You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: memdocs/intune/enrollment/macos-enroll.md
+16-14Lines changed: 16 additions & 14 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -37,30 +37,32 @@ ms.collection:
37
37
38
38
Microsoft Intune supports enrollment on personal and company-owned devices. This article describes the methods and features you can use to enroll personal, company-owned, and VM devices in Intune.
39
39
40
-
## Enable macOS enrollment
40
+
## Enable enrollment in Microsoft Intune
41
41
42
-
Before enrolling devices, you must enable enrollment in your Microsoft Intune tenant. Complete this list of prerequisites to ensure that people can successfully enroll thier devices.
42
+
Complete these steps to enable enrollment in your Microsoft Intune tenant.
43
43
44
-
-[Verify that devices are eligible for Apple device enrollment](https://support.apple.com/en-us/HT204142#eligibility)
3.[Set the MDM Authority](../fundamentals/mdm-authority-set.md)
47
+
4.[Get an Apple MDM push certificate](../enrollment/apple-mdm-push-certificate-get.md)
48
+
5. Assign user licenses in the [Microsoft 365 admin center](https://go.microsoft.com/fwlink/p/?LinkId=698854)
49
+
6.[Create groups](../fundamentals/groups-add.md)
50
+
7.[Configure the Company Portal app](../apps/company-portal-app.md)
51
51
52
+
## Enroll devices
53
+
After you enable enrollment, use one of the supported methods described in this section to enroll user-owned and company-owned devices.
52
54
53
55
## User-owned macOS devices (BYOD)
54
56
55
-
Intune supports *bring-your-own-device*, or *BYOD*, which lets people enroll their personal devices themselves. To set up enrollment for BYOD scenarios, complete the prerequisites in this article. Then tell your device users to use one of these options to enroll devices:
57
+
Intune supports *bring-your-own-device*, or *BYOD*, which lets people enroll their personal devices themselves. To finish setting up enrollment for BYOD scenarios, tell your licensed users to use one of these options to enroll devices:
56
58
57
59
- Sign in to [Company Portal website](https://portal.manage.microsoft.com) and follow on-screen instructions to add device.
58
60
- Install Company Portal app for Mac at [aka.ms/EnrollMyMac](https://aka.ms/EnrollMyMac) and follow-on screen instructions to add device.
59
61
60
62
## Company-owned macOS devices
61
-
Intune supports the following enrollment methods for company-owned macOS devices:
63
+
Intune supports the following enrollment methods for company-owned macOS devices. Select a hyperlinked method to open its setup steps.
62
64
63
-
-[Apple Automated Device Enrollment](device-enrollment-program-enroll-macos.md): Use this method to automate the enrollment experience on devices purchased through Apple Business Manager or Apple School Manager. Automated device enrollment deploys the enrollment profile over-the-air, so you don't need to have physical access to devices.
65
+
-[Apple Automated Device Enrollment](device-enrollment-program-enroll-macos.md): Use this method to automate the enrollment experience on devices purchased through Apple Business Manager or Apple School Manager. Automated device enrollment deploys the enrollment profile over-the-air, so you don't need to have physical access to devices.
64
66
-[Device enrollment manager (DEM)](device-enrollment-manager-enroll.md): Use this method for large-scale deployments and when there are multiple people in your organization who can help with enrollment setup. Someone with device enrollment manager (DEM) permissions can enroll up to 1,000 devices with a single Azure Active Directory account. This method uses the Company Portal app or Microsoft Intune app to enroll devices. You can't use a DEM account to enroll devices via Automated Device Enrollment.
65
67
-[Direct enrollment](device-enrollment-direct-enroll-macos.md): Direct enrollment enrolls devices with no user affinity, so this method is best for devices that aren't associated with a single user. This method requires you to have physical access to the Macs you're enrolling.
66
68
@@ -134,9 +136,9 @@ No changes are required for virtual machines running on Apple Silicon hardware.
134
136
135
137
## User-approved enrollment
136
138
137
-
This type of enrollment lets you manage macOS devices that aren't part of Apple School Manager or Apple Business Manager. It provides the same level of control as supervised macOS devices enrolled using Automated Device Enrollment or Apple Configurator.
139
+
All Mac enrollments in Intune are considered user-approved. User-approved enrollment lets you manage macOS devices that aren't part of Apple School Manager or Apple Business Manager. It provides the same level of control as supervised macOS devices enrolled using Automated Device Enrollment or Apple Configurator.
138
140
139
-
All Mac enrollments in Intune, except those enrolled via Automated Device Enrollment (ADE), are considered user-approved. Intune automatically turns on supervision for user-approved devices running macOS 11 and later. It also does this for enrolled devices that later update to macOS 11 or later.
141
+
Intune automatically turns on supervision for user-approved devices running macOS 11 and later. It also does this for enrolled devices that later update to macOS 11 or later.
0 commit comments