How to Use Direct Enrollment for macOS Using Intune

In this post, We will go through the topic of direct enrollment for macOS devices using Intune, reviewing briefly each step need to perform for the enrollment profile push. Also, as you know, we have covered the macOS BYOD enrollment method.

Our last blog post discussed managing macOS Login Background App using Intune. As we have observed in the last post, what is login and background item, and how to configure a policy with the help of Intune for macOS?

Also, as we discussed in our previous posts, the latest Microsoft Intune release 2211 supports 6 platforms such as Windows, iPadOS/iOS, macOS, Android, ChromeOS, and Linux OS. Let’s review each enrollment step available by Microsoft to set up macOS enrollment for company-owned and BYOD (Bring Your Own Devices).

As both company-owned (Corporate) and BYOD (Personal) setup devices can be managed in MDM (mobile device management) Microsoft Intune. However, a few prerequisites need to be met before the setup of the device enrollment process, as discussed below.

Patch My PC

Enable Enrollment in Microsoft Intune

To enroll the MacBook enrollment to Intune, we should first complete the below steps :

No. of StepsEnable enrollment in IntuneDescription
1Verify that devices are eligible for Apple device enrollmentEligible for macOS v10.9 or later
2Configure domainsMake sure to have the organization domain configured/exists
3Set the MDM AuthorityChoose the MDM authority, e.g. Intune standalone, Co-management(JAMF+Intune).
4Get an Apple MDM push certificateDownload and configure the trust relationship certificate from the Apple Push Certificates Portal.
5Assign user licenses to the Microsoft 365 admin centerMake sure to have the required licenses to use Intune
6Create groupsCreate security and M365 groups to manage license and access
7Configure the Company Portal appConfigure the company portal app as per the organisation standards
Table 1 – Enable enrollment in Microsoft Intune

Types of Enrollment Methods

After we enable enrollment in Intune, let’s discuss the types of enrollment methods

  • Company-Owned (Corporate)
  • User-Owned (BYOD)

Company Owned macOS Device Enrollment

As discussed in the enrollment methods, In Intune, Company owned macOS enrollment methods are further divided into 3 sub-categories :

  • Apple Automated Device Enrollment – In this method, we can automate the enrollment experience of company purchased macOS devices through Apple Business Manager or Apple School Manager.
  • Device enrollment manager (DEM) – In this method, particularly for large-scale deployments, IT Admins with device enrollment manager permissions can enroll up to 1,000 devices with single Azure AD account.
  • Direct enrollment (discussed below in the blog)

Direct Enrollment

This method is only used for Company-Owned or corporate devices, It doesn’t need the device to be wiped out, however, it needs the user’s intervention while enrolling the device. This method only applies settings on the OS platform set by IT Admins as per company restrictions, policy settings, and standards in the Microsoft Endpoint manager Admin Center.

Adaptiva

Prerequisites for Direct Enrollment

To enroll your macOS device, you will need to meet the following prerequisites:

  • IT Admin/User needs to enroll the macOS device physically
  • Set MDM authority

On Microsoft Intune release 1911 service release or later, MDM authority is by-default set to Intune.

  • Apple MDM push certificate
  • IT Admin/User must have Administrative privileges on the mac

Create an Apple Configurator Profile for Devices

As said earlier, this enrollment profile only applies the macOS settings during enrollment. To create the enrollment profile, let’s follow the process with Apple Configurator.

In the Microsoft Endpoint Manager admin center, choose Devices > Enroll devices.

How to Use Direct Enrollment for macOS Using Intune Fig.1
How to Use Direct Enrollment for macOS Using Intune Fig.1

A device enrollment profile defines the settings applied during enrollment. These settings are applied only once. Select Apple enrollment > Apple Configurator.

How to use direct enrollment method for macOS devices using Intune Fig. 2
How to Use Direct Enrollment for macOS Using Intune Fig.2

To enroll iOS devices through Apple Configurator, create an enrollment profile by choosing Profiles > Create.

How to use direct enrollment method for macOS devices using Intune Fig. 3
How to Use Direct Enrollment for macOS Using Intune Fig.3

Under Create Enrollment Profile, in the Basics tab, type a Name and Description for the profile for administrative purposes.

How to use direct enrollment method for macOS devices using Intune Fig. 4
How to Use Direct Enrollment for macOS Using Intune Fig.4

For User Affinity, choose Enroll without User Affinity 

Select Enroll with User Affinity for devices that perform tasks without accessing local user data ( used for particular Users) (E.g. 1 user – 1 device).

Select Enroll without User Affinity for devices that don’t need company portal or will be used by multiple users in the organization. (E.g., kiosk, POS devices, or shared utilities)

How to use direct enrollment method for macOS devices using Intune Fig. 5
How to Use Direct Enrollment for macOS Using Intune Fig.5

Here you can review the added details for the enrollment profile and Select Create to save the profile.

How to use direct enrollment method for macOS devices using Intune Fig. 6
How to Use Direct Enrollment for macOS Using Intune Fig.6

As Direct Enrollment only supports enrollment without user affinity, the company portal cannot be used for application installation on the device.

Export the Profile and Install on macOS Devices

To export the profile and install it on macOS devices, follow these steps:

  • In the Microsoft Endpoint Manager admin center, go to Devices > Enroll devices.
  • Select Apple enrollment > Apple Configurator > Profiles.
  • Select the profile you want to export, and then select Export Profile.
How to use direct enrollment method for macOS devices using Intune Fig. 7
How to Use Direct Enrollment for macOS Using Intune Fig.7

Under Direct enrollment, choose Download profile, and then save the file on the macOS device.

How to use direct enrollment method for macOS devices using Intune Fig. 8
How to Use Direct Enrollment for macOS Using Intune Fig.8

On the mac, double-click on the downloaded .mobileconfig to execute. When prompted to install the management profile, select Install.

Confirm on the next prompt you want to install the management profile by selecting Install.

How to use direct enrollment method for macOS devices using Intune Fig. 9
How to Use Direct Enrollment for macOS Using Intune Fig.9

Sign in with an admin account on the macOS device, then select Enrol.

How to use direct enrollment method for macOS devices using Intune Fig. 10
How to Use Direct Enrollment for macOS Using Intune Fig.10

The macOS device is now enrolled in Intune and ready to manage. To verify the device is enrolled, we can check by the below steps.

How to use direct enrollment method for macOS devices using Intune Fig. 11
How to Use Direct Enrollment for macOS Using Intune Fig.11

Conclusion

As we know, organizations use kiosk devices, or multi user devices which can use Direct enrollment method to get managed by Intune MDM Platform. Once the device is enrolled, through intune compliance policies and configuration profiles can be pushed by IT Admins to secure and protect the device inside organisation.

Author

Snehasis Pani is currently working as a JAMF Admin. He loves to help the community by sharing his knowledge on Apple Mac Devices Support. He is an M.Tech graduate in System Engineering.

Leave a Comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.