First page of Microsoft's 100,000-partner directory, sorted by responsiveness Microsoft Solutions Partner — Security, Modern Work, Infrastructure, App Innovation Microsoft partner since 2006 1,100+ organizations under management
Home/Services/Microsoft Intune Initial Setup for macOS Device Management
Implementation

Microsoft Intune Initial Setup for macOS Device Management

Microsoft Intune Initial Setup for macOS Device Management is a two-week, fixed-fee add-on that extends your Intune tenant to corporate-owned Macs. IT Partner configures the Apple trust connections — MDM push certificate, Automated Device Enrollment token, and Apps and Books token — under client-owned accounts, designs the enrollment and Microsoft Entra ID authentication experience including Platform SSO, builds baseline compliance and configuration policies with FileVault encryption and escrowed recovery keys plus a managed software-update policy, deploys managed applications including Microsoft Defender for Endpoint onboarding for the pilot where licensed, and proves it all on up to five pilot Macs. Windows is covered by Microsoft Intune Initial Setup for Windows Device Management; iPhone and iPad by Microsoft Intune Initial Setup for iPhone & iPad Management; Android by Microsoft Intune Initial Setup for Android Device Management.

Timeline 2 weeksService owner Roman SotnikOffice 365microsoft 365

What this engagement is

Macs sit in most executive, creative, and developer teams — and in many Microsoft-cloud organizations they are the last unmanaged devices: no enforced encryption, no update policy, no compliance signal, and a password that has nothing to do with the user's Microsoft Entra identity. macOS management runs on the same Apple trust relationships as iPhone and iPad — an MDM push certificate, an Automated Device Enrollment token, and an Apps and Books token, each tied to an Apple account on its own renewal clock — plus decisions that are unique to the Mac: how the local account relates to Microsoft Entra ID, how FileVault recovery keys are escrowed, and how updates are enforced on a machine users treat as their own. This add-on extends your Intune tenant to corporate-owned Macs. The standard design uses Apple Business Manager with Automated Device Enrollment for supervised, user-affinity Macs: IT Partner configures the Apple connections under client-owned accounts, one enrollment profile with the Setup Assistant authentication experience selected for your fleet, Platform SSO with Microsoft Entra ID per the approved design, FileVault enforcement with recovery-key escrow to Intune, one baseline compliance policy and one baseline configuration profile, a managed software-update policy, and managed application deployment — including Microsoft Defender for Endpoint onboarding for the pilot Macs where you hold the licensing — validated end to end on up to five pilot devices. Who this is for: US commercial organizations of roughly 100–500 seats on the Microsoft cloud with corporate-owned Macs alongside their Windows fleet — the mixed-fleet reality of most SMB executive and creative teams. Who it is not for: personally owned Macs (a different privacy and enrollment design), shared-lab and classroom estates, and migrations off Jamf or another Mac MDM — each available as separately scoped work on this same foundation. The two-week schedule is elapsed calendar time paced by Apple Business Manager processing and client dependencies. The engagement covers one Intune tenant and one standard enrollment scenario; additional scenarios extend this foundation as separately scoped work.

Success criteria

01The Apple MDM push certificate is active in Intune, was created with a client-controlled organizational Apple account, and has a documented owner and renewal procedure.
02The Apple Business Manager Automated Device Enrollment token is active, assigned Macs synchronize to Intune, and the standard macOS enrollment profile is assigned to every approved pilot device.
03Up to five approved pilot Macs enroll through Setup Assistant, appear in Intune as corporate-owned and supervised, and complete the approved Microsoft Entra authentication and registration experience, including Platform SSO where the design and macOS versions support it.
04FileVault is enforced on the pilot Macs with personal recovery keys escrowed to Intune, and your administrators can retrieve a recovery key through the documented procedure.
05The pilot Macs receive the approved compliance policy, configuration baseline, and software-update policy, and report their resulting status in Intune without unresolved assignment conflicts caused by the implemented scope.
06The approved managed applications deploy to the pilot Macs — including the Microsoft Defender for Endpoint app with its onboarding profile where licensed — and report installation status in Intune.
07Your administrators can locate the pilot Macs, review inventory, encryption, and compliance status, initiate a synchronization, and perform the agreed non-destructive remote action.
08Your administrators receive and can follow the as-built, enrollment, troubleshooting, and annual Apple certificate and token renewal procedures.

What you receive

macOS readiness assessment: licensing, Apple Business Manager state, device ownership and eligibility, supported macOS versions and hardware, existing MDM state, applications, network access, and identity-policy dependencies.
Target-state and decision record for one corporate-owned, supervised, user-affinity enrollment scenario — including the local-account design and the Platform SSO authentication method (Secure Enclave key or password synchronization) selected for your fleet, with the reasoning documented.
One active Apple MDM push certificate connection with documented client account ownership, expiration date, and annual renewal procedure.
One Apple Business Manager Automated Device Enrollment token connection, device synchronization configuration, and the standard supervised macOS enrollment profile with the approved Setup Assistant experience.
Platform SSO configuration for Microsoft Entra ID per the approved design, deployed and validated on the pilot Macs the design covers.
Pilot assignment group, enrollment restrictions per the approved design, and documented profile and policy assignments.
One baseline macOS compliance policy, one baseline configuration profile built in the settings catalog, FileVault enforcement with recovery-key escrow to Intune, and one managed software-update policy using the current Intune-supported mechanism appropriate to your fleet's macOS versions.
One Apps and Books location token connection and deployment of the approved managed applications — Company Portal where the design requires it, the Microsoft Defender for Endpoint app and onboarding profile for the pilot where licensed, plus up to three additional applications.
Enrollment and policy validation report for up to five client-provided pilot Macs, including identified dependencies and unresolved items outside scope.
As-built configuration, pilot enrollment guide, administrator operations and troubleshooting runbook, annual certificate and token renewal calendar, and an administrator handoff session.

How the work unfolds

Days 1–2 — Kickoff and readiness review

Confirm the relationship to the core Intune service, device ownership and eligibility, Apple Business Manager readiness, the local-account and Platform SSO design questions, pilot devices and users, applications, policies, success measures, and client responsibilities.

Days 2–3 — Apple trust and token connections

Review or configure the Apple MDM push certificate, the Automated Device Enrollment token, and the Apps and Books location token, each under a client-controlled organizational Apple account.

Days 3–4 — Enrollment and authentication design

Configure the pilot group, enrollment restrictions, and the supervised user-affinity macOS enrollment profile with the approved Setup Assistant experience. Configure Platform SSO with Microsoft Entra ID per the approved design and document the local-account decisions.

Days 4–6 — Policies, encryption, updates, and applications

Configure the approved compliance baseline and settings-catalog configuration profile, FileVault enforcement with recovery-key escrow, the managed software-update policy, and the managed application deployments including Defender for Endpoint onboarding for the pilot where licensed.

Days 6–7 — Device synchronization and enrollment

Confirm that up to five pilot Macs are assigned to the Intune MDM server in Apple Business Manager, synchronize them to Intune, and complete their new-device or post-erase enrollment through Setup Assistant.

Days 8–9 — Pilot validation and remediation

Validate supervision, Microsoft Entra registration and Platform SSO behavior, FileVault escrow, policy and application delivery, update assignment, compliance reporting, inventory, and approved administrative actions, then correct in-scope issues.

Day 10 — Documentation and handoff

Finalize the as-built and renewal procedures, review rollout recommendations and open dependencies, conduct the administrator handoff, and confirm acceptance criteria.

Prerequisites

An active Microsoft Intune tenant with MDM authority configured — through Microsoft Intune Initial Setup for Windows Device Management, an existing equivalent Intune foundation, or a concurrent implementation.
Assigned Microsoft Intune licensing for every pilot user, plus Microsoft Defender for Endpoint licensing if the pilot Defender onboarding is in the approved design. Licensing costs are not included.
A verified Apple Business Manager organization with client administrators holding the roles required to create MDM server connections, assign devices, download tokens, and manage Apps and Books.
Client-controlled organizational Apple accounts for the MDM push certificate, the Automated Device Enrollment token, and the Apps and Books token, with account recovery and long-term ownership retained by you.
Between one and five supported corporate-owned Macs that are new or approved for erasure, and that are (or can be) assigned to the correct Intune MDM server in Apple Business Manager. Macs purchased outside Apple's business channels may not be in Apple Business Manager; adding them is a separately scoped client task with Apple or your reseller.
Your authorization to erase pilot Macs after required data is backed up. Automated Device Enrollment is validated from Setup Assistant on a new or freshly erased Mac.
Approved pilot users with Microsoft Entra accounts, the agreed user and device assignments, authentication requirements, and timely acceptance of any updated Apple Business Manager agreements.
An Apps and Books location token that is not active in another MDM service or Intune tenant. Token transfer, license reconciliation, and migration from an existing Mac management service (including Jamf) are separately scoped.
An approved list of up to three additional applications available through Apple Business Manager Apps and Books, sufficient licenses for every required app, and any sign-in or testing credentials needed to validate them.
Reliable internet, DNS, firewall, and proxy access to the required Apple, Microsoft Entra, Microsoft Intune, application, and software-update endpoints.
Disclosure of existing MDM enrollment, Conditional Access, Terms of Use, authentication, compliance, certificate, VPN, Wi-Fi, and application policies that could affect Mac enrollment or management.
A client-approved decision on the Platform SSO design questions — authentication method and local-account handling — made at kickoff with our recommendation, plus a client-approved alternate authentication path for any pilot users subject to phishing-resistant multifactor requirements during Setup Assistant.
A client project owner and technical decision-maker who can provide access, approvals, devices, user availability, testing feedback, and acceptance within the two-week schedule.
Your agreement to own annual certificate and token renewals after handoff, using the same organizational accounts and the delivered renewal calendar — or a separately contracted renewal-management arrangement.

Who does what

IT Partner

  • Lead the macOS discovery, readiness assessment, design decisions, implementation plan, pilot, and acceptance review.
  • Review or configure the Apple MDM push certificate, the Automated Device Enrollment token, and the Apps and Books location token in Intune.
  • Design and configure the supervised, user-affinity macOS enrollment profile, the Setup Assistant experience, and Platform SSO with Microsoft Entra ID per the approved design.
  • Configure the pilot group, enrollment restrictions, profile assignments, and the approved compliance, configuration, FileVault, and software-update policies.
  • Deploy the approved managed applications, including the Microsoft Defender for Endpoint app and onboarding profile for the pilot where licensed, plus up to three additional Apps and Books applications.
  • Assist with synchronization and enrollment of up to five client-provided pilot Macs, and troubleshoot issues caused by the implemented configuration.
  • Validate the agreed device, policy, encryption, application, update, compliance, and administrative outcomes, and document out-of-scope dependencies.
  • Provide the as-built configuration, enrollment guide, troubleshooting runbook, annual renewal calendar and procedures, rollout recommendations, and administrator handoff.

Your team

  • Provide and maintain Microsoft Intune and Defender for Endpoint licenses, Apple Business Manager, organizational Apple accounts, application licenses, supported Macs, and any third-party subscriptions.
  • Provide approved administrative access to Microsoft Intune, Microsoft Entra, Apple Business Manager, the Apple Push Certificates Portal, and required client systems.
  • Complete the Apple Business Manager organization, domain, account-recovery, reseller, purchasing, and contractual tasks that only you or your vendors can perform — including getting eligible Macs assigned into Apple Business Manager.
  • Assign pilot Macs to the correct Intune MDM server in Apple Business Manager and provide between one and five new or erasable pilot devices.
  • Back up pilot-device data, authorize erasure, make pilot users available, and perform any required physical device steps during enrollment and testing.
  • Provide policy decisions — including the Platform SSO and local-account design choices — application selections, licenses, network access, change approvals, and user communications.
  • Review testing results and deliverables, provide decisions and feedback within the agreed schedule, and approve acceptance against the published success criteria.
  • Retain ownership of the Apple accounts and renew the MDM push certificate, Automated Device Enrollment token, and Apps and Books token before expiration — annually, with the delivered renewal calendar — unless renewal management is separately contracted.

What's not included

Other platforms — Windows Intune configuration (provided by Microsoft Intune Initial Setup for Windows Device Management; Windows Autopilot zero-touch deployment is a further separate service), iPhone and iPad management (provided by Microsoft Intune Initial Setup for iPhone & iPad Management), Android Enterprise (provided by Microsoft Intune Initial Setup for Android Device Management), and tvOS or visionOS management.
Other Mac enrollment scenarios — personally owned or BYOD Macs, Company Portal user-initiated enrollment as the production design, shared-Mac, lab, classroom, and kiosk designs, Apple School Manager, and Apple Configurator workflows.
Migration and coexistence — migration from Jamf or any other Mac MDM, Apps and Books token transfer or license reconciliation, mass unenrollment or re-enrollment, manual addition of legacy Macs to Apple Business Manager, and conversion of already-activated Macs to supervised management beyond the erase-and-enroll path described here.
Beyond-baseline Mac engineering — custom line-of-business app packaging (PKG/DMG) and scripted deployments, Munki or third-party patching frameworks, custom shell-script libraries, printer and font management at scale, kernel and system-extension engineering beyond what the included applications require, and certificate services (SCEP, NDES, Cloud PKI).
Security and identity program work — tenant-wide Conditional Access, MFA redesign, identity federation, Zero Trust architecture, full Microsoft Defender for Endpoint tenant configuration and security-operations tuning (provided by Microsoft Defender for Endpoint Deployment for Intune-Managed Devices — this engagement onboards the pilot Macs only), DLP, SIEM/SOC integration, custom VPN or Wi-Fi engineering, and network access control.
Commercial and logistics items — Microsoft and Apple licenses, paid applications, devices, accessories, Apple Business Manager organization creation or federation remediation, organization-wide rollout beyond the five-device pilot, physical staging or shipping, backup or migration of user data, formal end-user training, ongoing administration including certificate and token renewals after acceptance, travel, and taxes.

Limitations & technical notes

!What partners most often get wrong on the Mac — three warnings worth reading first: (1) Apple trust connections created under a consultant's personal Apple ID become a time bomb at renewal — here every certificate and token is created under client-controlled organizational accounts; (2) FileVault that users enabled themselves leaves no escrowed recovery key in Intune — encrypted data on a departed employee's Mac can be unrecoverable, so the pilot validates enforcement with escrow and the rollout plan addresses key rotation for already-encrypted Macs; (3) a Mac enrolled by its user through a browser or Company Portal is not the same as an Automated Device Enrollment Mac — only ADE through Apple Business Manager delivers supervised, non-removable management, and an already-activated Mac generally reaches that state only by erase and re-enrollment.
!The included design is one corporate-owned, supervised, user-affinity Automated Device Enrollment scenario. Other ownership, authentication, and shared-device models require separate design and testing.
!Eligible Macs must be in Apple Business Manager and assigned to Intune before Setup Assistant runs, and must be new or erased to receive the intended Automated Device Enrollment experience. Macs bought at retail may need reseller or Apple processing before they can appear in Apple Business Manager — a client-side dependency that can pace the schedule.
!Platform SSO behavior depends on macOS version, hardware, and identity configuration; the design records which method applies to which Macs, and older macOS versions in the pilot may receive a reduced experience documented in the validation report.
!Apple tokens and agreements are living dependencies: updated Apple Business Manager agreements or account changes can pause synchronization until you resolve them, and all three trust connections sit on annual renewal clocks under your ownership after handoff.
!Enrollment, application and policy delivery, software updates, synchronization, and compliance reporting are not instant. Timing depends on Apple and Microsoft service availability, connectivity, device state, licenses, and OS behavior. Update controls apply only where Apple and Intune support the selected behavior on the fleet's macOS versions, and no exact install time is guaranteed.
!The two-week schedule is elapsed calendar time. It assumes an active Intune foundation, a verified Apple Business Manager organization, usable organizational Apple accounts, assigned pilot Macs, available application licenses, timely approvals, and no unresolved third-party MDM conflicts.
!The fixed project fee covers one Intune tenant, one standard enrollment scenario, up to five pilot Macs, the required managed-app deployment including pilot Defender onboarding where licensed, and up to three additional Apps and Books applications. Additional devices, applications, scenarios, platforms, or remediation require a written, approved change in scope.
!Intune management improves consistency and administrative control, but no management platform can guarantee prevention of every data-loss event, security incident, service outage, enrollment failure, or compliance issue.
!Technical content reviewed August 2026. Apple changes agreements, tokens, and Setup Assistant behavior on a roughly annual cycle; this page is re-verified against Microsoft Learn and Apple Business Manager documentation on that cadence.

Frequently asked questions

How will our Macs authenticate — what is Platform SSO?

Platform SSO is the modern bridge between a Mac and Microsoft Entra ID: the user signs in once and the Mac holds an Entra credential that keeps apps and browsers signed in without password prompts. The design decision this engagement makes with you is the authentication method. Secure Enclave key: the Mac stores a hardware-bound cryptographic credential — phishing-resistant, passwordless sign-in to Entra resources, our default recommendation where the fleet supports it. Password synchronization: the local macOS password is kept in sync with the Entra password — simpler mental model, familiar sign-in, but it remains a password. The choice, and how local accounts are handled, is documented in the design record, and the pilot validates the selected experience end to end.

What do partners most often get wrong on the Mac — and how does this service avoid it?

Three mistakes cause most Mac-estate emergencies. First, creating the Apple trust connections under a consultant's personal Apple ID: renewal then depends on a person who may be gone — here every certificate and token is created under client-controlled organizational accounts with a renewal calendar. Second, ignoring FileVault escrow: users enable encryption themselves, no recovery key lands in Intune, and the data on a departed employee's Mac is unrecoverable — the pilot proves enforcement with escrowed keys and the rollout plan covers already-encrypted Macs. Third, treating a user-enrolled Mac as managed: browser or Company Portal enrollment produces removable, unsupervised management — only Automated Device Enrollment through Apple Business Manager delivers the supervised state this design is built on.

Who is this service for — and who is it not for?

It fits US commercial organizations of roughly 100–500 seats on the Microsoft cloud with corporate-owned Macs alongside a Windows fleet — the executive, creative, and developer Macs most SMBs actually have. It is not the right shape for personally owned Macs (a different enrollment and privacy design), shared-lab or classroom estates, or a migration off Jamf or another Mac MDM — each of those is available as separately scoped work on the same foundation.

What is included in Microsoft Intune Initial Setup for macOS Device Management?

The service configures the Apple MDM push certificate, the Apple Business Manager Automated Device Enrollment connection and one supervised macOS enrollment profile, the Apps and Books token, Platform SSO with Microsoft Entra ID per the approved design, one compliance baseline, one settings-catalog configuration baseline, FileVault enforcement with recovery-key escrow, a managed software-update policy, managed application deployment including Defender for Endpoint onboarding for the pilot where licensed plus up to three additional applications, pilot validation on up to five Macs, documentation including the renewal calendar, and an administrator handoff.

How does this add-on relate to the other Intune services?

Microsoft Intune Initial Setup for Windows Device Management provides the core foundation every add-on builds on. This service is the macOS add-on; the mobile add-ons are Microsoft Intune Initial Setup for iPhone & iPad Management and Microsoft Intune Initial Setup for Android Device Management; and Microsoft Defender for Endpoint Deployment for Intune-Managed Devices layers endpoint detection and response across the managed fleet. Windows Autopilot zero-touch deployment is a further separate engagement on the same foundation. Together they cover a complete, defended multi-platform estate.

How much does the macOS setup cost?

The fee is fixed per project — see the price on this page. It covers one Intune tenant, one standard enrollment scenario, up to five pilot Macs, the required managed-app deployment including pilot Defender for Endpoint onboarding where licensed, and up to three additional Apps and Books applications. Licensing, hardware, full-fleet deployment, additional scenarios, and MDM migration are not included, and no out-of-scope work is performed without your written approval.

How long does implementation take?

Two weeks — ten business days of elapsed calendar time paced by Apple Business Manager processing and client dependencies rather than ten days of continuous engineering. The schedule assumes the Intune foundation and Apple Business Manager organization are ready, the Apple accounts and tokens are available, pilot Macs can be erased and assigned, and decisions and testing arrive on time. Client-side delays move the completion date rather than the scope.

How are macOS software updates managed?

Through a managed update policy using the mechanism Intune currently supports for your Macs' OS versions — on current macOS releases that is the declarative device management (DDM) approach, which enforces a target version by a deadline with a transparent countdown for the user, and which Apple is standardizing on as it retires the legacy MDM update commands. The design records which mechanism applies to which devices, and the pilot validates the enforcement behavior your users will actually see.

Is Apple Business Manager required?

Yes. Apple Business Manager is required for the included Automated Device Enrollment design. You maintain the verified organization, assign eligible Macs to the Intune MDM server, hold the required Apple roles and accounts, and accept Apple's agreements when they update. Macs purchased at retail rather than through business channels may need Apple or reseller processing before they can be added — a client-side task we identify in the readiness assessment.

Does this service manage employees' personal Macs?

No. The included design is for corporate-owned, supervised Macs enrolled through Apple Business Manager. Managing personally owned Macs is a different model with a different privacy posture and different enrollment mechanics, and it is separately scoped — as is app protection without device enrollment.

Can you migrate us off Jamf (or another Mac MDM)?

Not inside this engagement — and it matters to be precise about why. Moving Macs between MDMs is not a settings export: supervised state, FileVault keys, and Apps and Books licenses each have their own migration behavior, and devices generally re-enroll to change management. This engagement establishes the Intune macOS foundation a migration would land on; the migration itself — coexistence design, token and license transfer, staged re-enrollment — is quoted separately once we can see your current estate.

What about our Microsoft Defender for Endpoint coverage on Macs?

The pilot Macs get the Defender for Endpoint app deployed and onboarded through Intune where you hold the licensing — so by the end of the pilot, your security tooling sees the Macs it will see in production. Tenant-wide Defender configuration, policy tuning, and security-operations integration remain the separate Microsoft Defender for Endpoint Deployment for Intune-Managed Devices engagement, which this pilot onboarding slots into cleanly.

Who renews the Apple certificates and tokens after handoff?

You do, by default — using the delivered renewal calendar that names each trust connection, its expiration date, its owning account, and the exact renewal steps. All three renew on roughly annual cycles, and renewing on time with the same accounts is what keeps the fleet managed. If you would rather not carry that clock, IT Partner can quote an annual renewal-management arrangement separately.

What happens after implementation?

You receive the validated configuration, pilot results, as-built document, enrollment and troubleshooting runbooks, the renewal calendar, and an administrator handoff. Natural next steps, each separately scoped: the production rollout across the Mac fleet, fleet-wide Defender for Endpoint deployment, additional scenarios such as shared Macs, and the multi-platform bundle completing Windows, iPhone/iPad, Android, and macOS under one management design.

Didn’t find your question?

Ask it here. A real engineer answers by email within one business day — and if it’s a good one, it becomes part of this page so the next person finds it.

Answered by a person, one time, to your inbox. Nothing you type here is published without a human reviewing and anonymizing it first.

Often combined with

$3,950 per project
2 weeks
Book a macOS scoping call