macOS Management with Microsoft Intune

Managing macOS with Intune: Apple Business Manager, APNs, automated device enrollment and configuration profiles, including PPPC for Full Disk Access, Accessibility and Screen Recording.

  • Status: In progress
  • Lab project
  • Concept

Overview

  1. Apple Business ManagerDevices assigned to MDM server
  2. APNs certificateRenewed yearly, same Apple ID
  3. Intune ADE tokenEnrollment profile
  4. macOS deviceSetup Assistant → enrolled
  5. Configuration profilesPPPC, settings, apps

Privacy permissions (PPPC / TCC)

Remote support and security tools need macOS privacy permissions. A Privacy Preferences Policy Control profile can pre-approve some of them, but not all:

Full Disk Access
SystemPolicyAllFiles — can be allowed by MDM
Accessibility
Accessibility — can be allowed by MDM
Screen Recording
ScreenCapture — MDM cannot grant it; it can only let a standard user approve it (AllowStandardUserToSetSystemService) or deny it
bash
codesign -dr - /Applications/ExampleApp.app
# Copy the "designated =>" value into CodeRequirement
Getting the code requirement for a PPPC entry

Troubleshooting

  • Check the profile landed: System Settings → Privacy & Security → Profiles.
  • Identifier and CodeRequirement must match the signed binary exactly — including helper apps.
  • Inspect TCC decisions: log stream --predicate 'subsystem == "com.apple.TCC"'
  • An expired APNs certificate stops all Apple device management — track the renewal date.

Lessons learned

To be written.

Back to all projects