S03E07 - Enrolling Apple devices to Intune (I.T)

Поділитися
Вставка
  • Опубліковано 6 сер 2024
  • Part 3 of 3 - Ben & Steve prepare the Intune.Training tenant to enroll "pre-owned" Apple devices.
    In this video, we FINALLY enroll Steve's Mac Mini to our Intune tenant!!
    00:00 - Intro
    01:55 - Apple T2 Security Chip
    support.apple.com/en-us/HT208862
    04:20 - AppleSeed
    appleseed.apple.com/sp/welcome
    05:11 - Apple Configurator for iOS
    07:35 - Assign a mac to your organisation
    09:48 - Apple Business Manager devices
    11:33 - Intune ABM devices
    14:01 - Mac enrolment
    18:40 - Wrap up
    Visit our websites and social media for more or to get in touch with us
    Steve Hosking - Microsoft MMD Team
    / onpremcloudguy
    steven.hosking.com.au/
    mvp.microsoft.com/en-us/Publi...
    github.com/onpremcloudguy
    Adam Gross - Microsoft MVP - Enterprise Mobility
    / adamgrosstx
    www.asquaredozen.com
    github.com/AdamGrossTX
    mvp.microsoft.com/en-us/Publi...
    Ben Reader - Microsoft MVP - Enterprise Mobility
    / powers_hell
    www.powers-hell.com/
    github.com/tabs-not-spaces
    mvp.microsoft.com/en-us/Publi...
    Jake Shackelford - Desktop Engineer
    / shackelfjaco
    sysmansquad.com/author/jshack...
    / jacob-shackelford-a5bb...

КОМЕНТАРІ • 47

  • @thereflecs
    @thereflecs 2 роки тому +5

    Great video! Just had my first personal experience with this. The experience is far from flawless. I can remove the Management profile as a user myself by using the "-" button below the profiles. After that I needed to re register the device in ABM for it to be able to get enrolled again. I see in your video (17:32) the "-" button at the bottom of the window isn't greyed out aswell. The Firewall profile is greyed out. I believe this is a major issue.
    Also Intune tells me the device is supervised, but I cannot use the supervised mode functionalities from Intune. (like Restart, Shutdown and Lost Mode).

  • @IntuneVitaDoctrina
    @IntuneVitaDoctrina 2 роки тому

    Gréât vidéo, nice to see apple on the screen and all the steps 🙏

  • @lltagged
    @lltagged 2 роки тому

    Great show as always.

  • @RoelofdeGroot
    @RoelofdeGroot 2 роки тому +2

    Thanks for the videos on covering macOS!
    Oh and a pro tip: Command - Ctrl - Space 😉

  • @majorblazer9055
    @majorblazer9055 Рік тому +1

    User profile can be AAD backed now with Xcreds an opensource program

    • @dmitrykravtsov853
      @dmitrykravtsov853 Рік тому

      Your hint is like a breath of clean air! Thank you very much man!

  • @Gus247365
    @Gus247365 Рік тому

    Thank you guys - very helpful!!!

  • @iliassoukallaris7274
    @iliassoukallaris7274 2 роки тому

    Hi guys, can you share how you sideloaded apple configurator 2 to the iphone? Would be really helpful.

  • @PaulShadwell
    @PaulShadwell 3 роки тому

    This is great. I've been trying to find this. I'm disappointed that it's so complicated. I used to be able to add devices by just adding the serial number into the Apple Business Manager.

    • @schiefvancleef
      @schiefvancleef 2 роки тому +1

      Adding a SN# in Apple Business Manager is possible as well. The shown Method (manually adding a Mac) is similiar to the current process of adding iOS/iPaOS Devices MANUALLY with Apple Configurator 2. Thats why you should always buy your Apple HW at a official (and certified) Apple (Enterprise) Reseller. He can add SN# for you retroactive, so you dońt need to MANUALLY add Device with Apple Configurator 2 (iOS/iPadOS) or Apple Configurator App (iOS). Adding devices manually also has the disadvantage that the user has a grace period of 30 days during which he can still remove the manually added devices from the Apple Business Manager or Automated Device Enrollment. Only after the 31st day does the device behave as if it had always been registered. Do´nt forget: Apple has built this way in afterwards. Scaling is not desired here. That is why we are also talking about a MANUAL approach here.

  • @ThiagoBeier
    @ThiagoBeier Рік тому

    Thanks for the detailed video, is there a way to skip the "create a computer account" at 15:55 ? get the device enrolled at ABM > Intune > profile and skip this part so user is not "root" in the system and we continue to manage the device from intune?

  • @laxmanwadhwa8175
    @laxmanwadhwa8175 Рік тому

    What about the Mac App Store applications? They seem to be greyed out after this type of enrolment??

  • @RamanSingh-uf4bb
    @RamanSingh-uf4bb 2 роки тому

    Is a device reset required for this method? what is process if the devices are already enrolled into inTune?
    basically trying to get devices added ABM so they can be enrolled properly, so we can push out ISO updates.

  • @ronikuggz3362
    @ronikuggz3362 2 роки тому

    Hi guys just a quick question, how will you control admin credentials for it? will it be AAD cred or do you need to create a local admin account?

  • @DLSC2374
    @DLSC2374 3 роки тому

    if you enrolling devices in ADE you will need to get them enrolled through apple is that correct

  • @babitahopal5100
    @babitahopal5100 3 роки тому

    hi, is there anyway that it can automate too with the installing the Office365

  • @jaredfoley7010
    @jaredfoley7010 Рік тому

    Do you have any advice on enrolling a Mac VM into ABM that we can use for Intune testing?

  • @XriddimXkillaX
    @XriddimXkillaX 2 роки тому

    Hey ya'll, I'm running into an 500 error when the device is trying to enroll. Intune can see it and has a profile but only one Mac has been able to successfully join the server. Any idea where I could look?

  • @MikeFerguson1
    @MikeFerguson1 3 роки тому

    Hey, @10:10 the blur of the serials doesn't quite show up in time, just FYI!!

  • @jimcopeland4011
    @jimcopeland4011 Рік тому

    Is there any way to do patch management via Intune for MacOS devices? I don't see a way out of the box, but I do see the ability to create custom template profiles. Perhaps something can be scripted?

  • @DaleHiltner
    @DaleHiltner 2 роки тому +2

    Thanks so much for this video. I'm a total visual guy so reading all the documentation just confused the hell out of me. You answered all the questions that was holding me back after reading the documentation.
    Question: In the previous episode we created the companyportal-installer package and created a LOB app in Intune. That LOB app was assigned to a group however the device that needed to be in that group didn't exist in Intune yet. Then in this episode, after enrolling the device into ABM and after allowing it to sync over to Intune, I didn't see you add the mac device to the Intune group so that the company portal app could install. Was that a missed step and, if using groups to install a package, don't we need to add the mac to that group for company portal install?

    • @Dreas204
      @Dreas204 2 роки тому

      I am actually having the same question. Seems like a missing step

  • @chrislamonte8554
    @chrislamonte8554 2 роки тому +2

    Do you have to already have a mac to set-up the company portal before you can begin enrolling brand new macs? In S03E05 you guys already had a mac that you were logged into before you did the company portal, but in this video the mac you're using is brand new.

    • @IntuneTraining
      @IntuneTraining  2 роки тому

      There have been recent changes to how MAC enrollment can be done.
      Check out the docs for more guidance
      docs.microsoft.com/en-us/mem/intune/user-help/enroll-your-device-in-intune-macos-cp
      docs.microsoft.com/en-us/mem/intune/enrollment/macos-enroll

  • @billymedia177
    @billymedia177 2 роки тому

    Why does it tell you to create a computer account? I would think i should be signing into my azure AD account like windows. I dont want my users creating an account. Would be too much for them. Is there a way I can skip that?

  • @eg4am1
    @eg4am1 2 роки тому +4

    Excellent Ben & Steve. I have done everything as you have shown in the video, my MacBook pro is showing in Enrollment program tokens and also in Apple business manager. When I boot the device it tries to connect to our MDM server in Azure but I get an error "Unable to connect to MDM server" any ideas why this might be?

    • @chrislamonte8554
      @chrislamonte8554 2 роки тому +1

      did you ever find a solution to this? we are having the same error.

    • @eg4am1
      @eg4am1 2 роки тому +2

      @@chrislamonte8554 I deleted all the connections and tokens and started again. It worked. Though we have now moved to Jamf which is miles better at managing apple devices

  • @jonathanp6508
    @jonathanp6508 3 роки тому +2

    Thanks guys, Did you guys make a video how to enroll IOS devices ?

  • @christianjrgensen6466
    @christianjrgensen6466 2 роки тому +2

    This is brilliant! Will the Apple Configurator be available for iOS/iPhones aswell after beta? Or will you still be forced to sideload the app?

    • @IntuneTraining
      @IntuneTraining  2 роки тому +1

      I assume it will be in the app store for iOS devices, but we are not in a position to commit to the direction for the Apple roadmap

    • @schiefvancleef
      @schiefvancleef 2 роки тому

      The Apple Configurator App will be available at the Public iOS/iPadOS AppStore, as well as the Apple Configurator 2 App at the Mac AppStore.

    • @Dreas204
      @Dreas204 2 роки тому

      @@schiefvancleef Unfortunately, I personally dont see Configurator 2 at all

  • @jacksonmullen5246
    @jacksonmullen5246 3 роки тому +2

    Do you know if microsoft/apple are planning to implement a solution similar to jamf that will allow the use of an AAD account to authenticate/sign in to a macbook?

    • @Schnitzer325ci
      @Schnitzer325ci 2 роки тому

      I think the only option would be hybrid. I know you can use an AD account to sign in once the Mac has been domain joined.

  • @DaleHiltner
    @DaleHiltner 2 роки тому +1

    I have followed all the steps and it didn't work. Configured the Enrollment Program Token and Created the Enrollment profile for the macOS. I then erased content and settings on the MAC mini OS v.12.4, and added it to ABM via the configurator app. I then assigned the MDM server in to the device in ABM, did a sync in Intune and the device showed up in in device list under the Enrollment Program Token. I then assigned the macOS enrollment profile to the device. Then I powered on the mac and never got the Remote Management screen during setup.
    How did it work for you guys? Is there a group somewhere that I need to assign the device to?

    • @sachutharaman
      @sachutharaman Рік тому

      I'm also stuck at the same place now, Did you find any solution?

  • @samwu8285
    @samwu8285 Рік тому

    After my MacBook is enrolled to MDM server, I can still delete the management profile by pressing minus "-" icon without any restrictions. The Apple ID I used is a standard user profile. Any idea how to prevent standard user from doing this?

    • @DankLordvsGames
      @DankLordvsGames Рік тому

      The enrollment token profile can be set to "Locked enrollment" to stop this.

  • @PaulShadwell
    @PaulShadwell 3 роки тому

    Also, how do you add an existing device that a user is already using?

    • @IntuneTraining
      @IntuneTraining  3 роки тому +1

      Currently the work flow is only to reset a device back to factory with the latest beta of both macOS and iOS

    • @davveedoff
      @davveedoff 2 роки тому

      @@IntuneTraining what about using an emulator for iOS ? (don't want to wipe my phone..)

    • @IntuneTraining
      @IntuneTraining  2 роки тому +2

      We haven't found an emulator that works for the workflows we are testing.

  • @nissetuta
    @nissetuta 9 місяців тому

    Youre video resolution is really to low.