Event details

macOS management with Intune continues to evolve, with new capabilities helping organizations deliver more streamlined onboarding, stronger security, and a more complete management experience across Apple devices.

Tune in as Microsoft MVP Ugur Koc guides you through the full journey of managing macOS devices with Intune—showing how the platform continues to expand across enrollment, policy management, security, and day-to-day administration.

You’ll see how to:

  • Connect Apple Business Manager with Intune for streamlined onboarding
  • Configure enrollment profiles and user experiences for macOS devices
  • Apply policies, including security controls like FileVault and firewall
  • Use modern capabilities such as native local admin account management
  • Understand how identity, compliance, and device configuration come together in practice
  • Explore emerging capabilities and what’s next for macOS management

This session is designed for IT admins who want a practical, end-to-end view of macOS management using Intune—with real demos, actionable takeaways, and a clear look at how the experience continues to improve.

How do I participate?

Registration is not required. Add this event to your calendar and select Attend to receive reminders. Post your questions in advance, or any time during the live broadcast.

Stay informed, stay connected 

Bookmark the Microsoft Intune for MSPs resource guide, your home for all things #IntuneForMSPs, for future session dates and resources to help you on your journey. 

Pearl-Angeles
Updated Jun 12, 2026

18 Comments

  • Dorian_Gray's avatar
    Dorian_Gray
    Copper Contributor

    Hi, When Intune will get possibility to use Custom Attributes in dynamic Policy assignment for App policy deployment or script policy deployment?

  • Gabika's avatar
    Gabika
    Copper Contributor

    I have a production ADE profile, and I recently created a new one to test LAPS. The new profile works, but my question is: should I move all my devices to this new ADE profile, or is there a better approach?

    I also set the new profile as the default enrollment profile, but when I wipe a device, it still receives the ADE profile to which it was originally assigned.

    • NickCowley's avatar
      NickCowley
      Copper Contributor

      You will have to manually assign to the new profile as automatic assignment only happens on newly synced devices.

  • Adam_Juelich's avatar
    Adam_Juelich
    Occasional Reader

    IntuneMyMac has the Company Portal install via one of their scripts.  Will this work for ADE with PSSO, or do I need to have it as a LOB App?

    • NickCowley's avatar
      NickCowley
      Copper Contributor

      I deploy via LOB, but either will work.

      Usually via script is a little faster which is why they have it in IntuneMyMac, but personally not seen much difference in install speed and preferer to have visibility of all my apps outside scripts.

  • Ali11CH's avatar
    Ali11CH
    Iron Contributor

    Can you use the setup assistant panes for enrolling shared devices without user affinity? (bigger use case for shared Education devices)

    Can you deploy Apps as available to devices enrolled without user affinity?

  • lalanc01's avatar
    lalanc01
    Iron Contributor

    Hi, Have you been able to enable Platform SSO during ADE enrollment?

    We have tried but we're never able to go past the 'sign in to your organization'

    We enter our creds and it fails.

    We have been using SSO post enrollment without issues for months

    Thks

    • NickCowley's avatar
      NickCowley
      Copper Contributor

      lalanc01​  have a look at his link, useful resource. 


      https://intuneirl.com/psso-just-got-smarter-platform-sso-in-macos-setup-assistant-a-deep-dive/

      If you still have issues ping me and I may be able to help.

    • NickCowley's avatar
      NickCowley
      Copper Contributor

      Have it working with multiple client including registration during setup.

      What are you using secure enclave, password, etc?

  • HeyHey16K's avatar
    HeyHey16K
    Steel Contributor

    Does macOS have a BitLocker To Go equivalent we can manage through Intune? If not, how do we encrypt/manage removable media please?

    • NickCowley's avatar
      NickCowley
      Copper Contributor

      FieVault can automatically be enabled during setup and key held in Intune, you can also set a recovery options key which I would recommend.

      You can use FileVault to encrypt removable media, not sure now it could be done automatically from Intune, but worst case you could use a script.,

  • HeyHey16K's avatar
    HeyHey16K
    Steel Contributor

    Also we have found lots of Intune managed settings for Edge on macOS - but barely anything for Safari. How do we manage Safari settings via Intune please?

    • JF_Rigot's avatar
      JF_Rigot
      Occasional Reader

      Through Settings Catalogs, mostly. More included in DDM (like the Extensions)

    • HeyHey16K's avatar
      HeyHey16K
      Steel Contributor

      We have installed Edge and want our staff to use Edge but Safari is a pre-installed app you cannot remove, so we need to manage safari as well 🙃

  • Welcome, everyone, to our June #IntuneForMSPs community meetup. If you have questions at any time during today's session, please post them here in the comments. We'll have time for Q&A at the end of Ugur's presentation.

  • HeyHey16K's avatar
    HeyHey16K
    Steel Contributor

    We are an entirely Intune managed Windows environment, and just starting our Intune managed macOS journey. Really loving how fast macOS builds (ADE/new PSSO) 🥳. One challenge we're facing is the pre-installed macOS apps cannot be uninstalled (where we can uninstall the Store apps on Windows). Other apps install bypassing elevation (same issue as on Windows - e.g. Chrome, Firefox, Zoom etc.). What is the best way through Intune (or other methods) to prevent apps from installing and running on macOS please (ideally using a blocklist)?