HomeSetup guides › Enrol a Mac (macOS) via Apple ADE
Setup guide · from scratch

Enrol a Mac (macOS) via Apple ADE

Turns a corporate-owned Mac into a supervised, Intune-managed device the moment it's switched on — zero-touch, straight from the box. The trap: a Mac that syncs from Apple Business Manager with no enrolment policy assigned fails Setup Assistant outright, so set a Default Policy before anyone powers one on.

Apple Business Manager + Intune (macOS enrollment) + a Macassisted guide — Decolla walks you through this
≈ 45 min
Apple — iPhone, iPad & Mac · step 12 of 12 · ≈ 45 min‹ Previous
Do these first — this guide assumes you already have:
The Decolla way — skip the clicks.

Every step below can be done by hand. Or connect your Microsoft tenant to Decolla once, and Decolla performs this for you over Microsoft Graph in your own tenant — then hands back a verified result you can see and roll back per item. It also puts the fundamentals this step depends on in place — the target group, the licence allocation — so a build is never blocked half-way by a missing dependency.

⏱ By hand: about 45 min of clicking, every build. The Decolla way: part of one tenant connect, then automatic.
0 of 11 done
Step 1. In Apple Business Manager (business.apple.com), sign in as an Administrator or Device Enrolment Manager, open Devices from the sidebar, find the Mac by its serial number, and assign (or confirm) its device management to the MDM server that represents this Intune tenant.
Screenshot: ABM Devices list with the Mac selected, showing it assigned to the Intune MDM server (captured during a live customer build — coming to this page)
Why: ADE only works for Macs Apple already knows are yours and has handed to your MDM. This assignment is what makes the Mac 'yours' in Apple's eyes; without it there is nothing for Setup Assistant to match against.
Watch for: Apple has relabelled this control over time (Assign Device Management / Edit MDM Server) — plainly, you are pointing the device at your Intune server. If the Mac is not listed here at all, it was never added to ABM; add it via your reseller's Apple Customer Number or Apple Configurator first. A shop-bought or non-ABM-reseller Mac can never be ADE-enrolled.
Don’t: Do not assume assigning a Mac in ABM enrols it — assignment only takes effect through Setup Assistant on a new or erased device.
Step 2. In the Microsoft Intune admin centre, go to Devices > Enrollment > macOS tab > Enrollment program tokens, open your ADE token, select Devices, then Sync. Wait for the sync to finish and confirm the Mac's serial number appears in the device list.
Screenshot: Intune Enrollment program token > Devices view with the Sync button and the Mac's serial number visible (captured during a live customer build — coming to this page)
Why: Intune only sees the ABM assignment after a sync pulls the serial across. Until the serial shows here, nothing you configure can reach the device.
Watch for: Some tenants nest this under Devices > Device onboarding > Enrollment, and some still show a single 'Apple' tab rather than a separate 'macOS' tab — the token lives in the same place either way. A manual Sync is throttled to once every 15 minutes and a full sync to once every 7 days, so a brand-new assignment can lag; give it time rather than hammering Sync.
Step 3. Still on the token, select Enrollment policies > Create policy > macOS, and on the Basics tab give the policy a clear name and description. These are admin-only labels — device users never see them.
Screenshot: Create policy > macOS Basics tab with name and description filled in (captured during a live customer build — coming to this page)
Why: This is the current 'Enrollment policies' experience. The older 'Profiles' experience still exists but is being retired and receives no new features, so build here.
Watch for: The policy name can double as the trigger for a dynamic Entra device group (via the enrollmentProfileName attribute), so name it deliberately if that is how you group devices.
Step 4. On the Configuration settings tab, set User Affinity to 'Enroll with User Affinity', then set the authentication method to 'Setup Assistant with modern authentication'. Set 'Await final configuration' to Yes and 'Locked enrollment' to Yes.
Screenshot: Configuration settings showing Enroll with User Affinity, Setup Assistant with modern authentication, Await final configuration = Yes, Locked enrollment = Yes (captured during a live customer build — coming to this page)
Why: Modern authentication is the current recommended method: it makes the user prove who they are and drives the Company Portal sign-in that finishes enrolment. 'Await final configuration' holds the Mac on a locked screen until your critical policies land, so users cannot reach the desktop mid-build.
Watch for: Locked enrollment = Yes cannot be changed afterwards without wiping the Mac — decide deliberately. Choose 'Enroll without User Affinity' only for shared or kiosk Macs; those get no Company Portal and cannot be verified the way step 11 describes.
Don’t: Do not pick 'Setup Assistant (legacy)' without a specific reason — Microsoft no longer recommends it.
Step 5. Under Account settings, decide how local accounts are created: enable the Intune-managed local administrator (macOS LAPS) so each Mac gets a unique, random 15-character admin password stored and rotated by Intune, and configure the primary local user account. Note that the primary account is itself an admin account — macOS requires at least one.
Screenshot: Account settings pane showing the managed local administrator (LAPS) option and the primary account fields (captured during a live customer build — coming to this page)
Why: This is where macOS diverges hard from iOS. A Mac must have a local admin account; iOS has no such concept. LAPS gives you a break-glass admin per device without a shared password across the fleet.
Watch for: Configuring any account setting silently forces 'Await final configuration' on, whatever you set it to — local account creation depends on it. Skipping the account-creation pane here (or via a kiosk/Platform SSO flow) is exactly what can leave the macOS bootstrap token un-escrowed later — see step 11.
On a schedule: Intune rotates the LAPS admin password every six months by default; confirm where admins look it up before you hand the Mac over.
Step 6. Under Setup Assistant, enter a support Department Name and Department Phone, then choose which Setup Assistant panes to Show or Hide. For a hands-off build, hide the optional panes; leave the FileVault decision to your encryption plan. Select Next, review the summary, and select Create.
Screenshot: Setup Assistant screen list with Show/Hide toggles and the Create button (captured during a live customer build — coming to this page)
Why: Hidden panes are not gone forever — users can set those features up later in System Settings. Hiding them simply shortens first-boot and removes distractions.
Watch for: Hiding a pane is not the same as configuring the feature. Hiding the FileVault screen does not encrypt the disk or escrow a key — that needs a separate FileVault disk-encryption policy, and you must verify the key actually reaches Intune (step 11).
Step 7. Back on the token, select Devices, pick the Mac and choose Assign policy > your new policy > Assign. Then, on the token itself, choose 'Set Default Policy' and select the same policy so every future synced Mac inherits it automatically.
Screenshot: Token view showing the policy assigned to the device and 'Set Default Policy' set to the new policy (captured during a live customer build — coming to this page)
Why: This is the single most common way a first ADE run fails, and setting a default closes the gap for every device on the token.
Watch for: A Mac that syncs from ABM with no enrolment policy assigned, then gets switched on, fails Setup Assistant enrolment outright — there is nothing to hand it.
Don’t: Do not rely on per-device assignment alone at scale — a device that syncs in overnight with no default policy will strand whoever unboxes it.
Step 8. Confirm the Company Portal for macOS app is deployed to these users or devices as a Required app. If it is not, add it from Apps and assign it Required before you power on the Mac.
Screenshot: Intune Apps list showing Company Portal for macOS assigned as Required (captured during a live customer build — coming to this page)
Why: With user affinity plus modern authentication, the Mac is not finished until the user signs in to Company Portal — that sign-in is what completes Microsoft Entra registration and satisfies Conditional Access.
Watch for: This is the macOS Company Portal (a .pkg app), not the iOS App Store or VPP build. Assigning it Required means it is waiting on the desktop when the user first lands, rather than something they must hunt for.
Step 9. On the Mac itself, start from a clean state — a brand-new Mac, or an existing one erased with 'Erase All Content and Settings' (System Settings > General > Transfer or Reset). Power it on, connect it to Wi-Fi or Ethernet, and step through Setup Assistant until the 'Remote Management' screen appears and applies your organisation's management.
Screenshot: macOS Setup Assistant 'Remote Management' screen showing the organisation configuring management on the Mac (captured during a live customer build — coming to this page)
Why: Remote Management is Apple's ADE hand-off screen; seeing it is proof the Mac matched its ABM assignment and picked up your policy.
Watch for: If Remote Management never appears, the Mac either is not assigned to your MDM server in ABM (step 1), has not synced into Intune (step 2), or has no assigned/default policy (step 7). A network drop at this screen also stalls enrolment.
Don’t: Do not skip erasing an already-set-up Mac — ADE and Remote Management only trigger during Setup Assistant, which a configured Mac has already passed. (An already-configured Mac can be enrolled instead by running 'sudo profiles renew -type enrollment' in Terminal, but that is a different, non-zero-touch path.)
Step 10. After Setup Assistant completes and any 'Awaiting final configuration' hold releases, open Company Portal on the Mac and sign in with the user's Microsoft Entra credentials to finish enrolment.
Screenshot: Company Portal for macOS signed in, showing the Mac as managed (captured during a live customer build — coming to this page)
Why: Until this sign-in happens, the device is enrolled into management but not registered to the user in Entra, so Conditional Access will keep bouncing them back to Company Portal every time they open a protected app.
Watch for: 'Awaiting final configuration' can hold the desktop for up to roughly 15 minutes while policies install — that is expected, not a hang. The more apps and policies you assigned, the longer it takes.
Step 11. In Intune (Devices > All devices), confirm the Mac shows as managed, Corporate-owned and supervised. Then verify the two macOS-specific safety nets: that the bootstrap token has escrowed, and that a FileVault recovery key is actually retrievable from Intune — not merely that the disk reports as encrypted.
Screenshot: Intune device blade showing the Mac managed and supervised, alongside a retrievable FileVault recovery key (captured during a live customer build — coming to this page)
Why: A green compliance tick tells you the disk is encrypted; it does not tell you Intune holds a usable recovery key, and it says nothing about the bootstrap token. Both fail silently and only surface during a lockout, or during a kernel-extension or software-update job, weeks later.
Watch for: On the Mac, 'sudo profiles status -type bootstraptoken' should report 'escrowed to server: YES'. If account creation was skipped during Setup Assistant, the bootstrap token may never have escrowed — a SecureToken-enabled user must log in once to trigger it. For FileVault, prove the key by retrieving it in the admin centre, not by trusting the compliance column.
Don’t: Do not treat the build as finished on the compliance column alone — verify FileVault-key retrieval and bootstrap-token escrow explicitly.

Put these on a schedule

StepRecurring action to diarise
Step 5Intune rotates the LAPS admin password every six months by default; confirm where admins look it up before you hand the Mac over.

If it goes wrong

The failures people actually hit on this process, each with the diagnosis and fix:

See it on a real device.

Decolla is in private build — early-access members see a build defined, deployed and rolled back first.

Get early access