Event details
macOS management with Intune continues to evolve, with new capabilities helping organizations deliver more streamlined onboarding, stronger security, and a more complete management experience across Apple devices.
Tune in as Microsoft MVP Ugur Koc guides you through the full journey of managing macOS devices with Intune—showing how the platform continues to expand across enrollment, policy management, security, and day-to-day administration.
You’ll see how to:
- Connect Apple Business Manager with Intune for streamlined onboarding
- Configure enrollment profiles and user experiences for macOS devices
- Apply policies, including security controls like FileVault and firewall
- Use modern capabilities such as native local admin account management
- Understand how identity, compliance, and device configuration come together in practice
- Explore emerging capabilities and what’s next for macOS management
This session is designed for IT admins who want a practical, end-to-end view of macOS management using Intune—with real demos, actionable takeaways, and a clear look at how the experience continues to improve.
How do I participate?
Registration is not required. Add this event to your calendar and select Attend to receive reminders. Post your questions in advance, or any time during the live broadcast.
Stay informed, stay connected
Bookmark the Microsoft Intune for MSPs resource guide, your home for all things #IntuneForMSPs, for future session dates and resources to help you on your journey.
21 Comments
- Pearl-Angeles
Community Manager
Thank you everyone for your participation in this session! Sharing the questions covered during the live Q&A, along with associated timestamps:
Question – There are a lot of preinstalled apps, macOS, basic apps, etc., How do we keep these from running in a professional environment when you’re managing these with Intune? – answered at 45:54.
Question – One aspect of Platform Single Sign-on (SSO) that is not equivalent on the Mac side is authorization groups. What would you tell an admin who misses or is looking for the same kind of functionality as authorization groups? – answered at 48:03.
Question – Does macOS has a BitLocker To Go equivalent that we can manage through Intune? – answered at 49:20.
Question – Can you use the Setup Assistant panes in the Setup Assistant screen for enrolling a shared device without user affinity? – answered at 50:12.
Question – AirDrop could create some data leak possibilities – have you any experience with controlling or limiting access to AirDrop? – answered at 51:42.
Question – Intune My Mac has a Company Portal install via script. Will this work for automatic device enrollment with Platform SSO, or does it need to be a line-of-business apps? – answered at 52:12.
Question – What are the main differences in enrollment for a corporate-owned versus a BYOD mac? – answered at 53:44.
Question – When should an admin use user affinity versus device affinity? – answered at 54:54. - HeyHey16KSteel Contributor
Thank you guys! 👏
- Dorian_GrayCopper Contributor
Hi, When Intune will get possibility to use Custom Attributes in dynamic Policy assignment for App policy deployment or script policy deployment?
- GabikaCopper Contributor
I have a production ADE profile, and I recently created a new one to test LAPS. The new profile works, but my question is: should I move all my devices to this new ADE profile, or is there a better approach?
I also set the new profile as the default enrollment profile, but when I wipe a device, it still receives the ADE profile to which it was originally assigned.
- NickCowleyCopper Contributor
You will have to manually assign to the new profile as automatic assignment only happens on newly synced devices.
- Adam_JuelichTin Contributor
IntuneMyMac has the Company Portal install via one of their scripts. Will this work for ADE with PSSO, or do I need to have it as a LOB App?
- NickCowleyCopper Contributor
I deploy via LOB, but either will work.
Usually via script is a little faster which is why they have it in IntuneMyMac, but personally not seen much difference in install speed and preferer to have visibility of all my apps outside scripts.
- Ali11CHIron Contributor
Can you use the setup assistant panes for enrolling shared devices without user affinity? (bigger use case for shared Education devices)
Can you deploy Apps as available to devices enrolled without user affinity?- Pearl-Angeles
Community Manager
Thanks for your questions! These were covered at around 50:12 during live Q&A.
- lalanc01Iron Contributor
Hi, Have you been able to enable Platform SSO during ADE enrollment?
We have tried but we're never able to go past the 'sign in to your organization'
We enter our creds and it fails.
We have been using SSO post enrollment without issues for months
Thks- NickCowleyCopper Contributor
lalanc01 have a look at his link, useful resource.
https://intuneirl.com/psso-just-got-smarter-platform-sso-in-macos-setup-assistant-a-deep-dive/
If you still have issues ping me and I may be able to help. - NickCowleyCopper Contributor
Have it working with multiple client including registration during setup.
What are you using secure enclave, password, etc?
- HeyHey16KSteel Contributor
Does macOS have a BitLocker To Go equivalent we can manage through Intune? If not, how do we encrypt/manage removable media please?
- Pearl-Angeles
Community Manager
This was covered around 49:20 during live Q&A.
- NickCowleyCopper Contributor
FieVault can automatically be enabled during setup and key held in Intune, you can also set a recovery options key which I would recommend.
You can use FileVault to encrypt removable media, not sure now it could be done automatically from Intune, but worst case you could use a script.,- HeyHey16KSteel Contributor
Thank you Nick 🙏
- HeyHey16KSteel Contributor
Also we have found lots of Intune managed settings for Edge on macOS - but barely anything for Safari. How do we manage Safari settings via Intune please?
- Heather_Poulsen
Community Manager
Welcome, everyone, to our June #IntuneForMSPs community meetup. If you have questions at any time during today's session, please post them here in the comments. We'll have time for Q&A at the end of Ugur's presentation.