Share via


Onboard and offboard macOS devices into Purview solutions using Intune for Microsoft Defender for Endpoint customers

You can use Microsoft Intune to onboard macOS devices into Microsoft Purview solutions.

Important

Use this procedure if you have already deployed Microsoft Defender for Endpoint (MDE) to your macOS devices.

Applies to:

Before you begin

Note

The three most recent major releases of macOS are supported.

Onboard macOS devices into Microsoft Purview solutions using Microsoft Intune

If Microsoft Defender for Endpoints (MDE) has already been deployed to your macOS device, you can still onboard that device into Purview solutions. Doing so is multi-phase process:

  1. Create system configuration profiles
  2. Update existing system configuration profiles
  3. Update MDE preferences

Prerequisites

Download the following files:

File Description
accessibility.mobileconfig Used for accessibility
fulldisk.mobileconfig Used to grant full disk access (FDA).

Note

To download the files:

  1. Right-click the link and select Save link as....
  2. Choose a folder and save the file.

Create system configuration profiles

  1. Open the Microsoft Intune admin center and navigate to Devices > macOS > Configuration.

  2. On the Policies page choose: + Create and then choose New policy.

  3. Select the following values:

    1. Platform = macOS
    2. Profile type = Templates
    3. Template name = Custom
  4. Choose Create.

  5. On the Basics tab, Enter a name for the profile, for instance: Microsoft Purview Accessibility Permission, and then choose Next.

  6. On the Configuration settings tab, Choose the accessibility.mobileconfig as the configuration profile file (downloaded as part of the prerequisites) and then choose Next.

  7. On the Assignments tab, add the group you want to deploy this configuration to and then choose Next.

  8. Review your settings and then choose Create to deploy the configuration.

  9. Still on the macOS > Configuration policies page. The profiles you created display (you may have to choose refresh).

  10. Choose the new policy. Next, choose Device assignment status to see a list of devices and the deployment status of the configuration profile.

Update existing system configuration profiles

  1. A full disk access (FDA) configuration profile should have been created and deployed previously for MDE. (For details, see Intune-based deployment for Microsoft Defender for Endpoint on Mac). Endpoint data loss prevention (DLP) requires additional FDA permission for the new application (com.microsoft.dlp.daemon).

  2. Update the existing FDA configuration profile with the downloaded fulldisk.mobileconfig file.

Update MDE preferences

  1. Find the existing MDE Preferences configuration profile. See Intune-based deployment for Microsoft Defender for Endpoint on Mac for details.

  2. Add the following key to the .mobileconfig file, then save the file.

     <key>features</key> 
     <dict> 
         <key>dataLossPrevention</key> 
         <string>enabled</string> 
     </dict> 
    

Offboard macOS devices using Microsoft Intune

Important

Offboarding causes the device to stop sending sensor data to the portal. However, data received from the device, including references to any alerts it has had, will be retained for up to six months.

  1. In the Microsoft Intune admin center, open Devices > Configuration. The policies you created display.

  2. Choose the MDE preferences policy.

  3. Under Properties  > Configuration Settings, choose Edit

  4. Remove these settings:

     <key>features</key>
     <dict>
         <key>dataLossPrevention</key>
         <string>enabled</string>
     </dict>
    
  5. Choose **Review+**Save. This will offboard the macOS device from Purview solutions while not changing the macOS device enrollment in MDE.