Enrolling macOS workstation in Intune using the Company Portal app

NOTE: The procedure described in this article will not work on a Mac that was registered in Automated Device Enrolmet (ADE) by Apple (see more).

University-owned and personal Apple macOS devices used for work (BYOD or Bring your Own Device) primarily by one person are referred to as primary-user workstations. They can be enrolled in Intune device management through the Company Portal app that needs to be downloaded and installed on the device. Enrolling macOS device in Intune this way allow user to

  • access internal resources and systems on that device
  • install additional software that the University is licensed for
  • reset the device remotely in the event it gets lost or stolen
  • protect user data on the device by Microsoft Defender
  • create a backup of the recovery key for File Vault local disk encryption

To enroll macOS device using the Company Portal app:

  1. Navigate to portal.manage.microsoft.com in Safari or other browser
  2. When prompted, sign in using UWin Account credentials (UWinID@uwindsor.ca as login name) of the main user of this Mac workstation. 
  3. If you see the screen picture below, click on Devices button. Otherwise, click on the three horizonatl lines icon in top-left corner and select Devices from the menu.


     
  4. Click Tap here to tell us which device you're using or to add a new device
  5. Click Download on the Add this device screen.
    NOTE: The Company Portal app for macOS can also be downloaded using this link: aka.ms/EnrollMyMac
  6. Open your Downloads folder in Finder and open the CompanyPortal_x.x.x-Installer.pkg file
  7. Click Continue at the Introduction screen
  8. Click Continue at the License screen, accept the License Agreement by clicking Agree
  9. Click Install at the Installation Type screen. When prompted, enter your device's password and click Install Software
  10. Click Close at the Summary screen
  11. Click Move to Trash to discard the installation package
  12. Microsoft AutoUpdate will launch and check for updates. When prompted to configure settings, ensure that Automatically Download and Install or Automatically keep Microsoft Apps up to date is selected.
  13. Launch Company Portal app that was just installed


     
  14. Click Sign In
  15. When prompted, sign in using UWin Account credentials of the main user of this Mac workstation
  16. Click Begin to start enrolling this device into Intune
  17. Click Continue on the Review privacy information screen
  18. Click Download profile on the Install Management profile screen
  19. The Mac will now direct you over to the System Preferences to install the management profile. When asked "Are you sure you want to install...," click Install and then Install again




     
  20. When prompted, enter your device's password and click Install
  21. Close all windows and dialogue boxes

At this point, the workstation is registered in Entra and enrolled in Intune. If this is University-owned device, the following apps will be installed on it automatically by Intune:

  • Microsoft Defender
  • GlobalProtect VPN
  • Microsoft Edge (browser that works best with all University apps and systems)

To verify your device's compliance with University security requirements (conditional access) at any time, launch the Company Portal app you installed on your device and check your device status under Devices. You can also use the Company Portal app to install University-licensed software on your Mac, such as Microsoft 365 Apps (formerly Microsoft Office 365 for Mac).

 

 

 

Print Article

Related Articles (6)

As of  May 1, 2018, I.T. Services adopted a new naming convention for managed computers running Windows and macOS operating systems. Computer name will consist of two parts separated by a dash: TLC-123456, where "TLC" is a three letter departmental code, and "123456" is a TeamdDynamix Asset ID.
ConnectWise Control Client software is being installed on every University owned workstation. It allows IT Services staff to remotely connect to workstations for the purpose of troubleshooting, software installation, etc.
At the University of Windsor, Microsoft Intune combined with Entra ID provides device and application administration, corporate data protection, identity management and directory services.
This article provides instructions on installing Lansweeper agent on Windows workstations.
Microsoft Company Portal is an app that faculty and staff at the University of Windsor use to manage their workstations.
This article provides suggestions for troubleshooting most common device enrollment issues in Microsoft Intune. It is geared towards IT staff.