VBallantyne Posted October 18, 2024 Posted October 18, 2024 Hey all, Ok, so managed the basics fine, I've configured a macOS device to be enrolled into Intune successfully fairly straight forward. I'm able to log onto the device with a Microsoft 365 email account. The problem I am having is meeting the requirements set out by the school. For Windows devices I am able to add a domain prefix so when logging in we only have to enter the samaccountname (Username) i.e. "Student" rather than the full UPN [email protected] Anyone made this work? Next issue is, the Token To User Mapping. I cant seem to find any other values or variables that could be used in the Account Name. Only option provided in documentation is userPrincipalName. Yet the local account created on the macOS ends up being the email address (almost). The Display name is Student but the account name becomes studentmhs.bright-futures.co.uk. It misses out the "@" because a macOS local account cant include an "@" This becomes a problem because I have a SMB share shortcut configured on the Dock but it prepopulates the username field with studentmhs.bright-futures.co.uk so having to manually enter in the "@". I noticed if I just enter "Student" the share works. So ideally I need a new variable in the Token to User Mapping that creates the local macOS account as just the Username and not the full UPN. Hopefully that would kill two birds with one stone with the domain prefix also just being the username and not the full UPN. Thoughts anyone? Thanks
Bankesy Posted October 18, 2024 Posted October 18, 2024 @VBallantyne I'm afraid I don't have anything useful to tell you in terms of your problem but your post grabbed my interest because we too have just started looking at how we will manage our Mac refresh and I have purchased one new Mac to manage via Intune. I got it enrolled but didn't do what you have regarding logins with 365 accounts, I just bound the device to AD. The problem I am having is deploying 365 Apps for MacOS, have you any experience of this? Thanks
2ilent8cho Posted October 18, 2024 Posted October 18, 2024 I've been watching Platform SSO for over a year now, looks like it's finally close to working. Have you tried asking on MacAdmins on Slack? There is a channel called platform-sso which seems like the most useful place for information.
VBallantyne Posted October 18, 2024 Author Posted October 18, 2024 Cant say I've ever used Slack in my line of work so wouldn't have known about it. Might give it a try, although an area full of MacAdmins I'm worried they laugh a Microsoft 365 guy out of there with pitchforks at the ready!
2ilent8cho Posted October 18, 2024 Posted October 18, 2024 Cant say I've ever used Slack in my line of work so wouldn't have known about it. Might give it a try, although an area full of MacAdmins I'm worried they laugh a Microsoft 365 guy out of there with pitchforks at the ready! �� No, plenty of Microsoft channels in there such as Microsoft-teams, Microsoft-onedrive , I believe some of the Microsoft Mac engineers sometimes hangout in some of the channels too. It's a handy place.
VBallantyne Posted October 18, 2024 Author Posted October 18, 2024 Not knowing your level of integration all I can say is, the ios and macos devices we use are present in Apple School Manager (ASM) either via a reseller or some devices were assigned to the ASM via Apple Configurator. Then the whole enrolment integration for ASM and Intune has been setup with Enrolment tokens / push certificates etc. So for installing Microsoft 365 apps it was just a case of assigning the bult in app profile to all devices, or you could target it to a specific AAD Group:
Bankesy Posted October 18, 2024 Posted October 18, 2024 @VBallantyne Silly question but assigning Microsoft 365 apps to all devices like this I assume Intune is intelligent enough to then only target all macOS devices and not also include all of the Windows devices in the directory? Thanks
VBallantyne Posted October 18, 2024 Author Posted October 18, 2024 In this instance I would have strongly have thought it was intelligent enough as it was the Apps category under macOS and the app itself says Microsoft 365 for macOS. But yes I know where you are coming from with your query. Any concerns, just use the assignment option and apply it to groups defined by you.
Bankesy Posted October 21, 2024 Posted October 21, 2024 @VBallantyne Thanks, assigning to all devices worked. The issue I was having with assignment groups is that the group was showing in Intune but not with the device in it...and yes I had added the device to the group in AD
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now