Search all guides & tools⌘ / Ctrl KReader Hub
LAlite£14.99 · Buy on Gumroad ↗

macOS enrolment options

Choose by ownership, then by user.

Three routes cover most Mac deployments. This page shows who does what and where to stop if the device does not fit the route.

Fast decision map

Follow the first answer that fits.

01BYOD device enrollmentPersonally owned Mac · user initiates

Use when: the device belongs to the user, BYOD is permitted and the user needs managed access to organisation resources.

Administrator
  1. Verify the macOS version is supported.
  2. Confirm APNs is active and the user has an Intune licence.
  3. Allow personal macOS enrollment and assign only the necessary policies.
  4. Publish Company Portal and clear privacy/support wording.
User
  1. Install or open Company Portal.
  2. Sign in with the organisation account.
  3. Select Begin and download the management profile.
  4. Approve the profile in System Settings and return to Company Portal.

Privacy boundary: explain what IT can and cannot see before enrolment. Assess whether approved browser-only access meets the need; do not assume mobile app-protection features also apply to macOS.

02Automated Device Enrollment (ADE)Organisation-owned · scalable and supervised

Use when: the Mac is owned by the school or organisation, purchased through Apple or a linked reseller, and should enrol during Setup Assistant.

Administrator
  1. Connect Apple School or Business Manager to Intune.
  2. Assign the Mac serial to the Intune MDM server.
  3. Sync the enrolment-program token.
  4. Create the current ADE enrollment policy, choose user affinity deliberately and assign it before power-on.
  5. Pilot the real Setup Assistant experience.
User
  1. Unbox or start the erased Mac.
  2. Connect to a permitted network.
  3. Follow Setup Assistant and organisation sign-in prompts.
  4. Wait for required policies and first-day applications.
  5. Contact support if Remote Management does not appear.

Portal route: Devices → Device onboarding → Enrollment → macOS → Enrollment program tokens → select the token → Enrollment policies → Create policy → macOS. Older deployments may still show Profiles; use Microsoft’s current policy workflow for a new deployment.

The Apple MDM push certificate, ADE server token and Apps and Books token serve different purposes. Configure the certificate and ADE connection first; record renewal ownership. For a named user, select user affinity and Setup Assistant with modern authentication. Complete Company Portal registration unless using the specifically configured Platform SSO during ADE route.

Verify: match the serial in Apple School Manager and Intune, then check management, policy delivery and the intended user. Configure Entra ID and Platform SSO separately.

Use a new or authorised erased pilot: do not erase an existing working Mac simply to follow this walkthrough.

Stop if no policy is assigned: Microsoft warns that an ADE device can fail enrollment if it becomes active before an enrollment policy is assigned. Set a default policy where appropriate and verify the serial before handover.

03Direct enrollmentOrganisation-owned · user-less or shared

Use when: the Mac is organisation-owned, should have no user affinity, and a hands-on Apple Configurator route is appropriate. Typical examples include kiosks, shared stations and dedicated-purpose devices.

Administrator
  1. Verify support, APNs and the intended user-less design.
  2. Create the Apple Configurator enrollment policy without user affinity.
  3. Export the profile and enrol the Mac with physical access.
  4. Assign device-targeted configuration and applications.
  5. Document who owns local access and recovery.
Device user
  1. No Company Portal sign-in is expected for a user-less design.
  2. Use only the supplied shared or dedicated workflow.
  3. Report missing applications or restrictions to support.
  4. Do not add a personal or organisation account unless the design requires it.

Important: direct enrollment is not the normal choice for a Mac that needs a named primary user. Use ADE with user affinity for that design.

Administrator pre-flight

Check these before handing over a Mac.

  1. 1

    Supported device and OSThe platform is supported by the current Intune requirements.

  2. 2

    Apple MDM push certificateAPNs is active and renewal ownership is recorded.

  3. 3

    Policy assignedThe correct enrollment and configuration policies target the pilot user or device.

  4. 4

    Network path worksRequired Apple and Microsoft endpoints are reachable without broken TLS inspection.

  5. 5

    Evidence recordedSerial, ownership, assigned profile, user affinity and last check-in match the intended design.

User walkthrough

Chosen Company Portal?

Open the screenshot-led guide →Open the full Mac deployment guide →

Search LAlite

A guide, a scenario or a checklist. Find it here.