Microsoft Intune App For Mac

Updated on November 11, 2019

Is there Intune for Macs®? Unfortunately, there isn’t a short answer to this question. What we can say is that while Microsoft® Intune does support some functions for Mac, it really wasn’t designed as a cross-platform system management solution. In general, the focus of Intune is directed towards mobile device management and mobile app management.

What Does Intune Really Provide?

Microsoft Edge Dev is ready to test for Mac users as well as Windows. This has been my preferred browser for most of my work for many months now. The availability for a Enterprise ready deployment also means that we can start testing the deployment of Microsoft Edge Dev with Intune. It is not new. Dec 16, 2019 downloading the Mac Company Portal app at aka.ms/EnrollMyMac. You can also send your users a link to online enrollment steps: Enroll your macOS device in Intune. For information about other end-user tasks, see these articles: Resources about the end-user experience with Microsoft Intune; Using your macOS device with Intune; Company-owned macOS.

Get the best Microsoft student discounts at the Education Store. Find deals on PCs, laptops, accessories, and more for students right now from the Microsoft Store. 2018-9-15  Research shows that inclusive, student-centered classrooms lead to overall learner success, and technology can help. With powerful Microsoft technology like Office 365 Education Learning Tools, FlipGrid, and Teams, educators can give every student equitable access and a voice in the classroom that helps them build confidence and 21st century. Educator discount microsoft office for mac.

On a macOS device, use the following IntuneAppUtil command within the Intune App Wrapping Tool for Mac to extract the detected parameters and version for the created.intunemac file: IntuneAppUtil -r -v. Microsoft Intune 帮助组织让其员工在配置设备设置以满足合规性要求时使用他们喜欢的设备和应用程序。Microsoft Intune 使您可从云管理您的设备,或者在连接到现有 System Center Configuration Manager 基础结构的情况下管理您的设备。. Today, Apple announced the availability of iOS 12 and macOS Mojave and we’re pleased to announce Microsoft Intune supports this update. Apple began releasing developer and beta builds a few months back, and the Intune team has been busy working to ensure that Intune App Protection Policies (APP).

Think of Intune as more of an alternative to VMWare’s Airwatch® rather than Microsoft’s System Center Configuration Manager (SCCM). Need a visual? Check out this diagram to see how the add-on fits into the bigger picture of Microsoft solutions.

The result is that while Intune can perform some functions on Macs, the concept of a platform that can dispense GPO-like Polices and commands for Macs isn’t completely delivered from Intune. Instead, Intune’s benefit is that it creates a framework for when devices can access Azure®-related data and applications. Intune, or a third-party solution, will send information back to Azure to decide its level of compliance. Note that implementing any device compliance capabilities requires the use of Azure AD as well as Active Directory® and SCCM if those are being used on-prem.

Microsoft Intune App For Mac

More Add-Ons Challenge macOS Management

The challenge for IT admins is that you need to find yet another solution beyond Intune and Azure AD to actually create the settings and manage the macOS device. For example, setting password complexity requirements, enabling FileVault, updating the OS, setting screensaver locks and more often need to be either handled manually by the IT admin, or by another solution all together. The result is that IT admins are now searching for additional IT management solutions beyond Intune and Azure AD (not to mention Active Directory and SCCM on-prem).

Philosophically, Microsoft’s approach to identity and system management is quite different from what we believe IT admins are truly searching for. Microsoft’s view is to create segmented solutions that are mostly focused on Windows and Azure, and then require additional solutions for non-Windows platforms. You can hardly blame them for doing so, but is this really the best approach for organizations that leverage mixed-platform environments?

For example, for Microsoft’s identity management solutions, IT admins need Active Directory and the domain controller on-prem, and then AD Connect, Azure AD, Azure AD DS, and more, all in Azure. For system management, SCCM is utilized on-prem and then Intune is added on for mobile device management from the cloud.

Delivering Wide Access Control from the Identity Provider

Sometimes, people are led to think that access control to corporate data is a device management feature. We don’t think of it that way because it isn’t something that the mobile operating system provides. Rather, it’s something the identity provider delivers. In this case, the identity provider associated with Intune is Azure Active Directory (Azure AD), Microsoft’s cloud identity and access management (IAM) system, but it is Intune that is providing the conditional access to Azure resources.

The JumpCloud® Directory-as-a-Service® platform takes the complete opposite view and is tightly integrating not only identity and access management, but system management as well. Further, macOS and Linux® are treated as first class systems similar to Windows, rather than being forced to find additional third-party solutions in Microsoft’s ecosystem.

Moving Beyond Intune for Macs

If you’re interested in understanding more about how Directory-as-a-Service compares to Intune for Macs, and would like to see how JumpCloud extends beyond just device management, give us a call or send us an email. One of our product experts will be happy to answer your questions or set up a demo. Furthermore, signing up to try Directory-as-a-Service is easy and free of charge for your first 10 users.

-->

Intune lets you manage macOS devices to give users access to company email and apps.

As an Intune admin, you can set up enrollment for company-owned macOS devices and personally owned macOS devices ('bring your own device' or BYOD).

Prerequisites

Complete the following prerequisites before setting up macOS device enrollment:

  • Make sure your device is eligible for Apple device enrollment.
  • Assign user licenses in the Microsoft 365 admin center

User-owned macOS devices (BYOD)

You can let users enroll their own personal devices into Intune management. This is known as 'bring your own device' or BYOD. After you've completed the prerequisites and assigned user licenses, your users can enroll their devices by:

  • going to the Company Portal website or
  • downloading the Mac Company Portal app at aka.ms/EnrollMyMac.

You can also send your users a link to online enrollment steps: Enroll your macOS device in Intune.

For information about other end-user tasks, see these articles:

Company-owned macOS devices

For organizations that purchase devices for their users, Intune supports the following macOS company-owned device enrollment methods:

  • Apple's Automated Device Enrollment (ADE): Organizations can purchase macOS devices through ADE. ADE lets you deploy an enrollment profile 'over the air' to bring devices into management.
  • Device enrollment manager (DEM): You can use a DEM account to enroll up to 1,000 devices.

Block macOS enrollment

By default, Intune lets macOS devices enroll. Alternative to microsoft office on mac. To block macOS devices from enrollment, see Set device type restrictions.

Enroll virtual macOS machines for testing

Note

macOS virtual machines are only supported for testing. You should not use macOS virtual machines as production devices for your end users.

You can enroll macOS virtual machines for testing using either Parallels Desktop or VMware Fusion.

For Parallels Desktop, you need to set the hardware type and the serial number for the virtual machines so that Intune can recognize them. Follow Parallels' instructions for setting hardware type and serial number to set up the necessary settings for testing. We recommend that you match the hardware type of the device running the virtual machines to the hardware type of the virtual machines that you're creating. You can find this hardware type in Apple menu > About this Mac > System Report > Model Identifier.

For VMware Fusion, you need to edit the .vmx file to set the virtual machine's hardware model and serial number. We recommend that you match the hardware type of the device running the virtual machines to the hardware type of the virtual machines that you're creating. You can find this hardware type in Apple menu > About this Mac > System Report > Model Identifier.

User Approved enrollment

User Approved MDM enrollment is a type of macOS enrollment that you can use to manage certain security-sensitive settings. For more information, see Apple's support documentation.

During the BYOD enrollment process, the user will be asked to manually approve the Apple management profile. Instructions are provided in the Company Portal app for macOS. Although approval of the management profile is not required to complete enrollment, Intune recommends user approved enrollments. If the user does not approve the profile during enrollment, the user can go to System Preferences > Profiles, choose the management profile, and select Approve.

Find out if a device is User Approved

  1. Sign in to the Microsoft Endpoint Manager admin center.
  2. Choose Devices > All devices> choose the device > Hardware.
  3. Check the User approved enrollment field.

Microsoft Intune App For Mac Windows 7

Microsoft Intune App For Mac

Next steps

Company Portal App

After macOS devices are enrolled, you can create custom settings for macOS devices.