Modern macOS management with Microsoft Intune

For many organizations, a mixed IT environment with both Windows and macOS is a daily reality. Whereas managing Apple devices used to require a separate solution such as Jamf, Microsoft Intune now offers powerful, integrated capabilities to fully and securely manage the Mac fleet as well. In this blog, we dive deeper into modern macOS management with Intune and how we apply it, with a focus on access management, device management, security, policy, patch management, and network configuration.

Access management: Controlled access on macOS

The core of a secure workplace is ensuring that only the right people, on approved devices, have access to organizational data. Intune manages this for macOS with a combination of identity and device status.

Conditional Access, a feature of Microsoft Entra ID, allows you to set rules that, for example, enforce that a user can only access Microsoft 365 applications if they log in from a macOS device that is managed by Intune and marked as ‘compliant’.

An important development is Platform Single Sign-On (PSSO) based on Secure Enclave. This modern approach ensures a seamless login experience. Users log in to their Mac, and Platform SSO ensures that they can easily access applications and websites, completely password-free and integrated with Microsoft Entra ID. This not only increases ease of use but also security, as this method is phishing-resistant. And with macOS 26 (Tahoe), you can even enforce Platform SSO immediately during deployment, register it, and the account will be created automatically.

Device management: From deployment to decommissioning

Intune offers a complete device lifecycle for macOS, starting with enrollment.

Automated Device Enrollment is the standard deployment of Apple devices owned by the organization. By linking Intune to Apple Business Manager, new Macs are automatically enrolled in Microsoft Intune right out of the box. This ensures zero-touch deployment, whereby the Mac is managed and immediately receives the correct configurations and apps, without IT having to physically handle the device. With developments from Root3, we ensure that this runs smoothly and is presented to the user.

For Bring Your Own Device (BYOD) scenarios, there is User Enrollment via the Intune Company Portal app. Users log in to their personal Mac with their Microsoft Entra ID account, after which Intune can separate work and private use, while the organization retains control over business data.

The devices are mainly configured via the Settings Catalog. This is the modern and recommended method for managing thousands of macOS settings, from passcode, FileVault, automatic software updates to complex system preferences. It offers a clear way to build configurations.

Microsoft Intune also supports some of Apple’s Declarative Device Management features, sometimes referred to as MDM 2.0. Examples include password policies and enforcing macOS software updates, whereby the device autonomously applies these settings when necessary. This is only a small part of what is technically possible. In our opinion, there is still much to be gained in the field of Declarative Device Management for many MDM solutions, given the many technical possibilities that Apple offers.

In addition, Microsoft Intune also offers the option of automatically decommissioning devices that have been inactive for a long time. This ensures a cleaner Intune environment and can be set per device category.

Security: Protecting the Mac

A Mac is a very secure platform in itself, but within organizations, additional, enforced security layers are often essential. Microsoft Intune provides the tools to further secure macOS and apply policies.

Through the security policy in Microsoft Intune, you can centrally enforce core macOS technologies:

  • FileVault: Encrypting the entire storage is often a basic requirement. Microsoft Intune can not only enforce encryption, but also securely store the recovery key (escrow), so that IT can help if the user no longer knows the Mac password or is locked out.
  • Gatekeeper: This enforces that users can only install software from the Mac App Store and/or identified developers, which significantly reduces the risk of malware.
  • Firewall: The built-in application firewall of macOS can be centrally configured and enabled to block unwanted incoming network connections.

CIS Benchmarks
The Center for Internet Security (CIS) Benchmarks are recognized worldwide as a set of best-practice configuration guidelines for securing systems. For macOS, these benchmarks provide detailed, expert-developed recommendations. They are divided into two levels:

  • Level 1: Basic security recommendations that do not or hardly hinder the functionality of the device.
  • Level 2: Recommendations for environments with higher security requirements, which may come at the expense of some user flexibility.

We recommend that you always evaluate these benchmarks carefully and choose the appropriate measures that suit your organization and risks. This often results in certain exceptions and additions to the CIS Benchmark.

Policy: Defining and enforcing rules

Policy forms the bridge between organizational rules and the technical configuration on the device. In Microsoft Intune for macOS, this mainly revolves around two types of policy.

1. Compliance Policies: These policies define the minimum security standard that a Mac must meet in order to access organizational data. You can set rules such as:

  • Minimum operating system version.
  • FileVault encryption must be enabled.
  • A password must be set.
  • System Integrity Protection (SIP) must be active.
  • The threat level, reported by Defender for Endpoint, must be ‘low’ or ‘medium’.

A Mac that does not comply will be marked as ‘non-compliant’ and may be denied access.

2. Configuration Policies: As mentioned earlier, this is largely managed through the Settings Catalog. This allows you to configure the user experience and functional aspects of the device. An important modern development, as mentioned earlier, is Declarative Device Management (DDM). With DDM, the Mac can manage updates and configurations more proactively, leading to faster and more reliable policy enforcement, especially for software updates.

Patch management

Keeping third-party apps up to date presents a number of challenges and limitations. The number of built-in app titles is limited to a few Microsoft apps, which means you have to package and distribute the app yourself, every time, which is very time-consuming. There are a number of products on the market for this purpose. We respond to this with App Catalog, optimized for Microsoft Intune and supporting the automatic installation and updating of more than 1,500 apps. No packages, daily automatic updates, and an alternative or supplement to the Intune Company Portal app for users to download apps. Want to know more about App Catalog? Visit App Catalog.

Network: Seamless and secure connectivity

Finally, Microsoft Intune facilitates the configuration of network connections on macOS devices, which is essential for both productivity and security.

You can create and distribute Wi-Fi profiles that contain all the necessary information (SSID, security type such as WPA2/WPA 3-Enterprise) and even include the required authentication certificate. This means that when an employee walks into an office, their Mac automatically and securely connects to the organization’s network without any manual actions.

The same applies to VPN profiles. You can pre-configure the connection details for various VPN protocols, including the server addresses and authentication method (such as certificate-based authentication). This ensures that remote connections always run through a secure tunnel that complies with organizational standards.

Support

We understand the complexity of a modern IT environment. That’s why we specialize in the seamless management of macOS within a Microsoft environment. Whether you’re starting to integrate your Apple products into Intune, need help with advanced configurations, or are looking for support in optimizing your security policy, we’re here to help.