Deployment planning
Write the outcome before building the policy.
Decide who owns each Mac, who signs in, what must work on day one, what proves the device is healthy, and who supports it when the first deployment fails.
Named user, shared device or lab? Standard user or approved local administrator? Which support team owns identity, network, apps and Apple services?
Apple silicon and supported macOS version? Purchased through a linked channel? Existing device that can be erased, or personal BYOD?
Which services require Conditional Access, certificates, Wi-Fi, VPN, Platform SSO or Microsoft 365 on first sign-in?
Who can approve a wipe, retrieve FileVault keys, rotate Recovery Lock, renew APNs and release a device from Apple ownership?
Use 5–10 representative Macs, at least two hardware models, one standard user, one IT administrator and the real network path. Test new setup, restart, offline sign-in, app install, update, FileVault recovery, noncompliance, remote action and a clean handover.
Microsoft Intune admin center → Devices → Overview; Microsoft Entra admin center → Groups
Create named pilot user and device groups with no broad production assignment.
A test user can sign in and the pilot group membership is deliberate and documented.
Assigning every policy to All users or All devices before dependencies and exclusions are understood.
Device enrolment
Choose enrolment by ownership and use.
Automated Device Enrollment (ADE) is the normal route for new or erased school-owned Macs purchased through Apple or a participating reseller. Company Portal is the self-service route Microsoft documents for personal Macs. Direct enrollment is a no-user-affinity option that needs physical access.
Yes: Apple School/Business Manager + ADE
No: plan migration; use Company Portal only if its ownership and supervision limits are acceptable
Yes: Company Portal user enrolment
No: do not enrol; provide the approved access alternative
ADE in plain language
- Link the purchase channel to Apple School or Business Manager.
- Assign the Mac to the Intune MDM server in Apple’s portal.
- Synchronise the enrollment-program token in Intune.
- Create an ADE profile: user affinity for 1:1 use; no user affinity for truly shared use.
- Use modern authentication and decide which Setup Assistant screens users should see.
- Assign only to the pilot device group, erase the test Mac, and complete Setup Assistant.
- Verify supervision, ownership, primary user, bootstrap-token escrow and last check-in.
Intune → Devices → Enrollment → Apple → Enrollment program tokens
Create one clearly named ADE profile and assign it only to pilot Macs.
The serial appears under the token, the profile is assigned, and the Mac enrols during Setup Assistant.
Expecting a Mac already in use to become supervised through ADE without erase and reactivation.
Compliance rules
Measure health before blocking access.
Compliance reports whether a Mac meets the standard. Conditional Access decides what that status means for sign-in. Keep those two layers separate, and prove reporting before enforcement.
Compliance policy
Start with supported macOS version, password requirements, encryption and threat level only where the required integration exists.
Actions for noncompliance
Use a grace period and notification that tells the user what failed and where to get help.
Conditional Access
Pilot “require compliant device” with exclusions, emergency-access accounts and sign-in log review.
Intune → Devices → Compliance → Policies → Create policy → macOS
Create a small baseline, add a useful noncompliance message and assign it to the pilot group.
The per-setting report names the exact passing or failing control on each test Mac.
Turning on Conditional Access before the Mac has checked in, calculated compliance and received Company Portal.
Device settings
Prefer small Settings Catalog profiles.
Microsoft recommends the Settings Catalog for new Apple policies where possible. Split profiles by purpose so a conflict can be traced to one owner and one change.
Platform SSO, login window and account settings
Wi-Fi, VPN, proxies and certificates
Cloud services, sharing, media and user controls
DDM target version, deadlines and deferrals
PPPC and system-extension approvals for known apps
Dock, browser and organisation settings only where supportable
Apple deprecated the older MDM software-update workload with macOS 26. Microsoft now recommends Apple Declarative Device Management update policies. Build new update controls with DDM, pilot deadlines and test restart behaviour.
Intune → Devices → Manage devices → Configuration → Create → New policy → macOS → Settings catalog
Create one profile per purpose, use a clear prefix such as macOS – Pilot – Wi-Fi, and assign it to the pilot group.
Device configuration reports show Succeeded, and the setting is present after a device sync and restart where required.
Configuring the same payload in Settings Catalog, a template and a custom profile, creating conflicts with no clear owner.
Endpoint security
Secure the Mac and preserve recovery.
Start with FileVault, firewall and a supported endpoint-protection design. Add Recovery Lock and local-administrator password management only after ownership and recovery roles are defined.
Encrypt
Deploy FileVault and confirm the personal recovery key is escrowed before declaring success.
Protect
Configure firewall and Defender for Endpoint where licensed; grant required system extensions and privacy permissions through managed profiles.
Recover
Test authorised FileVault key access. For supported macOS versions, use Intune LAPS for a managed local administrator and Recovery Lock to protect startup options.
Intune → Endpoint security → Disk encryption → Create policy → macOS
Require FileVault for pilot devices and escrow the recovery key; document the help-desk verification process.
The encryption report shows the Mac encrypted and its key available to an authorised role.
Enabling encryption without confirming who can retrieve a recovery key, or assuming an already-encrypted Mac has escrowed its key.
Authentication methods
Join device sign-in to cloud identity carefully.
Require MFA for administrative access and use Conditional Access for cloud resources. Platform SSO can connect the local Mac account with Microsoft Entra credentials, but it needs Company Portal, an SSO extension profile and a tested registration experience.
- Do pilot with a standard user, offline sign-in and password-change scenarios.
- Do use certificate profiles for Wi-Fi or VPN only after the certificate connector and renewal path are tested.
- Do not remove the tested local recovery route before Platform SSO registration is proven.
- Do not assume Platform SSO alone makes a Mac compliant; compliance and access remain separate policies.
Intune → Devices → Manage devices → Configuration → Settings catalog → Authentication → Extensible Single Sign On
Deploy the current Company Portal as required, then a Platform SSO profile to the pilot group.
Company Portal shows registration complete; password change, restart, lock, offline sign-in and token refresh all work.
Deploying the SSO extension before Company Portal and required permissions, or changing the authentication method mid-pilot.
App deployment
Separate first-day apps from everything else.
Deploy Company Portal to Macs with user affinity, then deliver Microsoft 365 and a short first-day set. Use Apple Apps and Books for store apps and a supported Intune macOS app type for signed line-of-business software.
Needed before work begins
Company Portal, identity or security agents, certificates and only the essential productivity apps.
User chooses later
Optional curriculum, departmental and specialist apps shown through Company Portal.
Know who keeps it current
Microsoft AutoUpdate, App Store/Apps and Books, vendor updater or a superseding Intune package—never an undocumented mixture.
Intune supports Declarative Device Management for required Apple volume-purchased apps on supported Apple OS versions. Check the Intune “What’s new” page before changing a production app-delivery design.
Intune → Apps → All apps → Create
Make Company Portal required for the pilot user group, then add Microsoft 365 using Intune’s built-in macOS app type.
Each app reports Installed, launches under a standard user, updates correctly and has a tested uninstall or supersedence route.
Marking every application as required, mixing user and device assignments without intent, or packaging unsigned software that needs interactive approval.
Remote actions
Use the least destructive action that proves the next fact.
For an enrolled, online Mac, Intune can expose actions such as Sync, Restart, Rename, Remote lock, Retire, Wipe, Delete, FileVault key rotation and Recovery Lock rotation. Availability depends on enrolment and configuration.
Use to deliver policy, clear a pending restart or correct inventory. Verify the action status and last check-in.
Confirm device identity, ownership and the authorised recovery route before acting.
Use approved change control. Retire, Wipe and Delete can take precedence over other pending actions; a server-side completion does not always prove the Mac received it.
Intune → Devices → All devices → select the Mac → device action
Test Sync and Restart on a pilot Mac; record how the action appears in Devices → Device actions.
The action status, Mac behaviour and updated last-check-in time agree.
Deleting the device object while it is offline and assuming that proves organisational data was removed from the Mac.
Evidence-led troubleshooting
Locate the failed layer before erasing the Mac.
| Symptom | First layer to inspect | Evidence to capture |
|---|---|---|
| Mac never receives the ADE profile | Apple assignment and Intune token sync | Serial number, Apple portal MDM assignment, token sync time and assigned profile. |
| Company Portal enrolment fails | Account, licence, APNs, restriction and Conditional Access | Exact message, user licence, enrolment restriction, macOS version and sign-in result. |
| Profile is Pending or Error | Assignment, payload compatibility and conflict | Per-setting status, device check-in, OS version, competing profiles and Console log time. |
| Mac is noncompliant | Per-setting compliance report | Failed control, grace period, last check-in, FileVault state and threat-provider status. |
| App remains Waiting or Failed | Assignment, app type, install context and detection | Intune app status, Intune Management Agent log, package signature, free space and user context. |
| Platform SSO will not register | Company Portal, SSO extension and authentication method | Company Portal version, profile status, local account state, network path and registration prompt. |
| Update deadline is ignored | DDM eligibility, target version and bootstrap token | macOS version, supervision, bootstrap-token escrow, update profile and available storage. |
| Remote action remains Pending | Connectivity and check-in | Last check-in, action timestamp, power/network state and APNs reachability. |
Record the serial, ownership, Apple assignment, Intune object, Entra object, primary user, recovery keys, activation state, last check-in, pending actions and data-recovery approval. Confirm which platform will release or retain the device after the action.
