Search all guides & tools⌘ / Ctrl KReader Hub
LAlite£14.99 · Buy on Gumroad ↗

Deployment guide · macOS + Microsoft Intune

Manage Macs without needing to be a Microsoft expert first.

One novice route from accounts and Apple trust to enrolment, compliance, settings, security, sign-in, apps and remote support.

Microsoft guidance reviewed · 31 August 2026

Before you touch a production Mac

Prepare four foundations.

Build these with a pilot administrator and test group. Use least privilege and keep an emergency-access route outside Conditional Access policies.

  1. 1

    Users, groups and licences

    Create a small Entra pilot group, add test users and devices, and assign a licence that includes Intune. Keep production users out until the pilot passes.

  2. 2

    MDM authority

    Verify Microsoft Intune is the mobile-device-management authority for the tenant. If another authority or migration is involved, stop and follow the documented migration route.

  3. 3

    Apple MDM push certificate

    Create the APNs certificate using an organisation-owned Apple account. Record the Apple ID and renewal owner; renew the same certificate before it expires.

  4. 4

    Apple organisation connection

    For school-owned Macs, connect Apple School Manager or Apple Business Manager, upload the Intune public key, and create an Automated Device Enrollment token.

The complete route

Build trust first. Add controls in layers.

01

Deployment planning

Write the outcome before building the policy.

Decide who owns each Mac, who signs in, what must work on day one, what proves the device is healthy, and who supports it when the first deployment fails.

People

Named user, shared device or lab? Standard user or approved local administrator? Which support team owns identity, network, apps and Apple services?

Device

Apple silicon and supported macOS version? Purchased through a linked channel? Existing device that can be erased, or personal BYOD?

Access

Which services require Conditional Access, certificates, Wi-Fi, VPN, Platform SSO or Microsoft 365 on first sign-in?

Recovery

Who can approve a wipe, retrieve FileVault keys, rotate Recovery Lock, renew APNs and release a device from Apple ownership?

A controlled first pilot

Use 5–10 representative Macs, at least two hardware models, one standard user, one IT administrator and the real network path. Test new setup, restart, offline sign-in, app install, update, FileVault recovery, noncompliance, remote action and a clean handover.

Portal path

Microsoft Intune admin center → Devices → Overview; Microsoft Entra admin center → Groups

First safe configuration

Create named pilot user and device groups with no broad production assignment.

Verify

A test user can sign in and the pilot group membership is deliberate and documented.

Common trap

Assigning every policy to All users or All devices before dependencies and exclusions are understood.

02

Device enrolment

Choose enrolment by ownership and use.

Automated Device Enrollment (ADE) is the normal route for new or erased school-owned Macs purchased through Apple or a participating reseller. Company Portal is the self-service route Microsoft documents for personal Macs. Direct enrollment is a no-user-affinity option that needs physical access.

ADE in plain language

  1. Link the purchase channel to Apple School or Business Manager.
  2. Assign the Mac to the Intune MDM server in Apple’s portal.
  3. Synchronise the enrollment-program token in Intune.
  4. Create an ADE profile: user affinity for 1:1 use; no user affinity for truly shared use.
  5. Use modern authentication and decide which Setup Assistant screens users should see.
  6. Assign only to the pilot device group, erase the test Mac, and complete Setup Assistant.
  7. Verify supervision, ownership, primary user, bootstrap-token escrow and last check-in.
Portal path

Intune → Devices → Enrollment → Apple → Enrollment program tokens

First safe configuration

Create one clearly named ADE profile and assign it only to pilot Macs.

Verify

The serial appears under the token, the profile is assigned, and the Mac enrols during Setup Assistant.

Common trap

Expecting a Mac already in use to become supervised through ADE without erase and reactivation.

03

Compliance rules

Measure health before blocking access.

Compliance reports whether a Mac meets the standard. Conditional Access decides what that status means for sign-in. Keep those two layers separate, and prove reporting before enforcement.

Measure

Compliance policy

Start with supported macOS version, password requirements, encryption and threat level only where the required integration exists.

Respond

Actions for noncompliance

Use a grace period and notification that tells the user what failed and where to get help.

Enforce

Conditional Access

Pilot “require compliant device” with exclusions, emergency-access accounts and sign-in log review.

Portal path

Intune → Devices → Compliance → Policies → Create policy → macOS

First safe configuration

Create a small baseline, add a useful noncompliance message and assign it to the pilot group.

Verify

The per-setting report names the exact passing or failing control on each test Mac.

Common trap

Turning on Conditional Access before the Mac has checked in, calculated compliance and received Company Portal.

04

Device settings

Prefer small Settings Catalog profiles.

Microsoft recommends the Settings Catalog for new Apple policies where possible. Split profiles by purpose so a conflict can be traced to one owner and one change.

Identity

Platform SSO, login window and account settings

Network

Wi-Fi, VPN, proxies and certificates

Restrictions

Cloud services, sharing, media and user controls

Updates

DDM target version, deadlines and deferrals

Privacy

PPPC and system-extension approvals for known apps

Experience

Dock, browser and organisation settings only where supportable

Current update direction

Apple deprecated the older MDM software-update workload with macOS 26. Microsoft now recommends Apple Declarative Device Management update policies. Build new update controls with DDM, pilot deadlines and test restart behaviour.

Portal path

Intune → Devices → Manage devices → Configuration → Create → New policy → macOS → Settings catalog

First safe configuration

Create one profile per purpose, use a clear prefix such as macOS – Pilot – Wi-Fi, and assign it to the pilot group.

Verify

Device configuration reports show Succeeded, and the setting is present after a device sync and restart where required.

Common trap

Configuring the same payload in Settings Catalog, a template and a custom profile, creating conflicts with no clear owner.

05

Endpoint security

Secure the Mac and preserve recovery.

Start with FileVault, firewall and a supported endpoint-protection design. Add Recovery Lock and local-administrator password management only after ownership and recovery roles are defined.

1

Encrypt

Deploy FileVault and confirm the personal recovery key is escrowed before declaring success.

2

Protect

Configure firewall and Defender for Endpoint where licensed; grant required system extensions and privacy permissions through managed profiles.

3

Recover

Test authorised FileVault key access. For supported macOS versions, use Intune LAPS for a managed local administrator and Recovery Lock to protect startup options.

Portal path

Intune → Endpoint security → Disk encryption → Create policy → macOS

First safe configuration

Require FileVault for pilot devices and escrow the recovery key; document the help-desk verification process.

Verify

The encryption report shows the Mac encrypted and its key available to an authorised role.

Common trap

Enabling encryption without confirming who can retrieve a recovery key, or assuming an already-encrypted Mac has escrowed its key.

06

Authentication methods

Join device sign-in to cloud identity carefully.

Require MFA for administrative access and use Conditional Access for cloud resources. Platform SSO can connect the local Mac account with Microsoft Entra credentials, but it needs Company Portal, an SSO extension profile and a tested registration experience.

  • Do pilot with a standard user, offline sign-in and password-change scenarios.
  • Do use certificate profiles for Wi-Fi or VPN only after the certificate connector and renewal path are tested.
  • Do not remove the tested local recovery route before Platform SSO registration is proven.
  • Do not assume Platform SSO alone makes a Mac compliant; compliance and access remain separate policies.
Portal path

Intune → Devices → Manage devices → Configuration → Settings catalog → Authentication → Extensible Single Sign On

First safe configuration

Deploy the current Company Portal as required, then a Platform SSO profile to the pilot group.

Verify

Company Portal shows registration complete; password change, restart, lock, offline sign-in and token refresh all work.

Common trap

Deploying the SSO extension before Company Portal and required permissions, or changing the authentication method mid-pilot.

07

App deployment

Separate first-day apps from everything else.

Deploy Company Portal to Macs with user affinity, then deliver Microsoft 365 and a short first-day set. Use Apple Apps and Books for store apps and a supported Intune macOS app type for signed line-of-business software.

Required

Needed before work begins

Company Portal, identity or security agents, certificates and only the essential productivity apps.

Available

User chooses later

Optional curriculum, departmental and specialist apps shown through Company Portal.

Update owner

Know who keeps it current

Microsoft AutoUpdate, App Store/Apps and Books, vendor updater or a superseding Intune package—never an undocumented mixture.

macOS 26 and newer

Intune supports Declarative Device Management for required Apple volume-purchased apps on supported Apple OS versions. Check the Intune “What’s new” page before changing a production app-delivery design.

Portal path

Intune → Apps → All apps → Create

First safe configuration

Make Company Portal required for the pilot user group, then add Microsoft 365 using Intune’s built-in macOS app type.

Verify

Each app reports Installed, launches under a standard user, updates correctly and has a tested uninstall or supersedence route.

Common trap

Marking every application as required, mixing user and device assignments without intent, or packaging unsigned software that needs interactive approval.

08

Remote actions

Use the least destructive action that proves the next fact.

For an enrolled, online Mac, Intune can expose actions such as Sync, Restart, Rename, Remote lock, Retire, Wipe, Delete, FileVault key rotation and Recovery Lock rotation. Availability depends on enrolment and configuration.

Low impactSync → Restart → Rename

Use to deliver policy, clear a pending restart or correct inventory. Verify the action status and last check-in.

Security responseRemote lock → rotate keys

Confirm device identity, ownership and the authorised recovery route before acting.

DestructiveRetire / Wipe / Delete

Use approved change control. Retire, Wipe and Delete can take precedence over other pending actions; a server-side completion does not always prove the Mac received it.

Portal path

Intune → Devices → All devices → select the Mac → device action

First safe configuration

Test Sync and Restart on a pilot Mac; record how the action appears in Devices → Device actions.

Verify

The action status, Mac behaviour and updated last-check-in time agree.

Common trap

Deleting the device object while it is offline and assuming that proves organisational data was removed from the Mac.

+

Evidence-led troubleshooting

Locate the failed layer before erasing the Mac.

SymptomFirst layer to inspectEvidence to capture
Mac never receives the ADE profileApple assignment and Intune token syncSerial number, Apple portal MDM assignment, token sync time and assigned profile.
Company Portal enrolment failsAccount, licence, APNs, restriction and Conditional AccessExact message, user licence, enrolment restriction, macOS version and sign-in result.
Profile is Pending or ErrorAssignment, payload compatibility and conflictPer-setting status, device check-in, OS version, competing profiles and Console log time.
Mac is noncompliantPer-setting compliance reportFailed control, grace period, last check-in, FileVault state and threat-provider status.
App remains Waiting or FailedAssignment, app type, install context and detectionIntune app status, Intune Management Agent log, package signature, free space and user context.
Platform SSO will not registerCompany Portal, SSO extension and authentication methodCompany Portal version, profile status, local account state, network path and registration prompt.
Update deadline is ignoredDDM eligibility, target version and bootstrap tokenmacOS version, supervision, bootstrap-token escrow, update profile and available storage.
Remote action remains PendingConnectivity and check-inLast check-in, action timestamp, power/network state and APNs reachability.
Before Wipe, Retire or Delete

Record the serial, ownership, Apple assignment, Intune object, Entra object, primary user, recovery keys, activation state, last check-in, pending actions and data-recovery approval. Confirm which platform will release or retain the device after the action.

Keep moving

Use the guide, then diagnose the exact symptom.

Search all 203 Intune scenarios →Switch to the Windows deployment guide →

Search LAlite

A guide, a scenario or a checklist. Find it here.