macOS Management with Microsoft Intune
Managing macOS with Intune: Apple Business Manager, APNs, automated device enrollment and configuration profiles, including PPPC for Full Disk Access, Accessibility and Screen Recording.
- Status: In progress
- Lab project
- Concept
Overview
- Apple Business ManagerDevices assigned to MDM server
- APNs certificateRenewed yearly, same Apple ID
- Intune ADE tokenEnrollment profile
- macOS deviceSetup Assistant → enrolled
- Configuration profilesPPPC, settings, apps
Privacy permissions (PPPC / TCC)
Remote support and security tools need macOS privacy permissions. A Privacy Preferences Policy Control profile can pre-approve some of them, but not all:
- Full Disk Access
- SystemPolicyAllFiles — can be allowed by MDM
- Accessibility
- Accessibility — can be allowed by MDM
- Screen Recording
- ScreenCapture — MDM cannot grant it; it can only let a standard user approve it (AllowStandardUserToSetSystemService) or deny it
codesign -dr - /Applications/ExampleApp.app
# Copy the "designated =>" value into CodeRequirementTroubleshooting
- Check the profile landed: System Settings → Privacy & Security → Profiles.
- Identifier and CodeRequirement must match the signed binary exactly — including helper apps.
- Inspect TCC decisions: log stream --predicate 'subsystem == "com.apple.TCC"'
- An expired APNs certificate stops all Apple device management — track the renewal date.
Lessons learned
To be written.