Enroll macOS in Intune: A Step-by-Step Guide for Beginners (2024)

This guide demonstrates the steps to enroll macOS in Intune. Microsoft Intune supports enrollment on personal and company-owned devices.We will enroll macOS devices into Microsoft Intune using the Company Portal app to gain secure access to organization’s email, files, and apps.

When you enroll your macOS device in Intune, it is called a managed device. Intune can manage macOS devices efficiently provided they fall under supported devices list. Your organization can assign policies and apps to macOS devices using an MDM solution such as Intune.

This article describes how to use the Company Portal app for macOS to set up and maintain your device so that you meet your organization’s requirements. Like Windows devices, the company portal app can be installed on your macOS and you can enroll macOS into Intune.

Refer to these useful guides related to device enrollment in Intune:

  • Enroll iOS iPadOS devices in Microsoft Intune
  • Configure Intune Device Enrollment Restrictions
  • Enroll Windows 11 Devices in Intune with 2 Easy Methods
  • Enroll Windows 10 devices in Intune
  • Enroll HoloLens 2 Device for Autopilot Deployment

What happens after you enroll macOS devices in Intune?

Before you enroll your macOS devices into Intune, let’s understand about the benefits that you get. When you enroll macOS in Intune, you give your IT support permission to manage your device to help protect the company information on the device. When your Mac device is enrolled, your company support can:

  • Reset your device back to manufacturer’s default settings if the device is lost or stolen.
  • Remove all installed company-related data and business apps. Your personal data and settings aren’t removed.
  • Require you to have a password or PIN on the device.
  • Require you to accept terms and conditions.
  • Disable the camera on your device to prevent you from taking pictures of sensitive company data.
  • Enable or disable web browsing on your device.
  • Enable or disable backup, document sync, Photo Stream to iCloud.
  • Enable or disable data roaming on your device. If data roaming is allowed, you might incur roaming charges.
  • Enable or disable voice roaming on your device. If voice roaming is allowed, you might incur roaming charges.
  • Enable or disable automatic file synchronization while in roaming mode on your device. If automatic file synchronization is allowed, you might incur roaming charges.

Prerequisites for enrolling macOS devices in Intune

To enroll macOS in Intune, following are the prerequisites:

  • Intune now supports macOS 10.15 and later. Review the Intune Monthly updates for more information.
  • You must download and install Company Portal app for macOS before enrollment.
  • Intune company portal can only be installed on macOS version 11 or later.
  • To log in to the company portal, you’ll need a user account with an Intune license.
  • Maintain an internet connection until all steps are complete.
  • Have access to Safari web browser on your device.

Steps to Enrolling macOS Devices in Intune

The procedure to enroll macOS in Intune includes a series of steps that needs to be followed. After the successful enrollment of macOS, you can apply policies and configuration profile from Intune Portal.

The following high-level steps are involved in enrolling macOS devices into Intune.

  1. Check the prerequisites and ensure you are using supported macOS devices for enrollment.
  2. Apple MDM Push certificate configuration: Involves downloading the Intune certificate signing request and creating a new push certificate. Later, upload this push certificate in Intune portal.
  3. Install the Company Portal app on an macOS device and authenticate.
  4. Set up macOS devices to access your company resources.
  5. Manage macOS devices from Intune Portal.

Note: If you have already created the Apple MDM push certificate during the enrollment of iOS devices in Intune, you can proceed with the next steps.

Step 1: Set up Apple MDM Push Certificate

An Apple MDM Push certificate is required to manage macOS devices in Microsoft Intune. You can configure Apple MDM push certificate with following steps:

Enroll macOS in Intune: A Step-by-Step Guide for Beginners (1)

On the Configure MDM Push Certificate window, select I agree to give Microsoft permission to send data to Apple. This is a mandatory step.

Enroll macOS in Intune: A Step-by-Step Guide for Beginners (2)

Step 2: Download the Intune Certificate Signing request

In this step, you have to download the Intune certificate signing request required to create an Apple MDM push certificate. Select Download your CSR to download and save the request file locally. Refer to the above screenshot for more details.

Shortly, the IntuneCSR.csr file will be downloaded and saved to the default location on your computer. We will need this file to request a trust relationship certificate from the Apple Push Certificates Portal.

Enroll macOS in Intune: A Step-by-Step Guide for Beginners (3)

Step 3. Create an Apple MDM Push Certificate

On the Configure MDM Push Certificate window, click Create your MDM push certificate. This is required to enroll macOS in Intune. A new link opens in your default browser and takes you to the Apple Push Certificates Portal. You must sign in with your company email address Apple ID, and then click Create a Certificate.

Enroll macOS in Intune: A Step-by-Step Guide for Beginners (4)

On the Terms of Use page, click Accept.

Enroll macOS in Intune: A Step-by-Step Guide for Beginners (5)

On the Create a new MDM Push Certificate page, select Choose File and browse to the Intune certificate signing request file (IntuneCSR.csr), and then choose Upload.

Enroll macOS in Intune: A Step-by-Step Guide for Beginners (6)

On the Confirmation page, select Download to download the certificate (.pem) file, and save the file locally. The Apple MDM push certificate file is saved with following name MDM_ Microsoft Corporation_Certificate.pem.

Enroll macOS in Intune: A Step-by-Step Guide for Beginners (7)

Step 4. Upload Apple MDM Push Certificate in Intune Portal

In step, you have two things that you need to configure:

  1. Enter the Apple ID used to create your Apple MDM push certificate.
  2. Upload the Apple MDM Push certificate by clicking Browse icon and upload the MDM_ Microsoft Corporation_Certificate.pem file to Intune. By successfully uploading the Apple MDM push certificate, Intune can enroll and manage macOS devices.
Enroll macOS in Intune: A Step-by-Step Guide for Beginners (8)

We see another notification confirming that your MDM push certificate was successfully created.

Enroll macOS in Intune: A Step-by-Step Guide for Beginners (9)

After you configure Apple MDM push certificate, the bulk enrollment methods are activated in Intune portal. The Apple bulk enrollment methods include:

  1. Apple configurator
  2. Enrollment Program Tokens

We also see the enrollment options that allow you to manage user enrollment and device enrollment options for iOS and iPadOS devices.

Enroll macOS in Intune: A Step-by-Step Guide for Beginners (10)

Step 5: Install Intune Company Portal App for Mac Enrollment

When you enroll iOS/iPadOS device in Intune, you get to install the company portal app via App Store. However, for macOS, you will not find the company portal app on App Store. You have to download the app using the browser and manually run the installer.

To download the company portal for macOS, go to enroll my Mac and download the installer. The Company Portal installer .pkg file will download. Open the installer and continue through the steps. On the Introduction page, click Continue.

Enroll macOS in Intune: A Step-by-Step Guide for Beginners (11)

Accept the application license terms by clicking on Continue.

Enroll macOS in Intune: A Step-by-Step Guide for Beginners (12)

Click Agree to continue to next step.

Enroll macOS in Intune: A Step-by-Step Guide for Beginners (13)

On the Destination Select page, click Continue.

Enroll macOS in Intune: A Step-by-Step Guide for Beginners (14)

Leave the install location to default and click Install.

Enroll macOS in Intune: A Step-by-Step Guide for Beginners (15)

The company portal application is now installed on the macOS successfully. Click Close.

Enroll macOS in Intune: A Step-by-Step Guide for Beginners (16)

Step 6: Enroll macOS in Intune using Company Portal App

Launch the company portal app by pressing the keys Command + Spacebar which opens the Spotlight search. Type “Company Portal” and select the company portal app to launch it. Once the app launches, you will see the screen with the option to Sign in. Click on Sign in.

Enroll macOS in Intune: A Step-by-Step Guide for Beginners (17)

Enter the credentials of the account that has been assigned with an Intune license. This is typically the work account email address. Click Next.

On the next screen, enter the password for the account and complete the authentication.

Enroll macOS in Intune: A Step-by-Step Guide for Beginners (18)

Once you have authenticated successfully, you see the Setup Portal Access screen. Click Begin to set up your device to access your email, devices, Wi-Fi, and apps for work.

Enroll macOS in Intune: A Step-by-Step Guide for Beginners (19)

On the Review Privacy Information screen, you can find out what you can organization can access and what it can’t. Go through this information if you haven’t seen this earlier and click Continue.

Enroll macOS in Intune: A Step-by-Step Guide for Beginners (20)

In this step, you download and install the management profile. On theInstall management profilescreen, selectDownload profile.

Enroll macOS in Intune: A Step-by-Step Guide for Beginners (21)

Your device’s system preferences will open. Select Install and then select Install again. If you’re prompted to, enter your device password.

Enroll macOS in Intune: A Step-by-Step Guide for Beginners (22)

When asked Are you sure you want to install profile “Management Profile”?, select Install.

Enroll macOS in Intune: A Step-by-Step Guide for Beginners (23)

The management profile is installed now. You’ll notice that Management profile status now shows as “Verified” and there are four settings installed by management profile.

Enroll macOS in Intune: A Step-by-Step Guide for Beginners (24)

Once you have successfully enrolled your Mac into Intune, you will see the below screen. You should now have access to your email, devices, Wi-Fi, and apps for work. Click Done.

Enroll macOS in Intune: A Step-by-Step Guide for Beginners (25)

You can now re-launch the company portal to view more details about your device, apps, and support details for your organization. You can configure these details by reading the guide on Intune company portal branding.

The company portal app on your Mac shows three tabs: Devices, Apps and Support. The Devices tab shows the device name, manufacturer name, model and operating system.

Enroll macOS in Intune: A Step-by-Step Guide for Beginners (26)

The Support tab shows the contact email and website details configured by your organization.

Enroll macOS in Intune: A Step-by-Step Guide for Beginners (27)

Check macOS Enrollment Status in Intune Portal

Once you have enrolled the macOS devices into Intune, you can verify the enrollment from the Intune Portal. To accomplish that, sign in to the Intune Portal. Navigate to Devices > macOS > macOS Devices. Here you can find all the macOS devices that are enrolled into Intune.

Enroll macOS in Intune: A Step-by-Step Guide for Beginners (28)
Enroll macOS in Intune: A Step-by-Step Guide for Beginners (2024)

FAQs

Enroll macOS in Intune: A Step-by-Step Guide for Beginners? ›

To create an enrollment profile, click the Add button at the bottom of the Profile Manager sidebar, then choose Enrollment Profile from the pop-up menu. To restrict the use of the enrollment profile to devices for which you entered a placeholder record, turn on “Restrict use to devices with placeholders.”

How do I create an enrollment profile on my Mac? ›

To create an enrollment profile, click the Add button at the bottom of the Profile Manager sidebar, then choose Enrollment Profile from the pop-up menu. To restrict the use of the enrollment profile to devices for which you entered a placeholder record, turn on “Restrict use to devices with placeholders.”

How do I manually Enrol a device in Intune? ›

3. Enrolling a device in Microsoft Intune
  1. Right-click on Windows > Settings > Accounts.
  2. Access Work or School Account and then click Connect.
  3. Click on Join this device to Azure AD Directory and add DEM user credentials and click on Next and Sign In.
  4. Click on Join and then click on Done.
Oct 31, 2022

Can you join Mac to Intune? ›

Enroll your macOS device with the Intune Company Portal app to gain secure access to your work or school email, files, and apps. Organizations typically require you to enroll your device before you can access proprietary data. After your device is enrolled, it becomes managed.

How to setup MDM macOS? ›

Enrolling your macOS device (MDM)
  1. Provide your credentials (either a one-time passcode that is provided by your organization or your user name and password). ...
  2. Accept the terms and conditions, and then click Continue.
  3. Click Install to install the MDM profile on the device. ...
  4. Follow these steps to enroll the device:

What are the top 3 best practices when implementing Intune? ›

7 Microsoft Intune Best Practices
  • Simplify access management by using Azure AD groups. ...
  • Apply Mobile Application Management (MAM) regulations to apps. ...
  • Leverage the Intune Company Portal mobile app. ...
  • Bring Microsoft Defender ATP into use. ...
  • keep track of performance using reports. ...
  • Set up conditional access.
Apr 13, 2023

What is the difference between Intune and Endpoint Manager? ›

Account editing: Microsoft Intune does not allow administrators to edit user accounts in the program's interface. Endpoint Manager allows users to manage accounts across its suite from its admin center.

What are the requirements for Intune management? ›

Intune requires Android 8. x or higher for device enrollment scenarios and app configuration delivered through Managed devices app configuration policies. This requirement does not apply to Microsoft Teams Android devices as these devices will continue to be supported.

How do I automatically enroll my Mac in Intune? ›

In the Microsoft Intune admin center, go to Devices > macOS > macOS enrollment. Select Enrollment program tokens. Select Add. Select I agree to grant permission to Microsoft to send user and device information to Apple.

What type of enrollment is Intune macOS? ›

All Mac enrollments in Intune are considered user-approved. User-approved enrollment lets you manage macOS devices that aren't part of Apple School Manager or Apple Business Manager. It provides the same level of control as supervised macOS devices enrolled using Automated Device Enrollment or Apple Configurator.

How to install MDM profile on Mac? ›

Locate the mail message or website that contains the configuration profile, and download it to your Mac. Your Mac should recognize the file and go to System Preferences > Profiles for you. Click Show Profile to view the profile, or click Continue to install the profile.

Do you need an Intune license to enroll a device? ›

Whether you manually add users or synchronize from your on-premises Active Directory, you must first assign each user an Intune Plan 1 license before users can enroll their devices in Intune.

How do I Enrol a device in MDM? ›

Enroll in device management only
  1. Launch the Settings app.
  2. Next, navigate to Accounts.
  3. Navigate to Access work or school.
  4. Select the Enroll only in device management link.
  5. Type in your work email address.
Apr 21, 2023

How do I know if my device is enrolled in Intune? ›

How to Confirm a Device Is Enrolled in Intune
  1. Click Start on your Windows device.
  2. Click on Settings.
  3. Click Accounts.
  4. Click Access work or school.
  5. Click Connected to MESA AD domain then click Info. Note: If the Info button does not appear on your device, your device has not been successfully enrolled.
Mar 2, 2021

Can you add a Mac device to Microsoft account? ›

Add a device to your Microsoft account

Download Microsoft Edge from the Apple App Store and sign in with your Microsoft account. Go to account.microsoft.com/devices, select Register device, then follow the instructions.

How do I join a Mac device to a domain? ›

Bind using Directory Utility
  1. In the Directory Utility app on your Mac, click Services.
  2. Click the lock icon.
  3. Enter an administrator's username and password, then click Modify Configuration (or use Touch ID).
  4. Select Active Directory, then click the “Edit settings for the selected service” button .

How do I join a Mac? ›

Using Mac's Built-In Apple Directory Utility
  1. Navigate through System Preferences > User & Groups.
  2. Click the lock icon and provide your user password.
  3. Click Login Options (Figure 1).
  4. Next to Network Account Server, click Join (Figure 1).
Mar 4, 2022

How do I enroll without user affinity in Intune Mac? ›

In the Intune admin center, create an enrollment profile. Select Enroll without user affinity (user-less devices or shared devices). With user-less devices: Users can't use apps that require a user, including the Company Portal app.

What is device enrollment on Mac? ›

The Device Enrollment Program (DEP) helps businesses easily deploy and configure Apple devices. DEP provides a fast, streamlined way to deploy organization-owned iPad and iPhone devices, Mac computers, and Apple TV purchased directly from Apple or participating Apple Authorized Resellers or carriers.

How do I register my Mac with Azure? ›

Creating a Policy Directing Users to Register Mac Computers with Azure Active Directory
  1. In Jamf Pro, click Computers at the top of the sidebar.
  2. Click Policies in the sidebar.
  3. Create a new policy requiring users to register their Mac computer with Azure AD.
  4. Use the General payload to specify policy settings.

What are the five phases in the Microsoft Intune application lifecycle? ›

By understanding these phases, you'll have the details you need to get started with app management in Intune.
  • Add. The first step in app deployment is to add the apps, which you want to manage and assign, to Intune. ...
  • Deploy. ...
  • Configure. ...
  • Protect. ...
  • Retire. ...
  • Next steps.
Mar 6, 2023

How many policies are there in Intune? ›

There are two parts to compliance policies in Intune: Compliance policy settings – Tenant-wide settings that are like a built-in compliance policy that every device receives.

What are the disadvantages of using Microsoft Intune? ›

  • Intune CONS :
  • * Narrow focus on mobile devices; not a full systems-management platform.
  • * Doesn't support server-side applications.
  • * Not intended for large applications.
  • * Doesn't have the feature-set to handle complex package deployments.

Is Intune now called Microsoft Endpoint Manager? ›

Microsoft Intune is our cloud-based unified endpoint management solution and has become a market leader – managing endpoints across Windows, Android, Mac, iOS, and now Linux operating systems.

What is the new name for Endpoint Configuration Manager? ›

Microsoft Intune new name. Effective October 12, 2022, Microsoft Intune becomes the name of the endpoint management family with the name Microsoft Endpoint Manager no longer being used.

Is SCCM and Intune the same? ›

Microsoft Intune is solely a cloud technology by Office 365. It is also known as cloud variant of SCCM, but it is NOT equivalent to SCCM. When it comes to Intune vs SCCM, SCCM is a much more powerful tool than Intune as a service for business users.

What is the minimum macOS for Intune? ›

Requires macOS 10.15 and newer. Network volumes: Your options: Not configured: Intune doesn't change or update this setting.

What licenses are needed for Intune? ›

View our list below to see what Microsoft licenses include Intune.
  • Microsoft 365 E5 - $57/user/month.
  • Microsoft 365 E3 - $32/user/month.
  • Enterprise Mobility + Security E5 - $16.40/user/month.
  • Enterprise Mobility + Security E3 - $10.60/user/month.
  • Microsoft 365 Business Premium - $20/user/month.
Jun 14, 2023

Do you need a server for Intune? ›

As a cloud-only service, Intune doesn't require an on-premises infrastructure such as servers or gateways.

How to deploy any application to macOS device using Intune? ›

Select the app package file
  1. In the Add app pane, click Select app package file.
  2. In the App package file pane, select the browse button. Then, select an macOS installation file with the extension . pkg. The app details will be displayed.
  3. When you're finished, select OK on the App package file pane to add the app.
May 1, 2023

What are the device features of Intune macOS? ›

Intune includes built-in settings to customize features on your macOS devices. For example, administrators can add AirPrint printers, choose how users sign in, configure the power controls, use single sign-on authentication, and more.

How do I approve MDM on Mac? ›

Approving the MDM Profile

From the Apple menu, launch 'System Preferences'. Click on 'Profiles'. Select the 'MDM Profile' and press 'Approve' (or 'Install' on newer operating systems).

Where is macOS script in Intune? ›

Sign in to the Microsoft Intune admin center. Navigate to Devices > Scripts and select a macOS shell script.

Is my Mac enrolled in MDM? ›

How Do I Know If My Mac Has MDM? It's easy to check whether your Mac has an MDM. Simply go to “System Preferences”. If you don't see a section as “Profiles” or “Profiles & Device Management”, then you don't have any MDM on your Mac.

What is the difference between user enrollment and device enrollment Intune? ›

Select this option only when the corporate data on the devices in the profile should be managed. Device Enrollment. Select this option when the devices in the profile should be fully managed.

Where are MDM Profiles on macOS? ›

Open System Preferences on your mac by clicking on the Apple icon in the top left corner and selecting "System Preferences..." from the drop-down list. Find the Profiles icon and click on it. Find "MDM Profile" in the list on the left and click on it.

Can you have two MDM on Mac? ›

Apple also restricts multiple MDM profiles on a device. Therefore, you can't install one MDM profile on top of another. When you migrate macOS devices to a new MDM, you'll need to send a command from the original MDM to remove the management profile from devices.

How does MDM work on Mac? ›

MDM lets you securely and wirelessly configure devices by sending profiles and commands to the device, whether they're owned by the user or your organization. MDM capabilities include updating software and device settings, monitoring compliance with organizational policies, and remotely wiping or locking devices.

What happens when a device is enrolled in Intune? ›

During device enrollment: Your device enrolls in Microsoft Intune, a mobile device management provider, and registers with your organization. This step ensures that you're authorized to access your organization's email, apps, and Wi-Fi. Your organization's device management policies are applied to your device.

How do I manually enroll devices into Intune? ›

Use Intune Company Portal to enroll devices running on Windows 10, version 1607 and later, and Windows 11.
  1. Open Company Portal and sign in with your work or school account.
  2. On the Set up your device screen, select Next.
  3. On the Connect to work screen, select Connect.
Feb 28, 2023

What is the process of enrolling a device into the system? ›

Enroll device

Enter the username and password for your work account. If you followed the create a user and assign a license evaluation step, you can use the user account that you created. Wait for your device to finish registering. When you see the You're all set!

How do I enroll my company owned device in Intune? ›

Sign in to the Microsoft Intune admin center and choose Devices > Android > Android enrollment > Corporate-owned devices with work profile. Choose Create profile and fill out the fields. Name: Type a name that you'll use when assigning the profile to the dynamic device group.

How long does it take for a device to enroll in Intune? ›

How long does the Intune Enrollment process take? We ask for your time and patience as the enrollment process can take up to 30 minutes.

Who can add devices to Intune? ›

A device enrollment manager (DEM) is a non-administrator user who can enroll devices in Intune. Device enrollment managers are useful to have when you need to enroll and prepare many devices for distribution.

What happens if you install the Company Portal app and enroll your device in Intune? ›

By enrolling your device in Intune, you get secure access to work or school apps on your mobile device, and access to apps in Intune Company Portal.

Can we deploy OS using Intune? ›

Self-Deploying mode then automatically joins your devices with your company's Azure AD tenant, which can perform MDM enrolment using Microsoft Intune and deploy your pre-set applications, certificates, policies and profiles without any need for additional IT input.

Which operating system does Intune manage? ›

Android. Intune requires Android 8.

What devices can be managed by Intune? ›

Microsoft Intune supports Android, Android Open Source Project (AOSP), iOS/iPadOS, macOS, and Windows client devices. With Intune, you can use these devices to securely access organization resources with policies you create.

Does MDM work on Mac? ›

iOS, iPadOS, macOS, and tvOS have a built-in framework that supports mobile device management (MDM). MDM lets you securely and wirelessly configure devices by sending profiles and commands to the device, whether they're owned by the user or your organization.

How do I add macOS to Intune? ›

Complete these steps first to enable enrollment in your Microsoft Intune tenant.
  1. Verify that devices are eligible for Apple device enrollment.
  2. Configure domains.
  3. Set the MDM Authority.
  4. Get an Apple MDM push certificate.
  5. Assign user licenses in the Microsoft 365 admin center.
  6. Create groups.
  7. Configure the Company Portal app.
Mar 7, 2023

What is the minimum OS version for Intune? ›

Set Minimum OS Version for Win32 Apps Deployment from Intune
RequirementsOS Version
Minimum operating systemWindows 11 21H2
Apr 3, 2023

What iOS version is needed for Intune? ›

All new Apple devices will also require a minimum of iOS/iPadOS version 14 or higher to successfully enrol to Intune. Local Administrators can view the OS version of all devices from the “Devices” section of the Intune Admin Console.

How many devices can be enrolled in Intune? ›

Intune device limit restrictions

You can allow a user to enroll up to 15 devices.

How does Intune enrollment work? ›

During enrollment, Intune installs an MDM certificate on the enrolling device. The MDM certificate communicates with the Intune service, and enables Intune to start enforcing your organization's policies, such as: Enrollment policies that limit the number or type of devices someone can enroll.

Which device will not delete from Intune? ›

Remove in device Settings app

Open the Settings app. Go to Accounts > Access work or school. Select the connected account that you want to remove > Disconnect. To confirm device removal, select Yes.

Where is the MDM key to activate Mac? ›

On a Mac, the bypass code can be entered by clicking Recovery Assistant in the menu bar and selecting the “Activate with MDM key” option.

Top Articles
Latest Posts
Article information

Author: Chrissy Homenick

Last Updated:

Views: 5710

Rating: 4.3 / 5 (74 voted)

Reviews: 81% of readers found this page helpful

Author information

Name: Chrissy Homenick

Birthday: 2001-10-22

Address: 611 Kuhn Oval, Feltonbury, NY 02783-3818

Phone: +96619177651654

Job: Mining Representative

Hobby: amateur radio, Sculling, Knife making, Gardening, Watching movies, Gunsmithing, Video gaming

Introduction: My name is Chrissy Homenick, I am a tender, funny, determined, tender, glorious, fancy, enthusiastic person who loves writing and wants to share my knowledge and understanding with you.