One of our customers had purchased a few MacBook Air laptops last week and were keen to get them up and running. I suggested that we at least get them enrolled in Intune with a very basic config before they go out in the field. Here are the steps I took to get them out the door.
Mac enrolment in Intune isn’t complicated once you’ve done it once. The tricky part is knowing which route to take before you start, because Apple gives you two very different paths depending on how the device was bought.
This guide covers both: Automated Device Enrolment (ADE) for a corporate-owned Mac bought through Apple Business Manager, and Company Portal enrolment for anything else. If you followed my earlier post on connecting Apple Business Manager to Intune for iOS, the ABM/MDM server link-up is already done. This is the same server, just adding Macs to it.
Which route do you need?
ADE (zero-touch) — the Mac was purchased through Apple Business Manager, or added to ABM via Apple Configurator. It shows up in Devices in ABM already. This is the route for corporate-owned kit and gives you a fully managed device from first boot.
Company Portal (user-driven) — the Mac wasn’t bought through ABM, or it’s a personal/BYOD device. The user installs Company Portal themselves and enrols manually. Less control (no Setup Assistant automation, user can technically unenrol), but it works on any Mac.
If you’re not sure which one you need, check Apple Business Manager under Devices first. If it’s listed there, use ADE.
Prerequisites
Before you start, confirm:
Apple Business Manager is linked to your Intune tenant (Devices > Enrollment devices > Enrollment Program Tokens in Intune)
The Mac is assigned to your MDM server in ABM, if you’re using ADE
You have a macOS enrolment profile configured in Intune (Devices > macOS > Enrollment > Enrollment profiles)
The user has an Intune licence assigned
Skip any of these and enrolment will either fail outright or leave the device half-configured.
Route 1: Automated Device Enrolment (ADE)
1. Assign the device to your MDM server in Apple Business Manager
Log into ABM, go to Devices, find the Mac by serial number, and assign it to the Intune MDM server. If it was bought directly through Apple with your ABM account linked, this happens automatically. If it came from a reseller, you may need to do this manually or ask the reseller to push it through.
2. Create or check your enrolment profile in Intune
Go to Devices > macOS > Enrollment > Enrollment Program Tokens, select your token, and open Profiles. Create a profile if you don’t have one:
Set authentication method (usually Setup Assistant with modern authentication)
Decide which Setup Assistant screens to skip (Location Services, Siri, and Apple ID are common ones to hide for corporate builds)
Enable “Await final configuration” if you want the device to stay locked to a Configuration screen until all app and profile pushes finish. Worth turning on if first-boot policy delivery has ever been patchy in your tenant.
3. Assign the profile to the device
Back in the device list under your token, select the Mac and assign the profile you just built. This can take a few minutes to sync from Apple’s side, so don’t panic if it’s not instant.
4. Boot the Mac
Power it on (or factory reset if it’s been used before — ADE only triggers on a clean Setup Assistant run). The device will check in with Apple, pull down the MDM enrolment, and the user will be guided through Setup Assistant with your configured screens. No Apple ID sign-in prompt, no manual profile installation.
5. Confirm enrolment in Intune
Once through Setup Assistant, the device should appear in Devices > All devices within a few minutes, with compliance and configuration policies starting to apply. Check Managed Apps and Compliance status to confirm policies are actually landing, not just that the device shows up.
Route 2: Company Portal (user-driven)
1. Install Company Portal
Download the .pkg installer directly from Microsoft by navigating to aka.ms/EnrollMyMac or by logging into the Intune Company Portal website. The macOS Company Portal app is not distributed through the Mac App Store.
2. Sign in
Open Company Portal and sign in with the user’s work account. It’ll prompt to enrol the device — accept.
3. Download and install the management profile
Company Portal generates a management profile the user needs to download and install manually through System Settings > Profiles. This is the one extra step ADE skips, and the one most users get stuck on, so it’s worth walking them through it the first time.
4. Confirm enrolment
Once the profile installs, Company Portal shows the device as enrolled, and it’ll appear in Intune within a few minutes same as the ADE route.
A few things that catch people out
ADE only fires on Setup Assistant. If the Mac has already been through first-time setup, you need to wipe it (or use Apple Configurator to force a factory-style reset) before ADE will apply. You can’t “convert” a live device to ADE enrolment after the fact.
Token expiry. ABM enrolment tokens expire annually. If devices stop showing up under your token in Intune with no obvious cause, check the token hasn’t lapsed first.
Await final configuration can backfire if your policies aren’t fully sorted, because the device sits on the lock screen until everything’s pushed. Test with one device before rolling it out to a batch.
Company Portal enrolment isn’t as sticky. A user can remove the management profile from System Settings unless you’ve layered in additional restrictions. Fine for BYOD, not something I’d rely on for a fully corporate-managed Mac.
Once you’ve got one Mac through either route, the rest of the fleet follows the same pattern. The main thing worth getting right early is deciding ADE vs Company Portal per device before it lands on a desk, since switching from one to the other later means a rebuild.
