needs.

## OneDrive sync app

KFM is only supported by the **standalone OneDrive sync app** (e.g. contained in Microsoft 365 Apps package in Intune). The version from **macOS App Store does not support KFM**.

## Intune Policies

### OneDrive settings

The following settings control the behavoiur of KFM: We are forcing KFM and enable it silently for Desktop and Documents. We also activate the KFM wizard to prompt users for activation (e.g.: kicks in if errors occur).

1. You can [download a ready to use KFM policy from here](https://github.com/ugurkocde/intunemacadmins/blob/main/content/.gitbook/assets/OneDrive/OneDriveKFM.json). Right click and select "Save as ..." to save it locally on your device.
2. Go to the [Intune Portal](https://intune.microsoft.com/#view/Microsoft_Intune_DeviceSettings/DevicesMacOsMenu/~/configuration) and sign in.
3. Select Create -> Import Policy and Upload the .json file that you have downloaded earlier.
4. Edit the policy and **replace "XYZ"** with your **Tenant ID** (two times).
5. Assign the policy to the desired (test) group.

### Service Management

OneDrive needs to run in background. Since macOS 13 (Ventura) this has to be consented explicitly. If you already have a policy for Service Management (Managed Login Items) you can add OneDrive there, too.

1. You can [download a ready to use Service Management policy from here](https://github.com/ugurkocde/intunemacadmins/blob/main/content/.gitbook/assets/OneDrive/OneDriveServiceManagement.json). Right click and select "Save as ..." to save it locally on your device.
2. Go to the [Intune Portal](https://intune.microsoft.com/#view/Microsoft_Intune_DeviceSettings/DevicesMacOsMenu/~/configuration) and sign in.
3. Select Create -> Import Policy and Upload the .json file that you have downloaded earlier.
4. Assign the policy to the desired (test) group.

### Full Disk Access

OneDrive needs Full Disk Access for KFM. If you already have a policy for Privacy Preferences Policy Control (that grants "System Policy All Files") you can add OneDrive there, too.

1. You can [download a ready to use Full Disk Access policy from here](https://github.com/ugurkocde/intunemacadmins/blob/main/content/.gitbook/assets/OneDrive/OneDriveFullDiskAccess.json). Right click and select "Save as ..." to save it locally on your device.
2. Go to the [Intune Portal](https://intune.microsoft.com/#view/Microsoft_Intune_DeviceSettings/DevicesMacOsMenu/~/configuration) and sign in.
3. Select Create -> Import Policy and Upload the .json file that you have downloaded earlier.
4. Assign the policy to the desired (test) group.


# Insights

Discover important insights about OneDrive Known Folder Move (KFM) for macOS, including troubleshooting tips and potential conflicts with iCloud sync.

## Policies in place but KFM not starting

Please ensure, that your are using OneDrive sync app standalone. If the version from App Store is used, noting will happen.

## iCloud

KFM might interfere with iCloud sync. So please verify that your users are not using this service with their Apple ID in parallel. You might use the settings from Device restrictions to block this (available via settings catalog):

* Allow Cloud Desktop And Documents
* Allow Cloud Document Sync


# Updating Microsoft Apps

Learn how to keep Microsoft apps up to date on macOS devices with Microsoft AutoUpdate (MAU) and Microsoft Intune.

Keeping Microsoft applications current on macOS is essential for security and reliability, and Microsoft AutoUpdate (MAU) is the tool that makes it possible. This section explains what MAU is and how to manage Microsoft app updates on Intune-managed Macs, including practical considerations for controlling update behavior. It is written for administrators responsible for patching and app lifecycle on macOS.

Start with the how-to guide, learn how MAU works, and review the insights.

* [**How to Update Microsoft Apps**](/updating-microsoft-apps/how-to-update-microsoft-apps) — Update Microsoft apps on macOS using Microsoft AutoUpdate (MAU).
* [**What is Microsoft Auto Update (MAU)?**](/updating-microsoft-apps/microsoft-auto-update) — Key features of MAU and how it keeps Microsoft apps up to date.
* [**Insights**](/updating-microsoft-apps/insights) — Key considerations for keeping Microsoft apps updated with Intune.


# How to Update Microsoft Apps

Learn how to update Microsoft apps on macOS devices using Microsoft AutoUpdate (MAU).

Before you start configuring policies for MAU, it is necessary to understand that it actually works.

The Microsoft AutoUpdate (MAU) checks for application updates every 12 hours by examining a version number that is embedded in an XML file, commonly referred to as a 'manifest,' which is located online. This version number is then contrasted with the version of the app that is presently installed on the local system. If the background process detects that the XML file points to a more recent version than the installed one, the full MAU application window pops open, prompting users to execute an update.

## Update process breakdown

* Checking for Updates: By default, MAU periodically checks for updates in the background. It communicates with Microsoft servers to see if there are any new patches, improvements, or features available for your installed Microsoft applications.
* Download and Installation: Depending on the settings you've chosen, MAU either notifies you about available updates or directly downloads and installs them. If you've opted for automatic updates, the process happens in the background, ensuring your Microsoft applications are always current.
* Update Notifications: If your settings allow for it, MAU will send you a notification whenever updates are available. You can then choose whether to download and install the updates immediately or delay them for a later time.
* Application Closure for Updates: Some updates may require the target application to close for successful installation. MAU will prompt you to close the application if it is running during the update process.
* System Restart: Certain significant updates might need a system restart to be fully integrated. MAU will notify you and request a system restart after the installation of such updates.

## Microsoft AutoUpdate (MAU) Options

* **Manual Updates**: In your Microsoft apps, you can manually check for updates by clicking on the 'Help' menu and selecting 'Check for Updates'. This will open the MAU interface, where you can view any available updates and manually initiate their download and installation. ![MAU](/files/iuWRNL1qL7hhVhEhAfSG)
* **Automatic Updates**: If you prefer not to manually check for updates, you can configure MAU to download and install updates automatically. This is particularly useful as it ensures you always have the most recent version of the application without needing to remember to check for updates regularly. ![MAU](/files/M4JW1Em3ATNVKHmII6ew)
* **Scheduled Updates**: MAU can also be set to check for updates on a specific schedule. This can be configured in the 'How would you like updates to be installed?' section in the MAU interface.
* **Choosing Update Channel**: With MAU, you can also select your preferred update channel, for instance, 'Current,' 'Monthly Enterprise,' 'Semi-Annual Enterprise,' or 'Beta'. The update channel you're subscribed to can influence the frequency and type of updates you receive. ![MAU](/files/SU6esIIJh0pwuJIcMXGb)

## Configuring Microsoft AutoUpdate

To configure your Microsoft AutoUpdate settings in Intune, follow these steps:

1. Sign in to the Microsoft Intune admin center.
2. Select Devices > macOS >Configuration profiles > Create profile
3. Select Settings catalog.
4. Select Create.
5. Select Next.
6. In Configuration settings, select Add settings. In the settings picker, search for "MAU" to select all the available settings.

Here is a part of what you can configure in Intune for MAU: ![MAU](/files/jziv0krHduOEbnjTlsJz)

## Best Practice

We recommend enabling the follwoing settings:

* **Automatically acknowledge data collection policy:** Suppress the Required Data Collection policy dialog from being shown to users.
* **Guard against app modification:** Retain and reuse app clones after the update cycle. This allows for future delta updates even when the source app has been modified by a third-party tool.
* **Register app on launch:** Force Office apps to register with AutoUpdate on each launch.
* **Enable AutoUpdate:** Specifies whether AutoUpdate should download and install updates. This value should be true unless you need to temporarily halt all updates.

{% hint style="info" %}
Additionally enable **Enable extended logging** to get more details and troubleshoot update issues. MAU will write verbose logging events to /Library/Logs/Microsoft/autoupdate.log
{% endhint %}

{% hint style="success" %}
You can run multiple rollout waves for Microsoft updates by using the **Deferred updates** Setting where you can set the number of days MAU should defer new updates for the Microsoft Apps. You can create multiple profiles with different assignments.
{% endhint %}

You can set a deadline for any of the following applications:

* An individual application, such as just Word.
* A group of applications, such as Word, Excel, and PowerPoint.
* All Microsoft applications that are updated by MAU.

{% hint style="info" %}
Users will receive notifications about the upcoming deadline and can temporarily postpone the updates from being installed. But once the deadline is reached, any applications the user has open will be closed and the updates applied.
{% endhint %}

More details: [Set a Deadline For Office Updates on macOS using MAU](https://www.intuneirl.com/controlling-update-behaviour-for-microsoft-applications-on-macos-using-microsoft-autoupdate/)


# What is Microsoft Auto Update (MAU)?

Learn about Microsoft Auto Update (MAU), its key features, and how to use it to keep Microsoft applications on macOS up-to-date.

Microsoft Auto Update (MAU) is a tool designed to keep Microsoft applications on macOS up-to-date with the latest security patches, bug fixes, and feature improvements. It ensures that your users have access to the most recent versions of Microsoft software, enhancing both functionality and security.

## Key Features of MAU:

1. **Automatic Updates**: MAU can be configured to automatically download and install updates for Microsoft applications.
2. **Manual Update Option**: Users can manually check for updates through the "Help" menu in any Microsoft application.
3. **Update Channels**: MAU offers different update channels, including production and insider channels for early access to new features.
4. **Deadline Setting**: MAU allows administrators to set deadlines for when updates must be installed.
5. **Flexible Configuration**: Administrators can configure MAU settings using configuration profiles, allowing for centralized management in enterprise environments.

## Advanced Features for IT Administrators:

1. **Update Deadlines**: Administrators can set deadlines for updates based on days or specific date/time.
2. **Notification System**: Users receive notifications about upcoming update deadlines, with options to postpone within limits.
3. **Grace Period**: A configurable grace period (default 60 minutes) allows users to save work before forced updates.
4. **Application-Specific Settings**: Different update settings can be applied to individual applications.


# Insights

Key insights and considerations for keeping Microsoft apps updated on macOS devices managed with Intune.


# Deploy Files on a Mac

Learn how to deploy files to macOS devices with Microsoft Intune, including the steps to follow and practical insights.

This section explains how to deploy files to managed macOS devices using Microsoft Intune, covering the deployment process and the insights to do it reliably. It is aimed at administrators who need to push configuration files, scripts, or other assets to Mac endpoints.

Follow the how-to guide and review the insights.

* [**How to deploy Files on a Mac**](/deploy-files-on-a-mac/how-to-deploy-files) — Step-by-step guide to deploying files to macOS devices with Intune.
* [**Insights**](/deploy-files-on-a-mac/insights) — Practical insights for deploying files to macOS devices.


# How to deploy Files on a Mac

Learn how to deploy files on macOS devices using Intune.

Deploying files to Intune-managed macOS devices can be challenging. This guide will walk you through the process of creating a .pkg application to securely deploy your files on macOS devices.

{% hint style="success" %}
This method is particularly useful for deploying files like fonts, Teams backgrounds, and license files.
{% endhint %}

## Why Use This Method?

There are several advantages to using a .pkg application for file deployment:

* No need to host files remotely or in the cloud
* No need for secrets in scripts
* Increased security compared to public endpoints or Azure Blob Storage

The main potential disadvantage is the initial setup time, which takes about 10 minutes, and the requirement of a macOS device for packaging.

## Creating the PKG Application

1. **Create the folder structure**
   * Organize your folders into two main directories: `Content` and `Scripts`
   * The `Content` folder will contain the files you want to deploy
   * The `Scripts` folder will contain the `postinstall` script
2. **Create the postinstall script**
   * Place the script in the `Scripts` folder
   * Make it executable with: `chmod a+x postinstall`
   * Remove any file extensions (e.g., .sh)
   * [View the full postinstall script example](https://github.com/ugurkocde/Intune/blob/main/MacOS/Create%20pkg%20/postinstall)
3. **Execute pkgbuild to create the .pkg file**
   * Run the following command in the terminal:

     ```
     pkgbuild --root Content --scripts Scripts --identifier com.yourdomain.yourapp --install-location /var/tmp --version 1.0 YourApp.pkg
     ```
   * Replace `com.yourdomain.yourapp` with your organization's identifier
   * Replace `YourApp.pkg` with the desired name for your .pkg file
4. **Upload the .pkg file to Intune**
   * Go to the Microsoft Intune portal
   * Navigate to **Apps** > **All apps** > **Create**
   * Select **macOS app (PKG)**
   * Upload your .pkg file
   * Configure the app settings as needed
   * Assign the app to your desired groups or users
5. **Deploy the app to your devices**
   * The app will be installed on the devices in the assigned groups or users
   * The files will be deployed to the specified location on the devices

{% hint style="success" %}
You can also use this method to deploy other types of files, such as scripts or configuration files.
{% endhint %}


# Insights

Insights on how to deploy files on macOS devices using Intune.

## Security

* **PKG vs. Cloud Storage**: PKGs are more secure than public cloud storage. Example: Deploying font files via PKG instead of downloading from a public URL.
* **No Exposed Secrets**: PKGs eliminate the need for credentials in scripts. Example: Avoid scripts like `curl -u username:password https://example.com/file.zip`.

## Efficiency

* **Offline Deployment**: PKGs work without internet post-download. Example: Deploying large video files that work immediately after installation.
* **Version Control**: Use version numbers in PKG names. Example: `CompanyWallpapers_v1.2.pkg`

## User Experience

* **Silent Installation**: PKGs install without user interaction. Example: Deploying license files without interrupting user workflow.

## Troubleshooting

* **Logging**: Implement detailed logging in postinstall scripts. Example:

  ```bash
  echo "$(date): Copying files to /Library/Company/" >> /var/log/company_deployment.log
  ```

## Best Practices

* **Testing**: Always test in a controlled environment first. Example: Deploy to a test group of 5-10 devices before full rollout.
* **File Organization**: Structure content logically within the PKG. Example:

  ```
  Content/
  ├── Fonts/
  ├── Wallpapers/
  └── Documents/
  ```
* **Incremental Updates**: Design PKGs to support incremental updates. Example: Update only changed files instead of re-deploying the entire package.


