Macos Intune Baseline

Guidance for hardening macOS endpoints managed by Microsoft Intune — automated device enrollment via Apple Business Manager (ABM), platform single sign-on (PSSO) with Entra ID, FileVault disk encryption escrow, security configuration profiles (Gatekeeper, XProtect, system extensions allowlist, firewall, login window, Privacy Preferences Policy Control / PPPC), Microsoft Defender for Endpoint on macOS, app management (VPP / managed apps / shell scripts via Intune), patching strategy (managed software updates / DDM), Conditional Access compliance signal, and cross-platform identity model. WHEN: Mac Intune baseline, macOS hardening Intune, FileVault escrow, ABM Apple Business Manager, Platform SSO macOS, PSSO Entra, MDE on Mac, Gatekeeper Intune, system extensions Intune, PPPC Intune, macOS compliance Conditional Access. DO NOT USE for general Intune device management end-to-end (use intune-device-mgmt), MDE config alone (use defender-for-endpoint), or iOS device management.

vinayaklatthe Updated

File contents

vinayaklatthe/microsoft-security-skills/tree/main/skills/macos-intune-baseline commit ada82659d5

Frequently asked questions

npx skillmds@latest add vinayaklatthe/macos-intune-baseline