- Verify the macOS version is supported.
- Confirm APNs is active and the user has an Intune licence.
- Allow personal macOS enrollment and assign only the necessary policies.
- Publish Company Portal and clear privacy/support wording.
macOS enrolment options
Choose by ownership, then by user.
Three routes cover most Mac deployments. This page shows who does what and where to stop if the device does not fit the route.
Fast decision map
Follow the first answer that fits.
Yes → use approved BYOD device enrollment with Company Portal.
Yes → use Automated Device Enrollment with user affinity where possible.
Use ADE without user affinity or direct enrollment where that route meets the requirement.
Administrator pre-flight
Check these before handing over a Mac.
- 1
Supported device and OSThe platform is supported by the current Intune requirements.
- 2
Apple MDM push certificateAPNs is active and renewal ownership is recorded.
- 3
Policy assignedThe correct enrollment and configuration policies target the pilot user or device.
- 4
Network path worksRequired Apple and Microsoft endpoints are reachable without broken TLS inspection.
- 5
Evidence recordedSerial, ownership, assigned profile, user affinity and last check-in match the intended design.
User walkthrough
