Intune App Protection Macos
- Intune Macos Custom Profile
- Intune Macos Support
- Intune Macos Enrollment
- Intune Application Protection Policy
Enroll your macOS device with the Intune Company Portal app to gain secure access to your work or school email, files, and apps.
Organizations typically require you to enroll your device before you can access proprietary data. After your device is enrolled, it becomes managed. Your organization can assign policies and apps to the device through a mobile device management (MDM) provider, such as Intune. To get continuous access to work or school information on your device, you must set up your device to match your organization's policy settings.
This article describes how to use the Company Portal app for macOS to set up and maintain your device so that you meet your organization's requirements.
![Intune app protection macos high sierra Intune app protection macos high sierra](https://uem4all.files.wordpress.com/2019/03/031119_2202_intunemacos17.png?w=840)
What to expect from the Company Portal app
During initial setup, the Company Portal app requires you to sign in and authenticate yourself with your organization. Company Portal then informs you of any device settings you need to configure to meet your organization's requirements. For example, organizations often set minimum or maximum character password requirements that you'll be required to meet.
You might ask what happens when the real device comes online, well for the Apple DEP system it doesn’t worry about what hardware is being used it just has a MacOS requesting it’s DEP Policy, while in Intune it is the last device that is registered into the system which will be fully managed. Apple volume-purchased (VPP) apps support for macOS. App wrapping tool support for 64-bits and macOS Catalina (10.15). Web clip install support for macOS. Expanded support for thousands of Apple VPP tokens per Intune tenant. Protect app inventory data on personal macOS devices. The rest of this article goes into further detail for each item above. When it enrolling your first macOS device into Intune take note, there's a couple of prerequisites you need in place. Ensure the device is eligible for Apple device enrollmentEnsure users have an assigned Intune licenceMake sure you have an Apple MDM push certificate Device Eligibility For device eligibility, the Mac computers must be running OS. Go to select Apps - All Apps - Add, Select app type Microsoft Defender ATP / macOS You get to the App configuration blade. Click Next - Add Scope tag if you use it - Assign the app to your dynamic device group as required - Review and create – Click Create. MacOS platform in Mobile Application Protection MAM policies Add the macOS to the MAM policies in the new intune portal. MacOS MDM works great but having the ability to protect apps like Outlook and not manage the device would be great for security and user adaption experiences.
After you enroll your device, Company Portal will always make sure that your device is protected according to your organization's requirements. For example, if you install an app from a source that's not trusted, Company Portal will alert you and might restrict access to your organization's resources. App protection policies like this one are common. To regain access, you'll likely need to uninstall the app.
If after enrollment your organization enforces a new security requirement, such as multi-factor authentication, Company Portal will notify you. You'll have the chance to adjust your settings so that you can continue to work from your device.
To learn more about enrollment, see What happens when I install the Company Portal app and enroll my device?.
![Intune Intune](https://docs.microsoft.com/en-us/intune/media/sso-blade.png)
Get your macOS device managed
Use the following steps to enroll your macOS device with your organization. Your device must be running macOS 10.12 or later.
Note
Throughout this process, you might be prompted to allow Company Portal to use confidential information that's stored in your keychain. These prompts are part of Apple security. When you get the prompt, type in your login keychain password and select Always Allow. If you press Enter or Return on your keyboard, the prompt will instead select Allow, which may result in additional prompts.
Install Company Portal app
- Go to Enroll My Mac.
- The Company Portal installer .pkg file will download. Open the installer and continue through the steps.
- Agree to the software license agreement.
- Enter your device password or registered fingerprint to install the software.
- Open Company Portal.
Important
Microsoft AutoUpdate might open to update your Microsoft software. After all updates are installed, open the Company Portal app. For the best setup experience, install the latest versions of Microsoft AutoUpdate and Company Portal.
Intune Macos Custom Profile
Enroll your Mac
Sign in to Company Portal with your work or school account.
When the app opens, select Begin.
Review what your organization can and can't see on your enrolled device. Then select Continue.
On the Install management profile screen, select Download profile.
Your device's system preferences will open.
a. Select Install and then select Install again.
b. If you’re prompted to, enter your device password.Once the profile is installed, it will appear in the profiles list under Management Profile.
Return to Company Portal.
Your organization might require you to update your device settings. When you're done updating settings, select Retry.
When setup is complete, select Done.
Troubleshooting and feedback
Intune Macos Support
If you run into issues during enrollment, go to Help > Send Diagnostic Report to report the issue to Microsoft app developers. This information is used to help improve the app. They'll also use this information to help resolve the problem if your IT support person reaches out to them for help.
Default Behavior Let's say you have a Finder window open and you click on the Finder icon in the Dock. By default Mac OS X will show you the current Finder window, this happens even if it's hidden under other application windows,it will be brought to the front. Mac apps open in finder window.
After you report the problem to Microsoft, you can send the details of your experience to your IT support person. Select Email Details. Type in what you experienced in the body of the email. To find your support person's email address, go to the Company Portal app > Contact. Or check the Company Portal website.
Additionally, the Microsoft Intune Company Portal team would love to hear your feedback. Go to Help > Send Feedback to share your thoughts and ideas.
Unverified profiles
When you view the installed mobile device management (MDM) profiles in System Preferences > Profiles, some profiles might show an unverified status. As long as the management profile shows a verified status, you don't need to be concerned.
How to delete itune and app caches from mac. The management profile is what defines the MDM channel connection. As long as the management profile is verified, any other profiles delivered to the machine via that channel inherit the security traits of the management profile.
Intune Macos Enrollment
Updating the Company Portal app
Updating the Company Portal app is done the same way as any other Office app, through Microsoft AutoUpdate for macOS. Find out more about updating Microsoft apps for macOS.
Next Steps
Intune Application Protection Policy
Still need help? Contact your company support. For contact information, check the Company Portal website.