Enroll Macs in Intune: ADE or BYOD
Enroll your Macs in Microsoft Intune via Automated Device Enrollment for company devices or Company Portal for BYOD, explained step by step for SMBs.
Macs are increasingly common in SMBs, yet they often sit outside the management perimeter, handled by hand or not at all. Enrolling them in Intune lets you apply the same security requirements as on Windows: FileVault encryption, forced updates, firewall, compliance policies. Two enrolment paths exist, and the right one depends above all on who owns the device.
Choosing the right path from the start avoids tedious rework. A Mac bought by the company and a personal Mac brought in by an employee call for neither the same level of control nor the same enrolment experience. Understanding that distinction is the first step towards clean, durable macOS management rather than a one-off that drifts over time.
Automated Device Enrollment: for company Macs
Automated Device Enrollment (ADE, via Apple Business Manager) is for Macs bought by the company. The device is tied to the tenant from purchase: on first setup it enrols into Intune automatically, with no user action and no way for the user to opt out.
- Zero-touch enrolment, straight out of the box, ideal for shipping a Mac directly to a new hire's home.
- Supervised management: more control, including policies the user cannot bypass.
- Ideal for large-scale rollout and for guaranteeing compliance from day one.
Supervised mode, unique to ADE, unlocks controls that are impossible otherwise: enforcing FileVault so the user cannot decline, preventing unenrolment, or locking down certain system settings. For a work Mac, that is the foundation that keeps compliance in place over time, even if a user tries to opt out. It is also what separates a mere enrolment from genuinely controlled management.
Company Portal: for BYOD
For personal Macs used at work (BYOD), the user installs the Intune Company Portal app and enrols manually. Management is then less intrusive, respecting privacy on a device the company does not own and reassuring reluctant employees.
BYOD is a trade-off: you gain visibility and compliance on devices you do not own, without fully supervising them. In practice, you target these Macs with compliance policies and Conditional Access, so a non-compliant device is refused access to company resources rather than being forced into changes. The pressure is on access, not on the personal device itself, which keeps the arrangement fair to the employee.
- 1The user downloads Company Portal from Intune.
- 2They sign in with their Microsoft Entra identity.
- 3A management profile is installed and the device appears in Intune.
- 4The targeted compliance and configuration policies apply.
In both cases an Apple MDM connector (Apple push certificate, plus Apple Business Manager for ADE) must be configured on the Intune side first. That certificate is what authorises Intune to manage Apple devices; it must be renewed every year. Set a calendar reminder for that renewal, because a lapsed certificate silently stops all Apple device management until it is replaced.
Choosing the right method
Company-purchased device? ADE. User's personal device? Company Portal.
Once the Mac is enrolled, you can move on to the essential protections: FileVault with key escrow, application firewall, forced updates and compliance policies paired with Conditional Access. Enrolment is only the entry point; its real value comes from the policies applied afterwards, which finally bring your Macs up to the same security level as your Windows machines.
Prepare the ground before enrolling
Before the first enrolment, two prerequisites save a lot of trouble. First, the Apple MDM connector and its push certificate must be valid; an expired certificate cuts management of every Mac at once, with no immediate warning. Second, for ADE the devices must appear in Apple Business Manager and be assigned to Intune as the MDM server.
Plan an enrolment profile as well, defining the setup experience: the steps shown to the user, supervised mode, and any authentication at enrolment. A well-thought-out profile makes a new Mac's arrival smooth, with no technical handling on the user's side, and gives a good first impression of the company's tooling.
Common mistakes to avoid
Mac enrolment tends to run into the same obstacles, all easy to anticipate once you know them.
- Forgetting to renew the Apple push certificate before it expires, and losing management of the entire Mac fleet.
- Using ADE for personal devices, forcing an unwelcome level of supervision onto a private Mac.
- Neglecting the enrolment profile, leaving the user facing a confusing setup.
- Enrolling Macs without chaining any security policy, and ending up with devices that are managed but not protected.
After enrolment: the first policies to chain
Once the Mac is visible in Intune, enrolment is only worth something if it leads to concrete policies. The classic mistake is to stop there and end up with devices that are managed but not protected. Here is the logical order of the protections to apply first, from the most critical to the most convenient.
- 1Enable FileVault with recovery-key escrow to encrypt the disk.
- 2Deploy the macOS application firewall and stealth mode to close inbound connections.
- 3Enforce critical macOS updates through a dedicated update policy.
- 4Create a compliance policy requiring encryption and a minimum version, paired with Conditional Access.
- 5Distribute business apps through Intune rather than letting each user install them by hand.
This sequence gradually brings your Macs up to the same security level as your Windows machines. By treating enrolment and hardening as a single project rather than two separate efforts, you avoid the limbo where a device is already in use but still unprotected. It is also the ideal moment to check in the reports that each policy actually applies before onboarding new users.
How AuPoint simplifies bringing Macs in
Setting up the Apple connector, telling ADE and BYOD apart and chaining the right policies can be discouraging when you are new to macOS in Intune. AuPoint is a SaaS that makes Intune security and compliance easy, with no PowerShell. It guides enrolment and offers ready-made macOS policies, with an impact preview and one-click reversibility, so your Macs are managed and protected from day one.
Frequently asked questions
Can a Mac move from BYOD to ADE later?
Not directly: ADE assumes the device is linked to Apple Business Manager, which normally happens at purchase through an authorised reseller. A BYOD-enrolled Mac can, however, be unenrolled and re-enrolled via ADE if it is added to ABM, but that means a full reconfiguration.
Can the company see personal data on a BYOD Mac?
No. In BYOD, management is deliberately limited: Intune applies compliance and configuration policies but does not give access to the user's personal content. That is what makes this mode acceptable on a private device.
Do I need an Apple Business Manager licence?
Apple Business Manager is a free Apple service. Your Macs do need to be linked to it, usually via your reseller or Apple directly, and the MDM connector must be configured on the Intune side with a valid push certificate. Once that groundwork is in place, adding further Apple devices to management becomes almost effortless.
How long does enrolling a Mac take?
Enrolment itself takes only a few minutes: with ADE it is built into the Mac's initial setup assistant; with BYOD, installing Company Portal and signing in take a similar amount of time. Fully applying the targeted policies can then take a little longer, while the device pulls down each profile and reports its state back to Intune.
Connect your Microsoft tenant to AuPoint and bring your Macs into Intune cleanly, from enrolment through hardening, with an impact preview and reversibility, no PowerShell. Start free at aupoint.io.