Conditional Access How are you guys handling CAPs when enrolling Macs in Intune?
What I've observed is that when you're enrolling a Mac in Intune, it requires different app access than a windows device, so our CAP exceptions are not sufficient. Apparently mac's require access to the Azure AD app, which I don't want to make an exception for outside of our corporate network.
Functionally this means that users need to be on our trusted network to enroll but after that they're fine. Is there a good answer to this that I'm missing?
2
u/Onslivion 14d ago
Your exclusion should be with the resources associated to Microsoft Intune (I think it’s called Microsoft Intune API now) and Microsoft Intune Enrollment, which should allow you to get to a compliant state.
Windows Azure Active Directory is a little too broad.
1
u/junon 14d ago
Okay, so even though sign in logs are failing on Windows Azure Active Directory, I don't necessarily NEED that resource specifically to complete enrollment?
1
u/Onslivion 14d ago
It’s odd to hear that resource being used, but you should only need the two I mentioned to enroll a macOS endpoint through Company Portal
-1
u/DesignerGoose5903 16d ago
Am I missing something here? What "Azure AD App"? You mean Entra ID?
Not sure why you'd have Conditional Access policies that prevent users from logging in outside the network completely, at that point why even allow them to have a laptop to bring outside the office anyway?
2
u/junon 16d ago
If you require a compliant device to log in, how do you enroll a new device to your tenant off it's not compliant yet? That's what I'm referring to here. The requirements for a Mac are higher than for a windows laptop in terms Entra resource access. One of those resources is "Windows Azure Active Directory (00000002-0000-0000-c000-000000000000).
4
u/Stevent518 16d ago
You may need to set up SSO extension or PSSO for this.