Enroll Personal/BYOD macOS device in Intune

Enroll Personal/BYOD macOS device in Intune


In this blog post, we will learn the steps to enroll a personal or BYOD type Mac device into Intune. For device enrollment, we would be using the company portal app that needs to be downloaded and installed on the Mac first, before proceeding with the enrollment steps.

Once the device is enrolled, you can manage it from Intune admin center. For example, you can deploy PKG apps, DMG apps or perform any config changes on the Mac using a device configuration profile. Below are some of the blog posts to get started on app deployment and device configuration profile for Intune-managed macOS devices.

Prerequisites

To enroll a personal Mac device in Intune, you must Allow Personally owned macOS devices in device platform restriction settings. Sign in to the Intune admin center > Devices > Enrollment > Device type restriction > Click on All Users to open default policy settings. If you have a custom device platform restrictions policy, you need to edit that policy.

Thiết kế hệ thống chuyên nghiệp OceanTech-Group enroll_MacOS_Intune_01 Enroll Personal/BYOD macOS device in Intune Thủ thuật

Steps to Enroll Personally Owned (BYOD) macOS device

The enrollment process has two steps: First, configuring the Apple MDM push certificate on the Intune, and Second, Installing the Company Portal App on your macOS device.

  1. Apple MDM Push Certificate.
  2. Install Company Portal Application.

1. Configure Apple MDM Push Certificate

To configure the Apple MDM Push certificate on the Intune admin center, refer to the link: Create Apple MDM Push Certificate for Intune.

2. Install the Company Portal App

  • Login to the Mac device that you want to enroll.
  • Click on the link: Install Company Portal Application. [This link will immediately download the CompanyPortal-Installer.pkg file on the device].
  • You may get a prompt before the download starts. Click Allow.
  • Launch the CompanyPortal-Installer.pkg file.
Thiết kế hệ thống chuyên nghiệp OceanTech-Group enroll_MacOS_Intune_03 Enroll Personal/BYOD macOS device in Intune Thủ thuật
  • Click on Continue.
Thiết kế hệ thống chuyên nghiệp OceanTech-Group enroll_MacOS_Intune_04 Enroll Personal/BYOD macOS device in Intune Thủ thuật
  • Click on Continue.
Thiết kế hệ thống chuyên nghiệp OceanTech-Group enroll_MacOS_Intune_05 Enroll Personal/BYOD macOS device in Intune Thủ thuật
  • Click on Agree.
Thiết kế hệ thống chuyên nghiệp OceanTech-Group enroll_MacOS_Intune_06 Enroll Personal/BYOD macOS device in Intune Thủ thuật
  • Click on Install.
Thiết kế hệ thống chuyên nghiệp OceanTech-Group enroll_MacOS_Intune_07 Enroll Personal/BYOD macOS device in Intune Thủ thuật
  • Provide the administrator password and then click on the Install Software button.
Thiết kế hệ thống chuyên nghiệp OceanTech-Group enroll_MacOS_Intune_08 Enroll Personal/BYOD macOS device in Intune Thủ thuật
  • The installation of the Company Portal app has been completed.
Thiết kế hệ thống chuyên nghiệp OceanTech-Group enroll_MacOS_Intune_09 Enroll Personal/BYOD macOS device in Intune Thủ thuật
  • As we no longer need to keep the Setup Installer file, click the Move to Bin button to remove it.
Thiết kế hệ thống chuyên nghiệp OceanTech-Group enroll_MacOS_Intune_10 Enroll Personal/BYOD macOS device in Intune Thủ thuật
  • Microsoft AutoUpdate may launch automatically to check if all Microsoft apps are updated.
Thiết kế hệ thống chuyên nghiệp OceanTech-Group enroll_MacOS_Intune_10_2 Enroll Personal/BYOD macOS device in Intune Thủ thuật
Microsoft AutoUpdate App Data Notice
  • To update your Microsoft apps, click on the Update button. After all the apps have been updated, you can close the window.
Thiết kế hệ thống chuyên nghiệp OceanTech-Group enroll_MacOS_Intune_11 Enroll Personal/BYOD macOS device in Intune Thủ thuật
Microsoft AutoUpdate
  • You can launch the app by typing Company Portal in the Spotlight Search bar and clicking on it when it appears in the search results.
Thiết kế hệ thống chuyên nghiệp OceanTech-Group enroll_MacOS_Intune_12 Enroll Personal/BYOD macOS device in Intune Thủ thuật
Search for the Company Portal App using Spotlight Search
  • Once the Company Portal App is launched, click the Sign In button to proceed.
Thiết kế hệ thống chuyên nghiệp OceanTech-Group enroll_MacOS_Intune_13 Enroll Personal/BYOD macOS device in Intune Thủ thuật
  • Please enter the user account details provided by your company or organization, and then click Sign In to continue.
Thiết kế hệ thống chuyên nghiệp OceanTech-Group enroll_MacOS_Intune_14 Enroll Personal/BYOD macOS device in Intune Thủ thuật
  • Click on Begin.
Thiết kế hệ thống chuyên nghiệp OceanTech-Group enroll_MacOS_Intune_15 Enroll Personal/BYOD macOS device in Intune Thủ thuật
  • Click Continue.
Thiết kế hệ thống chuyên nghiệp OceanTech-Group enroll_MacOS_Intune_16 Enroll Personal/BYOD macOS device in Intune Thủ thuật
Review Privacy Information and click on Continue
  • Registering your Mac…. device with Microsoft Entra ID.
Thiết kế hệ thống chuyên nghiệp OceanTech-Group enroll_MacOS_Intune_17 Enroll Personal/BYOD macOS device in Intune Thủ thuật
Registration of Mac device is in Progress
  • To download your device’s management profile, click the Download Profile button.
Thiết kế hệ thống chuyên nghiệp OceanTech-Group enroll_MacOS_Intune_18 Enroll Personal/BYOD macOS device in Intune Thủ thuật
Click on the Download Profile button to Download the management profile
  • After downloading the management profile, a pop-up notification will appear in the top right-hand corner to confirm that the profile has been downloaded. Additionally, it should automatically take you to the Management Profile screen, where you can Install it.
  • If the Management Profile window does not open automatically, you can manually access it by going to System Settings > General > Profiles. Look for the Management Profile with a warning sign and double-click on it. Then, click the Install button to proceed with the installation.
Thiết kế hệ thống chuyên nghiệp OceanTech-Group enroll_MacOS_Intune_19 Enroll Personal/BYOD macOS device in Intune Thủ thuật
System Settings > General > Profiles and double-click on Management Profile
  • That’s It; The macOS device is now Enrolled with Intune.

More Information

If you want more information about the Management Profile, you can navigate back to System Settings > General > Profiles. From there, double-click the Installed/Active Management Profile to access more information and details.

Thiết kế hệ thống chuyên nghiệp OceanTech-Group macOS_Profile_Failed_Intune_05-1 Enroll Personal/BYOD macOS device in Intune Thủ thuật
Management profile Rights / Control to MDM Provider

This Management Profile provides below Information:

  • Installed date
  • Rights / Control it provides to MDM service providers.
  • Certificate Details etc.

As you can see from the screenshot, Intune has the rights/control to:

  • Erase all data on this computer
  • Add or remove configuration profiles
  • Add or remove provisioning profiles
  • Lock Screen
  • Change Settings
  • Application and media management
  • Query security information
  • Query restrictions
  • Query computer information
  • Query network configuration
  • Query Installed applications
  • Query Installed configuration profiles
  • Query Installed provisioning processes

Confirm macOS Registration in Entra Admin Center

Now that the device registration has been completed successfully, we can check its status from the Microsoft Entra admin center. let’s check the steps:

  • Sign in to the Entra admin center.
  • Click on Devices > All devices under Identity.
  • You’ll notice that our MacBook Pro is registered in Entra ID. The MDM column shows that the Microsoft Intune manages it.
Thiết kế hệ thống chuyên nghiệp OceanTech-Group enroll_MacOS_Intune_20 Enroll Personal/BYOD macOS device in Intune Thủ thuật
Confirm macOS Registration in Entra Admin Center

Confirm macOS Registration from the Intune admin center

You can also verify the status of your macOS device in the Intune admin center to ensure it’s listed under All devices. Follow these steps to check and confirm the registration of your macOS device:

  • Sign in to the Intune admin center > Devices > All devices.
  • You should be able to locate the newly registered Mac within Intune. Please make sure to take note of the Compliance Status and the Primary User UPN, which, in my case, is MeganB@cloudinfra.net.
Thiết kế hệ thống chuyên nghiệp OceanTech-Group enroll_MacOS_Intune_21 Enroll Personal/BYOD macOS device in Intune Thủ thuật
Confirm macOS Registration from the Intune admin center

If you haven’t already set up Device compliance policies for Mac, creating one that specifically covers the macOS device platform is important. Now that this Mac device is enrolled in Intune, you can manage it, deploy configuration policies, run scripts and deploy applications, and monitor its status from the Intune admin center.

FAQS

1. Fix the Profile Installation Failed Error

You might encounter an error message that reads, Profile Installation Failed: Could not obtain the final profile using the Encrypted Profile Service. The credentials within your profile may have expired. Try downloading a new profile. This error occurs when attempting to install the management profile.

Thiết kế hệ thống chuyên nghiệp OceanTech-Group macOS_Profile_Failed_Intune_01 Enroll Personal/BYOD macOS device in Intune Thủ thuật
Profile Installation Failed Error

Refer to the blog post provides on how to fix the macOS Profile Installation Failed error during Intune enrollment.

2. Enroll Company-Owned macOS devices

Enrolling a company-owned macOS device into Intune offers greater management capabilities to an Intune administrator than enrolling a device through user-owned BYOD methods. Three methods are available for enrolling a company-owned macOS device.

  • Apple Automated Device Enrollment.
  • Device enrollment manager (DEM).
  • Direct enrollment.

Conclusion

In this blog post, we’ve covered enrolling a BYOD macOS device in Intune. This step-by-step guide includes screenshots for each enrollment step. We’ve also addressed the Profile Installation Failed error message and provided solutions to resolve it. This error typically occurs during the installation of the management profile on a macOS device.

Tags:

THIẾT KẾ HỆ THỐNG AD - EMAIL - ECOSYSTEM - AUTOMATION INTERGRATION CHUYÊN NGHIỆP - BẢO MẬT

 

Liên hệ ngay với OceanTech-Group để thiết kế hệ thống trơn chu chuẩn bảo mật cho doanh nghiệp của bạn!

Hotline: 0774-751-773
X
Chat với chúng tôi !