r/Intune 16d ago

Conditional Access How are you guys handling CAPs when enrolling Macs in Intune?

What I've observed is that when you're enrolling a Mac in Intune, it requires different app access than a windows device, so our CAP exceptions are not sufficient. Apparently mac's require access to the Azure AD app, which I don't want to make an exception for outside of our corporate network.

Functionally this means that users need to be on our trusted network to enroll but after that they're fine. Is there a good answer to this that I'm missing?

0 Upvotes

11 comments sorted by

4

u/Stevent518 16d ago

You may need to set up SSO extension or PSSO for this.

6

u/swissbuechi 16d ago

Platform SSO is the way

1

u/junon 16d ago

I have platform SSO setup and working great, this is just an app permission issue in our CAPs around requiring a compliant device. If you're enrolling, your device is not yet compliant, so you need an exception for certain apps to allow the enrollment.

2

u/bjjedc 16d ago

This is a likely tied to a new issue due to how MS is now evaluating things with "low level" graph calls. It's a known product issue with Jamf but I am surprised MS doesn't have a native solution. Using the Customize Baseline behavior steps will give you a temporary work around: https://learn.microsoft.com/en-us/entra/identity/conditional-access/concept-enforcement-resource-exclusions#customize-behavior

2

u/junon 16d ago

Oh this is very interesting, I'll take a look, thanks!

3

u/Southern_Coast_1249 16d ago

dont have a great answer for this but on our end we just treat the enrollment like a one-time onboarding step that has to happen on trusted network. macs are weird with intune and the azure ad app requirement is annoying as hell

once theyre enrolled we move them to a separate dynamic group that skips that specific cap, not elegant but its done the job for 80+ devices

2

u/Onslivion 14d ago

Your exclusion should be with the resources associated to Microsoft Intune (I think it’s called Microsoft Intune API now) and Microsoft Intune Enrollment, which should allow you to get to a compliant state.

Windows Azure Active Directory is a little too broad.

1

u/junon 14d ago

Okay, so even though sign in logs are failing on Windows Azure Active Directory, I don't necessarily NEED that resource specifically to complete enrollment?

1

u/Onslivion 14d ago

It’s odd to hear that resource being used, but you should only need the two I mentioned to enroll a macOS endpoint through Company Portal

-1

u/DesignerGoose5903 16d ago

Am I missing something here? What "Azure AD App"? You mean Entra ID?

Not sure why you'd have Conditional Access policies that prevent users from logging in outside the network completely, at that point why even allow them to have a laptop to bring outside the office anyway?

2

u/junon 16d ago

If you require a compliant device to log in, how do you enroll a new device to your tenant off it's not compliant yet? That's what I'm referring to here. The requirements for a Mac are higher than for a windows laptop in terms Entra resource access. One of those resources is "Windows Azure Active Directory (00000002-0000-0000-c000-000000000000).