Download Microsoft Intune Company Portal For Macos

-->

Download Free Intune Company Portal for PC using our guide at BrowserCam. Even if Intune Company Portal application is created suitable for Android operating system together with iOS by undefined. You are able to install Intune Company Portal on PC for windows computer. May 27, 2020  For related information, see How to customize the Intune Company Portal apps, Company Portal website, and Intune app. Android Company Portal user experience. In the 2005 release of Android Company Portal, end-users of Android devices that are issued a warn, block, or wipe by an app protection policy will see a new user experience. – macOS devices with OS X 10.11 Yosemite or later – Microsoft Intune licenses If needed, get an Enterprise Mobility + Security E5 trial here. The company portal is quite straight forward. Just download the pkg from the link in the pre-reqs, upload it to your Distribution Point, and create a policy to deploy and install it to your devices.

This article lists and describes the different settings you can control on macOS devices. As part of your mobile device management (MDM) solution, use these settings to allow or disable features, set password rules, allow or restrict specific apps, and more.

These settings are added to a device configuration profile in Intune, and then assigned or deployed to your macOS devices.

Note

Microsoft Intune Company Portal Application

The user interface may not match the enrollment types in this article. The information in this article is correct. The user interface is being updated in an upcoming release.

Portal

Before you begin

Create a macOS device restrictions configuration profile.

Note

These settings apply to different enrollment types. For more information on the different enrollment types, see macOS enrollment.

Built-in Apps

Settings apply to: All enrollment types

  • Block Safari AutoFill: Yes disables the autofill feature in Safari on devices. When set to Not configured (default), Intune doesn't change or update this setting. By default, the OS might allow users to change autocomplete settings in the web browser.

  • Block use of camera: Yes prevents access to the camera on devices. When set to Not configured (default), Intune doesn't change or update this setting. By default, the OS might allow access to the device camera.

    Intune only manages access to the device camera. It doesn't have access to pictures or videos.

  • Block Apple Music: Yes reverts the Music app to classic mode, and disables the Music service. When set to Not configured (default), Intune doesn't change or update this setting. By default, the OS might allow using the Apple Music app.

  • Block spotlight suggestions: Yes stops Spotlight from returning any results from an Internet search. When set to Not configured (default), Intune doesn't change or update this setting. By default, the OS might allow Spotlight search to connect to the Internet, and get search results.

  • Block file transfer using Finder or iTunes: Yes disables application file sharing services. When set to Not configured (default), Intune doesn't change or update this setting. By default, the OS might allow application file sharing services.

    This feature applies to:

    • macOS 10.13 and newer

Cloud and storage

Settings apply to: All enrollment types

  • Block iCloud Keychain sync: Yes disables syncing credentials stored in the Keychain to iCloud. When set to Not configured (default), Intune doesn't change or update this setting. By default, the OS might allow users to sync these credentials.

  • Block iCloud Desktop and Document Sync: Yes prevents iCloud from syncing documents and data. When set to Not configured (default), Intune doesn't change or update this setting. By default, the OS might allow document and key-value synchronization to your iCloud storage space.

  • Block iCloud Mail Backup: Yes prevents iCloud from syncing to the macOS Mail app. When set to Not configured (default), Intune doesn't change or update this setting. By default, the OS might allow Mail synchronization to iCloud.

  • Block iCloud Contact Backup: Yes prevents iCloud from syncing the device contacts. When set to Not configured (default), Intune doesn't change or update this setting. By default, the OS might allow contact sync using iCloud.

  • Block iCloud Calendar Backup: Yes prevents iCloud from syncing to the macOS Calendar app. When set to Not configured (default), Intune doesn't change or update this setting. By default, the OS might allow Calendar synchronization to iCloud.

  • Block iCloud Reminder Backup: Yes prevents iCloud from syncing to the macOS Reminders app. When set to Not configured (default), Intune doesn't change or update this setting. By default, the OS might allow Reminders synchronization to iCloud.

  • Block iCloud Bookmark Backup: Yes prevents iCloud from syncing the device Bookmarks. When set to Not configured (default), Intune doesn't change or update this setting. By default, the OS might allow Bookmark synchronization to iCloud.

  • Block iCloud Notes Backup: Yes prevents iCloud from syncing the device Notes. When set to Not configured (default), Intune doesn't change or update this setting. By default, the OS might allow Notes synchronization to iCloud.

  • Block iCloud Photos backup: Yes disables iCloud Photo Library, and prevents iCloud from syncing the device photos. Any photos not fully downloaded from iCloud Photo Library are removed from local storage on devices. When set to Not configured (default), Intune doesn't change or update this setting. By default, the OS might allow syncing photos between the device and the iCloud Photo Library.

  • Block Handoff: This feature allows users to start work on a macOS device, and then continue the work they started on another iOS/iPadOS or macOS device. Yes prevents the Handoff feature on devices. When set to Not configured (default), Intune doesn't change or update this setting. By default, the OS might allow this feature on devices.

    This feature applies to:

    • macOS 10.15 and newer

Connected devices

Settings apply to: All enrollment types

Microsoft Intune Company Portal Android

  • Block AirDrop: Yes prevents using AirDrop on devices. When set to Not configured (default), Intune doesn't change or update this setting. By default, the OS might allow using the AirDrop feature to exchange content with nearby devices.
  • Block Apple Watch auto unlock: Yes prevents users from unlocking their macOS device with their Apple Watch. When set to Not configured (default), Intune doesn't change or update this setting. By default, the OS might allow users to unlock their macOS device with their Apple Watch.

Domains

Settings apply to: All enrollment types

  • Unmarked Email Domains: Enter one or more Email domain URLs to the list. When users send or receive an email from a domain other than the domains you added, the email is marked as untrusted in the macOS Mail app.

General

Settings apply to: All enrollment types

  • Block Lookup: Yes prevents user from highlighting a word, and then looking up its definition on the device. When set to Not configured (default), Intune doesn't change or update this setting. By default, the OS might allow the definition lookup feature.

  • Block dictation: Yes stops users from using voice input to enter text. When set to Not configured (default), Intune doesn't change or update this setting. By default, the OS might allow users to use dictation input.

  • Block content caching: Yes prevents content caching. Content caching stores app data, web browser data, downloads, and more locally on devices. When set to Not configured (default), Intune doesn't change or update this setting. By default, the OS might enable content caching.

    For more information on content caching on macOS, see Manage content caching on Mac (opens another website).

    Add support for powerpc applications on macos x 10.10 yosemite. Oct 24, 2019  For the strongest security and latest features, find out whether you can upgrade to macOS Catalina, the latest version of macOS. If you still need OS X Yosemite, use this link: Download OS X Yosemite. A file named InstallMacOSX.dmg will download to your Mac. Adobe and Apple have worked closely together to test Adobe Creative Cloud applications for reliability, performance, and user experience when installed on Intel-based systems running Mac OS X Yosemite (version 10.10). The latest versions of all Adobe Creative Cloud products are compatible. MacOS Server, formerly named Mac OS X Server and OS X Server, is a discontinued, stand-alone server operating system by Apple Inc.It is also the name of its replacement software, an operating system addition, for macOS that provides additional server programs along with management and administration tools for iOS and macOS. Prior to version 10.7 (Lion), Mac OS X Server was a separate but. Feb 10, 2015  OS X Yosemite (10.10) MacRumors attracts a broad audience of both consumers and professionals interested in the latest technologies and products. We also boast an active community focused on purchasing decisions and technical aspects of the iPhone, iPod, iPad, and Mac platforms.

    This feature applies to:

    • macOS 10.13 and newer
  • Defer software updates: Yes allows you to delay when software updates are shown on devices, from 0-90 days. This setting doesn't control when updates are or aren't installed. When set to Not configured (default), Intune doesn't change or update this setting. By default, the OS might show updates on devices as Apple releases them. For example, if a macOS update gets released by Apple on a specific date, then that update naturally shows up on devices around the release date. Seed build updates are allowed without delay.

    • Delay visibility of software updates: Enter a value from 0-90 days. When the delay expires, users get a notification to update to the earliest version of the OS available when the delay was triggered.

      For example, if a macOS update is available on January 1, and Delay visibility is set to 5 days, then the update isn't shown as an available update. On the sixth day following the release, that update is available, and users can install it.

      This feature applies to:

      • macOS 10.13.4 and newer
  • Block screenshots and screen recording: Device must be enrolled in Apple's Automated Device Enrollment (DEP). Yes prevents users from saving screenshots of the display. It also prevents the Classroom app from observing remote screens. When set to Not configured (default), Intune doesn't change or update this setting. By default, the OS might allow users to capture screenshots, and allows the Classroom app to view remote screens.

    • Disable AirPlay, view screen by Classroom app, and screen sharing: Yes blocks AirPlay, and prevents screen sharing to other devices. It also prevents teachers from using the Classroom app to see their students' screens. When set to Not configured (default), Intune doesn't change or update this setting. By default, the OS might allow teachers to see their students' screens.

      To use this setting, set the Block screenshots and screen recording setting to Not configured (screenshots are allowed).

    • Allow Classroom app to perform AirPlay and view screen without prompting: Yes lets teachers see their students' screens without requiring students to agree. When set to Not configured (default), Intune doesn't change or update this setting. By default, the OS might require students to agree before teachers can see the screens.

      To use this setting, set the Block screenshots and screen recording setting to Not configured (screenshots are allowed).

  • Require teacher permission to leave Classroom app unmanaged classes: Yes forces students enrolled in an unmanaged Classroom course to get teacher approval to leave the course. When set to Not configured (default), Intune doesn't change or update this setting. By default, the OS might allow students to leave the course whenever the student chooses.

  • Allow Classroom to lock the device without prompting: Yes lets teachers lock a student's device or app without the student's approval. When set to Not configured (default), Intune doesn't change or update this setting. By default, the OS might require students agree before teachers can lock the device or app.

  • Students can automatically join Classroom class without prompting: Yes lets students join a class without prompting the teacher. When set to Not configured (default), Intune doesn't change or update this setting. By default, the OS might require teacher approval to join a class.

Password

Settings apply to: All enrollment types

  • Require password: Yes requires users to enter a password to access devices. When set to Not configured (default), Intune doesn't change or update this setting. By default, the OS might not require a password. It also doesn't force any restrictions, such as blocking simple passwords or setting a minimum length.

    • Required password type: Enter the required password complexity level your organization requires. When left blank, Intune doesn't change or update this setting. Your options:

      • Not configured: Uses the device default.
      • Alphanumeric: Includes uppercase letters, lowercase letters, and numeric characters.
      • Numeric: Password must only be numbers, such as 123456789.

      This feature applies to:

      • macOS 10.10.3 and newer
    • Number of non-alphanumeric characters in password: Enter the number of complex characters required in the password, from 0-4. A complex character is a symbol, such as ?. When left blank or set to Not configured, Intune doesn't change or update this setting.

    • Minimum password length: Enter the minimum length the password must have, from 4-16 characters. When left blank, Intune doesn't change or update this setting.

    • Block simple passwords: Yes prevents using simple passwords, such as 0000 or 1234. When the value is blank or set to Not configured, Intune doesn't change or update this setting. By default, the OS might allow simple passwords.

    • Maximum minutes of inactivity until screen locks: Enter the length of time devices must be idle before the screen is automatically locked. For example, enter 5 to lock devices after 5 minutes of being idle. When the value is blank or set to Not configured, Intune doesn't change or update this setting.

    • Maximum minutes after screen lock before password is required: Enter the length of time devices must be inactive before a password is required to unlock it. When the value is blank or set to Not configured, Intune doesn't change or update this setting.

    • Password expiration (days): Enter the number of days until the device password must be changed, from 1-65535. For example, enter 90 to expire the password after 90 days. When the password expires, users are prompted to create a new password. When the value is blank or set to Not configured, Intune doesn't change or update this setting.

    • Prevent reuse of previous passwords: Restrict users from creating previously used passwords. Enter the number of previously used passwords that can't be used, from 1-24. For example, enter 5 so users can't set a new password to their current password or any of their previous four passwords. When the value is blank, Intune doesn't change or update this setting.

  • Block user from modifying passcode: Yes stops the passcode from being changed, added, or removed. When set to Not configured (default), Intune doesn't change or update this setting. By default, the OS might allow passcodes to be added, changed, or removed.

  • Block Touch ID to unlock device: Yes prevents using fingerprints to unlock devices. When set to Not configured https://windowsomg.netlify.app/is-posixspwn-108-the-latest-update-for-el-capitan.html. (default), Intune doesn't change or update this setting. By default, the OS might allow users to unlock the device using a fingerprint.

  • Block password AutoFill: Yes prevents using the AutoFill Passwords feature on macOS. Choosing Yes also has the following impact:

    • Users aren't prompted to use a saved password in Safari or in any apps.
    • Automatic Strong Passwords are disabled, and strong passwords aren't suggested to users.

    When set to Not configured (default), Intune doesn't change or update this setting. By default, the OS might allow these features.

  • Block password proximity requests: Yes prevents devices from requesting passwords from nearby devices. When set to Not configured (default), Intune doesn't change or update this setting. By default, the OS might allow these password requests.

  • Block password sharing: Yes prevents sharing passwords between devices using AirDrop. When set to Not configured (default), Intune doesn't change or update this setting. By default, the OS might allow passwords to be shared.

Privacy preferences

On macOS devices, apps and processes often prompt users to allow or deny access to device features, such as the camera, microphone, calendar, Documents folder, and more. These settings allow administrators to pre-approve or pre-deny access to these device features. When you configure these settings, you manage data access consent on behalf of your users. Your settings override their previous decisions.

The goal of these settings is to reduce the number of prompts by apps and processes.

This feature applies to:

  • macOS 10.14 and newer
  • Some settings apply to macOS 10.15 and newer.
  • These settings only apply on devices that have the privacy preferences profile installed before being upgraded.

Settings apply to: User approved device enrollment, Automated device enrollment

  • Apps and processes: Add apps or processes to configure access. Also enter:
    • Name: Enter a name for your app or process. For example, enter Microsoft Remote Desktop or Microsoft Office 365.

    • Identifier type: Your options:

      • Bundle ID: Select this option for apps.
      • Path: Select this option for non-bundled binaries, which is a process or executable.

      Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing application bundle.

    • Identifier: Enter the app bundle ID, or the installation file path of the process or executable. For example, enter com.contoso.appname.

      To get the app bundle ID, open the Terminal app, and run the codesign command. This command identifies the code signature. So you can get the bundle ID and the code signature simultaneously.

    • Code requirement: Enter the code signature for the application or process.

      A code signature is created when an app or binary is signed by a developer certificate. To find the designation, run the codesign command manually in the Terminal app: codesign --display -r - /path/to/app/binary. The code signature is everything that appears after =>.

    • Enable static code validation: Choose Yes for the app or process to statically validate the code requirement. When set to Not configured, Intune doesn't change or update this setting.

      Enable this setting only if the process invalidates its dynamic code signature. Otherwise, use Not configured.

    • Block Camera: Yes prevents the app from accessing the system camera. You can't allow access to the camera. When set to Not configured, Intune doesn't change or update this setting.

    • Block Microphone: Yes prevents the app from accessing the system microphone. You can't allow access to the microphone. When set to Not configured, Intune doesn't change or update this setting.

    • Block screen recording: Yes blocks the app from capturing the contents of the system display. You can't allow access to screen recording and screen capture. When set to Not configured, Intune doesn't change or update this setting.

      Requires macOS 10.15 and newer.

    • Block input monitoring: Yes blocks the app from using CoreGraphics and HID APIs to listen to CGEvents and HID events from all processes. Yes also denies apps and processes from listening to and collecting data from input devices, such as a mouse, keyboard, or trackpad. You can't allow access to the CoreGraphics and HID APIs.

      When set to Not configured, Intune doesn't change or update this setting.

      Requires macOS 10.15 and newer.

      Instacast for mac yosemite 2017. The slim design, a unique quality of macOS make it one of the most demanded operating system. There are many opinions on Mac computers however the people who have used Mac will always back it. Apple’s macOS computers are one of the best performings and used in the world. Once you start using the Mac computer then you cloud never go back to another computer.

    • Speech recognition: Your options:

      • Not configured: Intune doesn't change or update this setting.
      • Allow: Allows the app to access the system speech recognition, and allows sending speech data to Apple.
      • Block: Prevents the app from accessing the system speech recognition, and prevents sending speech data to Apple.

      Requires macOS 10.15 and newer.

    • Accessibility: Your options:

      • Not configured: Intune doesn't change or update this setting.
      • Allow: Allows the app to access to the system Accessibility app. This app includes closed captions, hover text, and voice control.
      • Block: Prevents the app from accessing the system Accessibility app.
    • Contacts: Your options:

      • Not configured: Intune doesn't change or update this setting.
      • Allow: Allows the app to access contact information managed by the system Contacts app.
      • Block: Prevents the app from accessing this contact information.
    • Calendar: Your options:

      • Not configured: Intune doesn't change or update this setting.
      • Allow: Allows the app to access calendar information managed by the system Calendar app.
      • Block: Prevents the app from accessing this calendar information.
    • Reminders: Your options:

      • Not configured: Intune doesn't change or update this setting.
      • Allow: Allows the app to access reminder information managed by the system Reminders app.
      • Block: Prevents the app from accessing this reminder information.
    • Photos: Your options:

      • Not configured: Intune doesn't change or update this setting.
      • Allow: Allows the app to access the pictures managed by the system Photos app in ~/Pictures/.photoslibrary.
      • Block: Prevents the app from accessing these pictures.
    • Media library: Your options:

      • Not configured: Intune doesn't change or update this setting.
      • Allow: Allows the app to access Apple Music, music and video activity, and the media library.
      • Block: Prevents the app from accessing this media.

      Requires macOS 10.15 and newer.

    • File provider presence: Your options:

      • Not configured: Intune doesn't change or update this setting.
      • Allow: Allows the app to access the File Provider app, and know when users are using files managed by the File Provider. A File Provider app allows other File Provider apps to access the documents and directories stored and managed by the containing app.
      • Block: Prevents the app from accessing the File Provider app.

      Requires macOS 10.15 and newer.

    • Full disk access: Your options:

      • Not configured: Intune doesn't change or update this setting.
      • Allow: Allows the app to access all protected files, including system administration files. Apply this setting with caution.
      • Block: Prevents the app from accessing these protected files.
    • System admin files: Your options:

      • Not configured: Intune doesn't change or update this setting.
      • Allow: Allows the app to access some files used in system administration.
      • Block: Prevents the app from accessing these files.
    • Desktop folder: Your options:

      • Not configured: Intune doesn't change or update this setting.
      • Allow: Allows the app to access files in the user’s Desktop folder.
      • Block: Prevents the app from accessing these files.

      Requires macOS 10.15 and newer.

    • Documents folder: Your options:

      • Not configured: Intune doesn't change or update this setting.
      • Allow: Allows the app to access files in the user’s Documents folder.
      • Block: Prevents the app from accessing these files.

      Requires macOS 10.15 and newer.

    • Downloads folder: Your options:

      • Not configured: Intune doesn't change or update this setting.
      • Allow: Allows the app to access files in the user’s Downloads folder.
      • Block: Prevents the app from accessing these files.

      Requires macOS 10.15 and newer.

    • Network volumes: Your options:

      • Not configured: Intune doesn't change or update this setting.
      • Allow: Allows the app to access files on network volumes.
      • Block: Prevents the app from accessing these files.

      Requires macOS 10.15 and newer.

    • Removable volumes: Your options:

      • Not configured: Intune doesn't change or update this setting.
      • Allow: Allows the app to access files on removable volumes, such as a hard disk.
      • Block: Prevents the app from accessing these files.

      Requires macOS 10.15 and newer.

    • System events: Your options:

      • Not configured: Intune doesn't change or update this setting.
      • Allow: Allows the app to use CoreGraphics APIs to send CGEvents to the system event stream.
      • Block: Prevents the app from using CoreGraphics APIs to send CGEvents to the system event stream.
    • Apple events: This setting allows apps to send a restricted Apple event to another app or process. Select Add to add a receiving app or process. Enter the following information of the receiving app or process:

      • Identifier type: Select Bundle ID if the receiving identifier is an application. Select Path if the receiving identifier is a process or executable.

      • Identifier: Enter the app bundle ID, or the installation path of the process receiving an Apple event.

      • Code requirement: Enter the code signature for the receiving application or process.

        A code signature is created when an app or binary is signed by a developer certificate. To find the designation, run the codesign command manually in the Terminal app: codesign --display -r -/path/to/app/binary. The code signature is everything that appears after =>.

      • Access: Allow a macOS Apple Event to be sent to the receiving app or process. Your options:

        • Not configured: Intune doesn't change or update this setting.
        • Allow: Allows the app or process to send the restricted Apple event to the receiving app or process.
        • Block: Prevents the app or process from sending a restricted Apple event to the receiving app or process.
    • Save your changes.

Restricted apps

Settings apply to: All enrollment types

  • Type of restricted apps list: Create a list of apps that users aren't allowed to install or use. Your options:

    • Not configured (default): Intune doesn't change or update this setting. By default, users might have access to apps you assign, and built-in apps.
    • Approved apps: List the apps that users are allowed to install. To stay compliant, users must not install other apps. Apps that are managed by Intune are automatically allowed, including the Company Portal app. Users aren't prevented from installing an app that isn't on the approved list. But if they do, it's reported in Intune.
    • Prohibited apps: List the apps (not managed by Intune) that users aren't allowed to install and run. Users aren't prevented from installing a prohibited app. If a user installs an app from this list, it's reported in Intune.
  • Apps list: Add apps to your list:

    Download Wacom Bamboo Spark CDS600P Driver For Windows 10/8/7 And Mac Digital drawing And Graphics tablet Free. Bamboo Spark with tablet sleeve, utilizing Wacom's proprietary EMR technology and an integrated self-inking pen. Works with any A5 paper. Select Updates to see what (if any) updates are available for your Wacom product. Important: Your Wacom product must be connected to your computer to see available updates. If updates are available, select the respective link and carefully follow all instructions as you update your driver or product. Wacom does not recommend upgrading to OS 10.11 (“El Capitan”) if using a Cintiq 27QHD or Cintiq 27QHD Touch until an updated driver is released. Wacom expects the driver to be available within one week of Apple’s release of OS 10.11. Wacom continually monitors the compatibility of our products with current operating systems. Wacom bamboo update for el capitan. Download Wacom Bamboo Fun Driver For Windows 10/8/7 And Mac Digital drawing And Graphics tablet Free. Bamboo Fun lets you get hands-on with your creative projects, giving you the benefits of Multi-Touch along with the comfort and precision of Wacom’s ergonomically-designed pen.

    • App Bundle ID: Enter the bundle ID of the app. You can add built-in apps and line-of-business apps. Apple's web site has a list of built-in Apple apps.

      To find the URL of an app, open the iTunes App Store, and search for the app. For example, search for Microsoft Remote Desktop or Microsoft Word. Select the app, and copy the URL. You can also use iTunes to find the app, and then use the Copy Link task to get the app URL.

    • App name: Enter a user-friendly name to help you identify the bundle ID. For example, enter Intune Company Portal app.

    • Publisher: Enter the publisher of the app.

  • Import a CSV file with details about the app, including the URL. Use the <app bundle ID>, <app name>, <app publisher> format. Or, Export to create a list of apps you added, in the same format.

Next steps

Assign the profile and monitor its status.

You can also restrict device features and settings on iOS/iPadOS devices.

-->

Intune lets you manage macOS devices to give users access to company email and apps.

As an Intune admin, you can set up enrollment for company-owned macOS devices and personally owned macOS devices ('bring your own device' or BYOD).

Prerequisites

Complete the following prerequisites before setting up macOS device enrollment:

  • Make sure your device is eligible for Apple device enrollment.
  • Assign user licenses in the Microsoft 365 admin center

User-owned macOS devices (BYOD)

You can let users enroll their own personal devices into Intune management. This is known as 'bring your own device' or BYOD. After you've completed the prerequisites and assigned user licenses, your users can enroll their devices by:

  • Going to the Company Portal website or
  • Downloading the Mac Company Portal app at aka.ms/EnrollMyMac.

You can also send your users a link to online enrollment steps: Enroll your macOS device in Intune.

For information about other end-user tasks, see these articles:

Download Microsoft Intune Company Portal For Macos Download

Company-owned macOS devices

For organizations that purchase devices for their users, Intune supports the following macOS company-owned device enrollment methods:

  • Apple's Automated Device Enrollment (ADE): Organizations can purchase macOS devices through ADE. ADE lets you deploy an enrollment profile 'over the air' to bring devices into management.
  • Device enrollment manager (DEM): You can use a DEM account to enroll up to 1,000 devices.

Block macOS enrollment

By default, Intune lets macOS devices enroll. To block macOS devices from enrollment, see Set device type restrictions.

Enroll virtual macOS machines for testing

Note

macOS virtual machines are only supported for testing. You should not use macOS virtual machines as production devices for your end users.

You can enroll macOS virtual machines for testing using either Parallels Desktop or VMware Fusion.

For Parallels Desktop, you need to set the hardware type and the serial number for the virtual machines so that Intune can recognize them. Follow Parallels' instructions for setting hardware type and serial number to set up the necessary settings for testing. We recommend that you match the hardware type of the device running the virtual machines to the hardware type of the virtual machines that you're creating. You can find this hardware type in Apple menu > About this Mac > System Report > Model Identifier.

For VMware Fusion, you need to edit the .vmx file to set the virtual machine's hardware model and serial number. We recommend that you match the hardware type of the device running the virtual machines to the hardware type of the virtual machines that you're creating. You can find this hardware type in Apple menu > About this Mac > System Report > Model Identifier.

User Approved enrollment

Portal

User Approved MDM enrollment is a type of macOS enrollment that you can use to manage certain security-sensitive settings. For more information, see Apple's support documentation.

As of June 2020, all new macOS MDM enrollments in Intune, including those not done through Automated Device Enrollment (ADE), are considered user approved. The end-user must manually install the management profile in System Preferences > Profiles, and thus provide approval of the management profile. System Preferences is launched automatically from the Company Portal app for BYOD macOS users. Instructions to install the management profile are provided in the Company Portal app.

BYOD macOS MDM enrollments prior to June 2020 may not be user approved if the end-user did not manually provide approval of the management profile in System Preferences > Profiles. For BYOD enrollments after June 2020, the Company Portal app launches System Preferences for the user and the user will need to select Install. If the user did not approve the management profile during enrollment, the user can go to System Preferences > Profiles, choose the management profile, and select Approve to approve the profile at a later point in time.

Find out if a device is User Approved

Intune Company Portal For Mac

  1. Sign in to the Microsoft Endpoint Manager admin center.
  2. Choose Devices > All devices> choose the device > Hardware.
  3. Check the User approved enrollment field.
Download Microsoft Intune Company Portal For Macos

Microsoft Intune Company Portal Sign In

Next steps

After macOS devices are enrolled, you can create custom settings for macOS devices.