Add macOS kernel extensions in Intune
On macOS devices, you can add features at the kernel-level. These features access parts of the OS that regular programs can't access. Your organization may have specific needs or requirements that aren't available in an app, a device feature, and so on.
To add kernel extensions that are always allowed to load on your devices, add "kernel extensions" (KEXT) in Microsoft Intune, and then deploy these extensions to your devices.
For example, you have a virus scanning program that scans your device for malicious content. You can add this virus scanning program's kernel extension as an allowed kernel extension in Intune. Then, "assign" the extension to your macOS devices.
With this feature, administrators can allow users to override kernel extensions, add team identifiers, and add specific kernel extensions in Intune.
This feature applies to:
- macOS 10.13.2 and later
To use this feature, devices must be:
Enrolled in Intune using Apple's Device Enrollment Program (DEP). Automatically enroll macOS devices has more information.
Enrolled in Intune with "user approved enrollment" (Apple's term). Prepare for changes to kernel extensions in macOS High Sierra (opens Apple's web site) has more information.
Intune uses "configuration profiles" to create and customize these settings for your organization's needs. After you add these features in a profile, you can then push or deploy the profile to macOS devices in your organization.
This article shows you how to create a device configuration profile using kernel extensions in Intune.
For more information on kernel extensions, see kernel extension overview (opens Apple's web site).
What you need to know
- Unsigned legacy kernel extensions can be added.
- Be sure to enter the correct team identifier and bundle ID of the kernel extension. Intune doesn't validate the values you enter. If you enter wrong information, the extension won't work on the device.
Apple released information regarding signing and notarization for all software. On macOS 10.14.5 and newer, kernel extensions deployed through Intune don't have to meet Apple's notarization policy.
For information on this notarization policy, and any updates or changes, see the following resources:
- Notarizing your app before distribution (opens Apple's web site)
- Prepare for changes to kernel extensions in macOS High Sierra (opens Apple's web site)
Create the profile
Sign in to the Microsoft Endpoint Manager Admin Center.
Select Devices > Configuration profiles > Create profile.
Enter the following properties:
Name: Enter a descriptive name for the new profile.
Description: Enter a description for the profile. This setting is optional, but recommended.
Platform: Select macOS
Profile type: Select Extensions.
Settings: Enter the settings you want to configure. For a list of all settings, and what they do, see:
When you're done, select OK > Create to save your changes.