Managing Company Macs with Intune: Enrollment, Platform SSO, Compliance and Conditional Access, and When Jamf Is Still the Answer
A 20–500-seat Microsoft 365 organization with a dozen or a hundred Macs usually asks the same question: can Intune, which we already pay for, manage them properly, or do we need Jamf? For most of them the answer is Intune, if it is set up the Apple way: Apple Business Manager and Automated Device Enrollment, Platform SSO with Entra ID, compliance wired into Conditional Access, and Defender for Endpoint on the Mac. This article covers that setup, where Intune is thinner than Jamf, and the cases where Jamf is still the answer.
What you already own
Intune Plan 1 manages macOS as well as Windows, iOS and Android, and it is included in Microsoft 365 Business Premium and Microsoft 365 E3. Microsoft list prices, September 2026 price list, annual commitment: Microsoft 365 Business Premium $264.00 per user per year ($22.00 per month equivalent); Microsoft 365 E3 $468.00 per year ($39.00 per month); Microsoft Intune Plan 1 on its own $96.00 per year ($8.00 per month). Business Premium also includes Defender for Business; tenants without it add Microsoft Defender for Endpoint P1 at $36.00 per year ($3.00 per month) or P2 at $62.40 per year ($5.20 per month). Our Intune licensing explainer has the full matrix.
On the Apple side you need an Apple Business Manager account, your Macs bought through Apple or an authorized reseller so they appear in it, and an Apple MDM push certificate in Intune. The certificate is valid for 365 days, must be renewed with the same Apple account that created it, and has a 30-day grace period after expiry (Microsoft, May 2025). Put the renewal in a calendar that outlives the person who set it up.
Enrollment: Apple Business Manager and Automated Device Enrollment
Automated Device Enrollment (ADE) is Apple's enrollment method for corporate-owned Macs bought through Apple Business Manager or Apple School Manager; the prerequisites are access to one of them, Intune set as the MDM authority, and the push certificate (Microsoft, April 2026). You link Intune to Apple Business Manager with an enrollment program token, assign Macs to it, and build an enrollment profile.
The profile settings that matter (Microsoft, May 2026):
- User affinity. Choose "Setup Assistant with modern authentication" for personal Macs: the user completes Setup Assistant and signs in to the Company Portal app with Entra credentials before resources are released. Shared or lab Macs enroll without user affinity, and the Company Portal does not run on those.
- Locked enrollment. Set to Yes to remove the System Settings and Terminal options that let a user remove the management profile.
- Await final configuration. Set to Yes to hold the Mac at Setup Assistant until the first policies land, so the user's first desktop is already configured.
- Setup Assistant screens. Skip the ones you do not need.
Macs that are not in Apple Business Manager can still enroll through the Company Portal, with fewer controls. Microsoft Intune Initial Setup for macOS Device Management ($3,950 per project, 2 weeks) does the Apple Business Manager link, the profiles and the first policy set.
Platform SSO with Entra ID
Platform SSO is the piece that makes a Mac a first-class Entra device. It requires macOS 13 or later, Intune Company Portal 5.2404.0 or later, and an Intune enrollment; Microsoft recommends macOS 14 Sonoma for a smooth experience (Microsoft, June 2025 and June 2026). During registration the Mac becomes a Microsoft Entra device that Conditional Access can evaluate, and users get single sign-on to Microsoft 365 and to every application that authenticates with Entra ID.
Three authentication methods are available. Secure Enclave, which Microsoft recommends, provisions a hardware-bound key on the Mac and gives a passwordless, phishing-resistant sign-in comparable to Windows Hello for Business; Touch ID unlocks it. Smart card uses an external card or a hardware token. Password replaces the local account password with the Entra ID password and keeps the two in sync. The passkey rollout order in passkeys and phishing-resistant MFA in Microsoft 365 applies to Macs through the Secure Enclave method.
Two rules from Microsoft's Intune documentation: assign only one SSO policy to a group, and do not target a Platform SSO profile that registers during Setup Assistant at Macs enrolled without user affinity. Platform SSO also supports Kerberos single sign-on to on-premises Active Directory resources for tenants that still have some (Microsoft, June 2025).
Compliance, Conditional Access and Defender
Intune's macOS compliance policy (Microsoft, September 2025) checks System Integrity Protection, minimum and maximum OS version and build, password rules, encryption of data storage (FileVault), the firewall including stealth mode, and Gatekeeper's allowed app sources. Pair the encryption check with a FileVault configuration policy so Macs become compliant on their own rather than through the help desk.
Then wire the result into Conditional Access: require a compliant device for Microsoft 365 apps, in report-only mode for a pilot group first, then enforced. The policy set is in Conditional Access policies every business should have. Once enforced, a Mac that turns off FileVault loses access to mail until it is fixed.
Microsoft Defender for Endpoint on macOS deploys through Intune as an app plus the system extension, network filter and full disk access profiles. The Intune app documentation lists macOS 13 or later and 1 GB of disk space, and notes that Apple prevents Intune from uninstalling Defender once it is on the Mac (Microsoft, April 2024). Microsoft's current support statement is the three most recent major macOS releases, as reported in Microsoft Q&A and search results; verify on Microsoft Learn before you plan around older Macs. Microsoft Defender for Endpoint Deployment for Intune-Managed Devices ($3,500 per project, 15 days) covers Windows and macOS together.
Apps, scripts and updates: where Intune is thinner
Intune's macOS app types are Microsoft 365 Apps and Edge as built-in packages, Apple Volume Purchase apps through Apple Business Manager, line-of-business apps, unmanaged PKG, DMG, and web clips. Unmanaged PKG apps can be up to 8 GB, and pre-install and post-install scripts need the Intune management agent for macOS version 2309.007 or later (Microsoft, April 2026). DMG apps must contain .app bundles, are also limited to 8 GB, and Microsoft advises against bundling unrelated apps in one image (Microsoft, April 2026). Shell scripts run through the same management agent.
What is missing is the catalog. Intune has no native patching of third-party Mac applications, so browsers, creative tools and developer utilities are repackaged and re-uploaded on every release, by you or by community tooling. For macOS updates, Intune uses Apple's declarative device management to set deadlines, as reported in 2026 admin community write-ups; verify what your macOS version supports on Microsoft Learn. In a fleet of twenty Macs on Microsoft apps this is a non-issue; with two hundred Macs and forty applications, it is the reason Jamf exists.
When Jamf is still the answer
Jamf wins on depth: same-day support for new macOS features, a Self Service catalog, patch management for third-party Mac applications, smart groups on any attribute, and a scripting community that has already solved your problem. Education fleets on Apple School Manager, and creative or engineering firms where the Mac is the primary device and runs dozens of Mac-only applications, are Jamf's home ground. Jamf sells per-device subscriptions in tiered plans, billed annually with a minimum device count, as reported by third-party pricing summaries; check with Jamf for current terms.
The two are not exclusive. Intune's device compliance partner integration lets Jamf Pro report each Mac's compliance to Entra ID, so Jamf-managed Macs satisfy the same Conditional Access policies as everything else; Microsoft notes that the older Jamf Conditional Access integration stopped being supported after January 31, 2025, so tenants still on it move to the device compliance method (Microsoft, September 2023). Our rule of thumb: Windows-majority organizations with fewer than about fifty Macs run Intune alone; Mac-majority or education fleets run Jamf with Intune compliance and Entra ID as the identity. Our refreshed guide to running Microsoft 365 on Mac, iPhone and iPad covers the wider Microsoft-and-Apple picture.
Frequently asked questions
Is Intune good enough to manage Macs?
For a Windows-majority organization with a modest Mac count and mostly Microsoft and browser-based apps, yes. The gaps are third-party patching and the depth of macOS-specific configuration.
Do I need Jamf if I have Intune?
Not for the basics. You need Jamf when the Mac is the primary device for most staff, when you run many Mac-only applications that need patching, or in education. You can keep Jamf for management and still use Intune's compliance integration for Conditional Access.
Can Intune enforce FileVault on Macs?
Yes. A configuration policy turns FileVault on, and the compliance policy's encryption check plus Conditional Access keeps unencrypted Macs away from company data.
Does Platform SSO replace binding Macs to Active Directory?
Yes. The Mac registers with Entra ID, the local account is tied to the Entra identity through the Secure Enclave, smart card or password method, and Kerberos SSO covers any on-premises shares that remain.
Which Microsoft 365 license includes Intune for Mac?
Microsoft 365 Business Premium, E3 and E5 include Intune Plan 1, which covers macOS. Business Standard and Office 365 E3 do not; add Intune Plan 1 per user.
Sources
- Microsoft Learn source files on GitHub (MicrosoftDocs/memdocs), opened: "Create an Apple MDM push certificate", ms.date 05/12/2025; "Automated Device Enrollment for macOS" overview, ms.date 04/15/2026; "Set up automated device enrollment for macOS", ms.date 05/18/2026; "Configure Platform SSO for macOS devices", ms.date 06/22/2026; macOS compliance settings reference, ms.date 09/05/2025; "Add an unmanaged macOS PKG app" and "Add a macOS DMG app", ms.date 04/14/2026; "Add Microsoft Defender for Endpoint to macOS devices", ms.date 04/17/2024; "Jamf Pro device compliance with Microsoft Entra ID", ms.date 09/12/2023
- Microsoft Learn source file on GitHub (MicrosoftDocs/entra-docs), opened: "macOS Platform Single Sign-on overview", ms.date 06/12/2025
- Microsoft Learn: Defender for Endpoint on macOS system requirements (three most recent major releases) and Intune macOS software update settings, as reported by Microsoft Q&A and search results on 27 September 2026; not opened; verify on Microsoft Learn
- Jamf pricing model, as reported by third-party pricing summaries in search results on 27 September 2026; not opened; verify with Jamf
- IT Partner blog: content/blog/refreshed Microsoft and Apple in 2026; content/blog/new/intune-licensing-plan-1-vs-plan-2-vs-intune-suite-remote-help-epm.json; passkeys-phishing-resistant-mfa-microsoft-365-rollout-order.json; conditional-access-policies-every-business-should-have.json
- IT Partner pages: content/services/ITPWW710IMPOT, ITPWW080SECOT and ITPWW350MSPRC; Microsoft Intune Plan 1 (CFQ7TTC0LCH4); Microsoft Defender for Endpoint P1 (CFQ7TTC0J1GB)
- IT Partner engineering notes from macOS deployments, September 2026
| Need | Intune | Jamf |
|---|---|---|
| Zero-touch enrollment of new Macs | Yes, through Apple Business Manager and ADE | Yes |
| Entra ID sign-in and Conditional Access | Native, with Platform SSO and compliance | Through the Intune device compliance integration |
| FileVault, firewall, Gatekeeper, OS version compliance | Yes | Yes |
| Microsoft 365 apps, Edge, Defender deployment | Built-in app types | Packaged by you or from Jamf's catalog |
| Third-party Mac app patching | Repackage per release | Built-in patch management |
| Deep macOS configuration, same-day feature support | Partial | Strong |
| Self Service portal for users | Company Portal, basic | Mature |
| Education (Apple School Manager, classroom) | Basic | Strong |
| License cost | Included in Business Premium and E3 | Separate per-device subscription; check Jamf |
Key takeaways
- Intune Plan 1, included in Business Premium and E3, manages Macs; the Apple side needs Apple Business Manager and a push certificate renewed every 365 days with the same Apple account.
- Enroll with Automated Device Enrollment and Setup Assistant with modern authentication, locked enrollment on, await final configuration on.
- Platform SSO (macOS 13 or later, Company Portal 5.2404.0 or later) makes the Mac an Entra device; choose the Secure Enclave method for passwordless, phishing-resistant sign-in.
- Compliance checks FileVault, firewall, Gatekeeper, SIP and OS version; Conditional Access enforces them, and Defender for Endpoint deploys through Intune.
- Jamf still wins for third-party patching, deep macOS configuration, Self Service and education; it can coexist with Intune through the device compliance integration.
If you want the Apple Business Manager link, the enrollment profiles, Platform SSO, compliance and the first policy set built properly, Microsoft Intune Initial Setup for macOS Device Management is $3,950 per project over 2 weeks, fixed price, paid after approval. Add Microsoft Defender for Endpoint Deployment for Intune-Managed Devices ($3,500 per project, 15 days) for the Defender rollout across Macs and PCs, and the Managed Microsoft Intune Service ($5 per device, monthly) if nobody in-house will keep the policies and the push certificate current. Book a call with your Mac count and app list and we will tell you honestly whether Intune or Jamf fits.
Questions this article didn’t answer?
Thirty minutes with Mike — our CEO, not a sales rep. Bring the hard version of the question.