Home

Azure AD and Intune now support macOS in conditional access!

%3CLINGO-SUB%20id%3D%22lingo-sub-100046%22%20slang%3D%22en-US%22%3EAzure%20AD%20and%20Intune%20now%20support%20macOS%20in%20conditional%20access!%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-100046%22%20slang%3D%22en-US%22%3E%3CP%3EConditional%20access%20is%20one%20of%20the%20fastest%20growing%20services%20in%20EMS%2C%20constantly%20getting%20feedback%20from%20customers%20about%20new%20capabilities%20they%20would%20like%20to%20add%20to%20it.%20One%20of%20the%20most%20frequently%20requested%20is%20support%20for%20macOS.%20Customers%20want%20to%20have%20one%20consistent%20system%20for%20securing%20user%20accessing%20to%20Office%20365%20on%20all%20the%20platforms%20their%20employees%20are%20using.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20class%3D%22%22%3ESo%20we're%20excited%20to%20share%20that%20Azure%20Active%20Directory%20and%20Intune%20now%20support%20macOS%20platform%20for%20device-based%20conditional%20access!%20Administrators%20can%20now%20restrict%20access%20to%20Intune-managed%20macOS%20devices%20using%20device-based%20conditional%20access%20according%20to%20their%20organization%E2%80%99s%20security%20guidelines.%3C%2FP%3E%0A%3CP%20class%3D%22%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20class%3D%22%22%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20624px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F19073i6F254F918DA0CA3D%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22082217_2143_AzureADandI2.png%22%20title%3D%22082217_2143_AzureADandI2.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ERead%20more%20about%20it%20in%20the%20%3CA%20href%3D%22https%3A%2F%2Fblogs.technet.microsoft.com%2Fenterprisemobility%2F2017%2F08%2F23%2Fazure-ad-and-intune-now-support-macos-in-conditional-access%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3EEnterprise%20Mobility%20%26amp%3B%20Security%20blog.%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-100046%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAccess%20Management%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EAzure%20AD%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-101200%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20AD%20and%20Intune%20now%20support%20macOS%20in%20conditional%20access!%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-101200%22%20slang%3D%22en-US%22%3E%3CP%3EGood%20catch.%20%26nbsp%3BYes%2C%20you%20need%20a%20certifiacte%20in%20place%20to%20manage%20iOS%20and%20MacOS%20devices.%20%26nbsp%3BThe%20link%20points%20to%20the%20old%20(Silverlight)%20console%2C%20but%20the%20same%20principles%20apply%20to%20the%20new%20Ibiza%20console%20too.%20See%20here%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fintune%2Fapple-mdm-push-certificate-get%26nbsp%3B%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fintune%2Fapple-mdm-push-certificate-get%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-101177%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20AD%20and%20Intune%20now%20support%20macOS%20in%20conditional%20access!%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-101177%22%20slang%3D%22en-US%22%3EYes%20the%20user%20is%20licensed%20with%20EMS.%3CBR%20%2F%3EWhen%20using%20the%20portal%20it%20shows%20be%20an%20error%20This%20service%20is%20not%20supported.%20Error%3A%20AccountNotOnBoarded%3CBR%20%2F%3E%3CBR%20%2F%3EAccording%20to%20this%20article%20it%60s%20an%20certificate%20issue%3A%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fintune-classic%2Ftroubleshoot%2Ftroubleshoot-device-enrollment-in-intune%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fintune-classic%2Ftroubleshoot%2Ftroubleshoot-device-enrollment-in-intune%3C%2FA%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-100897%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20AD%20and%20Intune%20now%20support%20macOS%20in%20conditional%20access!%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-100897%22%20slang%3D%22en-US%22%3E%3CP%3EOK%2C%20so%20device%20enrollment%20requires%20an%20Intune%20license%20-%20is%20the%20user%20that%20is%20attempting%20the%20enrollment%20assigned%20an%20Intune%20license%3F%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAs%20an%20alternate%20to%20the%20Company%20Portal%20App%20-%20can%20you%20login%20in%20to%20the%20Company%20Portal%20site%20(portal.manage.microsoft.com)%3F%20%26nbsp%3BFrom%20here%20you%20can%20also%20attempt%20enrollment%20too.%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-100867%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20AD%20and%20Intune%20now%20support%20macOS%20in%20conditional%20access!%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-100867%22%20slang%3D%22en-US%22%3EI%20have%20downloaded%20the%20portal%20app%2C%20moved%20it%20to%20the%20applications%20folder.%20After%20opening%20en%20loggin%20on%20to%20the%20app%20when%20I%20try%20to%20enroll%20I%20receive%20the%20message%3A%20Couldn%60t%20enroll%20device%3CBR%20%2F%3EYou%20can%20retry%20or%20send%20a%20report%20to%20your%20IT%20admin.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-100801%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20AD%20and%20Intune%20now%20support%20macOS%20in%20conditional%20access!%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-100801%22%20slang%3D%22en-US%22%3E%3CP%3EHey%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F3194%22%20target%3D%22_blank%22%3E%40Peter%20Klapwijk%3C%2FA%3E%26nbsp%3B-%20where%20are%20you%20blocked%3F%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-100747%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20AD%20and%20Intune%20now%20support%20macOS%20in%20conditional%20access!%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-100747%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F41707%22%20target%3D%22_blank%22%3E%40Eric%20Starker%3C%2FA%3E%26nbsp%3BI%20know%20it%60s%20in%20preview%2C%20but%20can%20I%20get%20some%20support%20on%20enrolling%20our%20Mac%3F%3CBR%20%2F%3EWe%20have%20a%20few%20customers%20using%20only%20Mac%20for%20which%20this%20is%20very%20interesting%2C%20but%20we%20need%20to%20be%20able%20to%20demo%20this.%20Thanks%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-100355%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20AD%20and%20Intune%20now%20support%20macOS%20in%20conditional%20access!%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-100355%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F41707%22%20target%3D%22_blank%22%3E%40Eric%20Starker%3C%2FA%3E%26nbsp%3B-%20couldn't%20agree%20more%2C%20conditional%20access%20is%20a%20compelling%20story%20in%20managing%20and%20controlling%20access%20to%20services%20like%20Office%20365.%20Support%20for%20MacOS%20closes%20another%20gap.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F3194%22%20target%3D%22_blank%22%3E%40Peter%20Klapwijk%3C%2FA%3E%26nbsp%3B-%20yes%2C%20I%20also%20played%20with%20this%20during%20private%20preview.%20%26nbsp%3BThe%20actual%20MacOS%20management%20capabilities%20needs%20to%20grow%20more%2C%20but%20heading%20in%20the%20right%20direction.%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-100289%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20AD%20and%20Intune%20now%20support%20macOS%20in%20conditional%20access!%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-100289%22%20slang%3D%22en-US%22%3E%3CP%3E%3CSPAN%3EUnfortunatelly%20our%20Mac%20won%60t%20let%20me%20enroll%20the%20device%20and%20we%20only%20have%20one%20Mac%20to%20test%20on%2C%20we%20are%20all%20Windows%20users%20%3A)%3C%2Fimg%3E%3C%2FSPAN%3E%3CBR%20%2F%3E%3CSPAN%3EBut%20is%20anybody%20succesfull%20of%20enrolling%20their%20device%3F%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E
Community Manager

Conditional access is one of the fastest growing services in EMS, constantly getting feedback from customers about new capabilities they would like to add to it. One of the most frequently requested is support for macOS. Customers want to have one consistent system for securing user accessing to Office 365 on all the platforms their employees are using.

 

So we're excited to share that Azure Active Directory and Intune now support macOS platform for device-based conditional access! Administrators can now restrict access to Intune-managed macOS devices using device-based conditional access according to their organization’s security guidelines.

 

082217_2143_AzureADandI2.png

 

Read more about it in the Enterprise Mobility & Security blog.

 

 

8 Replies

Unfortunatelly our Mac won`t let me enroll the device and we only have one Mac to test on, we are all Windows users :)
But is anybody succesfull of enrolling their device?

@Eric Starker - couldn't agree more, conditional access is a compelling story in managing and controlling access to services like Office 365. Support for MacOS closes another gap. 

 

@Peter Klapwijk - yes, I also played with this during private preview.  The actual MacOS management capabilities needs to grow more, but heading in the right direction. 

@Eric Starker I know it`s in preview, but can I get some support on enrolling our Mac?
We have a few customers using only Mac for which this is very interesting, but we need to be able to demo this. Thanks

Hey @Peter Klapwijk - where are you blocked? 

I have downloaded the portal app, moved it to the applications folder. After opening en loggin on to the app when I try to enroll I receive the message: Couldn`t enroll device
You can retry or send a report to your IT admin.

OK, so device enrollment requires an Intune license - is the user that is attempting the enrollment assigned an Intune license? 

 

As an alternate to the Company Portal App - can you login in to the Company Portal site (portal.manage.microsoft.com)?  From here you can also attempt enrollment too. 

Yes the user is licensed with EMS.
When using the portal it shows be an error This service is not supported. Error: AccountNotOnBoarded

According to this article it`s an certificate issue: https://docs.microsoft.com/en-us/intune-classic/troubleshoot/troubleshoot-device-enrollment-in-intun...

Good catch.  Yes, you need a certifiacte in place to manage iOS and MacOS devices.  The link points to the old (Silverlight) console, but the same principles apply to the new Ibiza console too. See here: https://docs.microsoft.com/en-us/intune/apple-mdm-push-certificate-get 

Related Conversations
Tabs and Dark Mode
cjc2112 in Discussions on
30 Replies
Stable version of Edge insider browser
HotCakeX in Discussions on
35 Replies
flashing a white screen while open new tab
Deleted in Discussions on
14 Replies
How to Prevent Teams from Auto-Launch
chenrylee in Microsoft Teams on
29 Replies