Event banner
AMA: Securely manage iOS/iPadOS and macOS endpoints with Intune
Event details
Let’s chat about the latest and greatest in Intune Apple device management! With the introduction of Just-In-Time (JIT) functionality, your users will be able to enjoy a more seamless onboarding experience on bring your own device (BYOD) scenarios. The iOS Company Portal app will no longer be required for Azure AD registration and allow you to move towards a web-based device enrollment flow for BYOD scenarios. Similarly, the updated Account-Driven User Enrollment flow enables faster user enrollment for BYOD scenarios utilizing JIT registration without requiring the iOS Company Portal app. We are streamlining DMG app deployments and reducing vulnerabilities in your Mac environment by keeping macOS devices updated with the latest software updates. We are bringing the ability to use your Azure AD password to log in to your Intune-managed Macs.
Have questions? We’re here to answer them! Ask Microsoft Anything!
Post your questions in the Comments below. We'll have experts responding in the live stream and others in chat. |
This AMA is part of a Microsoft Intune edition of Tech Community Live. Visit https://aka.ms/TCL/Intune for the full agenda.
95 Comments
- deetsCopper ContributorInTune macOS application deployment is rather basic, are there any plans to integrate Munki into intune for better application deployment, akin to SimpleMDMs Munki integration
- Char_CheesmanBronze Contributor
Thanks for participating in today's AMA on Securely manage iOS/iPadOS and macOS endpoints with Intune! For reference, the panel covered this topic at around 24:00.
- Martin_HarrisOccasional ReaderI second this. The native DMG installer was welcome, but not being able to offer available was a deal breaker. We only really use intune for VPP apps. Scripts and Munki for the rest.
- CiscoC80AZCopper ContributoriOS question. Device affinity based enrollment devices do not pass device information into Azure and trigger CA policies even when using device filtering because the device information does not come in as it is checking the user's device azure id. We would like to bypass CA needs for device affinity enrolled devices.
- John_Moore2020Copper ContributorOneDrive Sync Client on Mac. In a Jamf Pro managed Mac with Jamf Connect configured with Azure AD as the IdP, are there any options to auto sign in to the OneDrive sync client utilising the Jamf Connect keychain?
- tushardeorukhkarCopper ContributorWe have noticed so many times, where an we are not able to enroll a device at remote management stage. As the remote management page does not shows up. What could be the possible issue and how to resolve this.
- CiscoC80AZCopper ContributoriOS question, Will we be seeing better integration with Intune and Azure. Currently Azure MFA is problematic when using ADE enrollment. CA should allow us to exclude ADE devices, but Azure is unable to see device information prior to enrollment forcing MFA. It would be nice to allow MFA on personal enrollment, and no MFA on corporate/ADE devices.
- Char_CheesmanBronze Contributor
Thanks for participating in today's AMA on Securely manage iOS/iPadOS and macOS endpoints with Intune! For reference, the panel covered this topic at around 15:30.
- mohaa98Brass ContributorIs there plans to improve Company portal deployed to Macs? Seems that most of the time when using to sync or install applications I get errors and even sometimes it doesn't detect that the device is managed.. Just seems to be buggy.
- dcruickshankBrass ContributorDoes Intune Mac support have connectors to other MDM solutions such as Kandji?
- benjamin_flamm
Microsoft
Yes, there's a list of device compliance partners here: https://learn.microsoft.com/en-us/mem/intune/protect/device-compliance-partners#supported-device-compliance-partners
- Manjit-BCopper ContributorWhen can we pass parameters with pkg deployment in InTune ?
- KarolosKoenOccasional ReaderIs it possible to have self enrolled iOS (private) devices make use of a work profile, such that a user could have the same application installed twice. One that is managed by us and part of the work profile and one that the user could use privately?
- raydomingueCopper Contributor
Back in Q4-2022 there was mention of moving to iOS ADE enrollments as the new standard. Then at some point in Q1 this was put on hold. Is this on hold permanently? Is Microsoft still moving towards this enrollment? Can you talk about when we should expect to see this as a "go" for all to start using? (As I understand it that this will be the new standard for iOS-AppleDEP enrollments).
- AnyaNovicheva
Microsoft
Thank you for your question! There is no specific timeline for moving away from the automatic deployment of the Company Portal app from iOS/iPadOS ADE enrollment policies, but we are moving towards that. Please keep an eye out for updates to that exact blog, and Intune's In development documentation for updates (https://learn.microsoft.com/en-us/mem/intune/fundamentals/in-development). We are currently working towards different improvements in the iOS/iPadOS ADE space, and removing that automatic Company Portal deployment is part of that. Any timelines will be posted with substantial time for you to make changes in your organization.