Onboard and offboard macOS devices into Microsoft Purview solutions using Intune
Note
Microsoft 365 compliance is now called Microsoft Purview and the solutions within the compliance area have been rebranded. For more information about Microsoft Purview, see the blog announcement and the What is Microsoft Purview? article.
You can use Intune to onboard macOS devices into Microsoft Purview solutions.
Important
Use this procedure if you do not have Microsoft Defender for Endpoint (MDE) deployed to your macOS devices
Applies to:
Before you begin
- Make sure your macOS devices are onboarded into Intune and are enrolled in the Company Portal app.
- Make sure you have access to the Microsoft Endpoint Manager center.
- This supports macOS version Catalina 10.15 and higher.
- Create the user groups that you are going to assign the configuration updates to.
- Install the v95+ Edge browser on your macOS devices
Onboard macOS devices into Microsoft Purview solutions using Microsoft Intune
Onboarding a macOS device into Compliance solutions is a six phase process.
- Create system configuration profiles
- Get the device onboarding package
- Deploy the onboarding package
- Enable system extension
- Get the installation package
- Deploy the installation package
Create system configuration profiles
- You'll need these files for this procedure.
file needed for | source |
---|---|
Onboarding package | downloaded from the compliance portal Onboarding package, file name DeviceComplianceOnboarding.xml |
accessibility | accessibility.mobileconfig |
full disk access | fulldisk.mobileconfig |
Network filer | netfilter.mobileconfig] |
System extensions | sysext.mobileconfig |
MDE preference | com.microsoft.wdav.mobileconfig |
MAU preference | com.microsoft.autoupdate2.mobileconfig |
Installation package | downloaded from the compliance portal Installation package, file name *wdav.pkg* |
Tip
You can download the .mobileconfig files individually or in single combined file that contains:
- accessibility.mobileconfig
- fulldisk.mobileconfig
- netfilter.mobileconfig
- system extensions
If any of these individual files is updated, you'd need to download the either the combined file again or the single updated file individually.
Open the Microsoft Endpoint Manager center > Devices > Configuration profiles.
Choose: Create profile
Choose:
- Platform = macOS
- Profile type = Templates
- Template name = Custom
Choose Create
Choose a name for the profile, like AccessibilityformacOS in this example. Choose Next.
Choose the accessibility.mobileconfig file that you downloaded in step 1 as the configuration profile file.
Choose Next
On the Assignments tab add the group you want to deploy these configurations to and choose Next.
Review your settings and choose Create to deploy the configuration.
Repeat steps 3-11 to create profiles for the:
- fulldisk.mobileconfig file
- com.microsoft.autoupdate2.xml file
- MDE preferences com.microsoft.wdav.xml file
- set Antivirus engine
passive mode
=true
orfalse
. Usetrue
if deploying DLP only. Usefalse
or do not assign a value if deploying DLP and Microsoft Defender for Endpoint (MDE).
- set Antivirus engine
- netfilter.mobileconfig
Open Devices > Configuration profiles, you should see your created profiles there.
In the Configuration profiles page, choose the profile that you just created, in this example AccessibilityformacOS and choose Device status to see a list of devices and the deployment status of the configuration profile.
Get the device onboarding package
In Compliance center open Settings > Device Onboarding and choose Onboarding.
For Select operating system to start onboarding process choose macOS.
For Deployment method choose Mobile Device Management/Microsoft Intune.
Choose Download onboarding package. This contains the onboarding code in the DeviceComplianceOnboarding.xml file.
Deploy the onboarding package
Open the Microsoft Endpoint Manager center > Devices > Configuration profiles.
Choose: Create profile.
Choose:
- Platform = macOS
- Profile type = Templates
- Template name = Custom
Choose Create
Choose a name for the profile, like OnboardingPackage in this example. Choose Next.
Choose the DeviceComplianceOnboarding.xml file as the configuration profile file.
Choose Next
On the Assignments tab add the group you want to deploy these configurations to and choose Next.
Review your settings and choose Create to deploy the configuration.
Enable system extension
In the Microsoft Endpoint Manager center select Create Profile under Configuration Profiles
Choose:
- Platform = macOS
- Profile type = Templates
- Template name = Extensions
Choose Create
In the Basics tab, give this new profile a name.
In the Configuration settings tab expand System Extensions.
Under Bundle identifier and Team identifier, set these values
Bundle identifier | Team identifier |
---|---|
com.microsoft.wdav.epsext | UBF8T346G9 |
com.microsoft.wdav.netext | UBF8T346G9 |
On the Assignments tab add the group you want to deploy these configurations to and choose Next.
Choose Next to deploy the configuration.
Get the installation package
In Compliance center open Settings > Device Onboarding and choose Onboarding.
For Select operating system to start onboarding process choose macOS
For Deployment method choose Mobile Device Management/Microsoft Intune
Choose Download installation package. This will give you the wdav.pkg file.
Important
Before you can deploy the wdav.pkg. package via Intune, it must be reformatted using the Intune App Wrapping Tools for Mac into the wdav.pkg.intunemac format.
Deploy the Microsoft DLP installation package
- Follow the procedures in How to add macOS line-of-business (LOB) apps to Microsoft Intune to convert the wdav.pkg file into the proper format and deploy it through Intune.
Offboard macOS devices using Intune
Note
Offboarding causes the device to stop sending sensor data to the portal but data from the device, including reference to any alerts it has had will be retained for up to six months.
In Microsoft Endpoint Manager center, open Devices > Configuration profiles, you should see your created profiles there.
In the Configuration profiles page, choose the wdav.pkg.intunemac profile.
Choose Device status to see a list of devices and the deployment status of the configuration profile
Open Properties and Assignments
Remove the group from the assignment. This will uninstall the wdav.pkg.intunemac package and offboard the macOS device from Compliance solutions.
Feedback
Submit and view feedback for