Hey,
In uservoice Intune multiple request are there with the question to implement AAD SSO logon in MacOS without the user is requested to create a local administrator account, now every corp. users end-up with a unique admin account in place of a standard account on his MacOS device. Compare with Airwath there's no prestaging config available in the enrollment profile in Intune, means de local user cannot be created BEFORE AAD logon. Please extend the options available in the enrollment profile! (Example: Await Configuration / Auto Advanced Setup / primary Account Creation / Admin account creation).
Uservoice:
https://microsoftintune.uservoice.com/forums/291681-ideas/suggestions/37913248-macos-azuread-password-sync-for-enrolled-macs
https://microsoftintune.uservoice.com/forums/291681-ideas/suggestions/43603650-support-for-macos-auto-advance-in-enrollment-profi
https://microsoftintune.uservoice.com/forums/291681-ideas/suggestions/39792439-macos-create-standard-vs-administrator-user-plu
Regards,
Geert