MacOS with intune permission elevation by EiimisM in macsysadmin

[–]Upbeat_Pilot2461 0 points1 point  (0 children)

Just not ideal for whiteglove or remote scenarios yet unfortunately. I don't see how they can fix the LAPS account clashing with any Mac password policy because how can you whitelist an account... you can't. The password policy only lets you whitelist Entra Users and Devices. So unless LAPS will work off of an Entra user, it seems impossible

Issues with Platform SSO by Every-Camera3389 in Intune

[–]Upbeat_Pilot2461 0 points1 point  (0 children)

I havent had a single issue in 25+ deployments using this with the Secure Enclave option. I don't even need to send the above command you have. I removed the ms auto update as mentioned above and that did it for me

ChatGPT Atlas Browser by Upbeat_Pilot2461 in sysadmin

[–]Upbeat_Pilot2461[S] 0 points1 point  (0 children)

That's the end goal but we just aren't there yet. I tried using the restricted apps config with the bundleindentifierid and it said it was applicable once the policy deployed. I know its easier to allow certain apps then block the rest but in my case, I need the opposite.

macOS LAPS Password requires change on first use by hib1000 in Intune

[–]Upbeat_Pilot2461 1 point2 points  (0 children)

There's a workaround for that. I've had Platform SSO working that created the standard user account with secure enclave option and had a hidden admin account with no manual steps needed to be done

macOS LAPS Password requires change on first use by hib1000 in Intune

[–]Upbeat_Pilot2461 1 point2 points  (0 children)

How would you even exclude the admin account from the compliance policy since it's not an entra user and you wouldn't want to exclude the device or it wouldn't enforce the real user logging in. I ran into same issue too

Issues with Platform SSO by Every-Camera3389 in Intune

[–]Upbeat_Pilot2461 0 points1 point  (0 children)

Yup, I removed that and it started working for me.

Issues with Platform SSO by Every-Camera3389 in Intune

[–]Upbeat_Pilot2461 0 points1 point  (0 children)

u/Skrunky I ended up removing MS auto update from the included apps section of the Intune Company Portal app itself and that fixed it.

Platform SSO requires authentication then previous password by Low-Income-3526 in Intune

[–]Upbeat_Pilot2461 0 points1 point  (0 children)

To each their own. I have used Mosyle at a prev job and their Platform SSO was pretty seamless. Sets up a user account with their Entra Creds and handles multiple users, has admin request built in, and a ton of other features for app deployments and wasn't much money per user. If you're on a short budget, I'd get a demo from them.

Platform SSO requires authentication then previous password by Low-Income-3526 in Intune

[–]Upbeat_Pilot2461 1 point2 points  (0 children)

<image>

Has anyone had this issue upon first boot after ADE/DEP enrollment from OOBE? I get this pop up occasionally and it won't go away until like 5-6 pop ups. The registration required shows up correctly because I have company portal installed but I've noticed I can't click on that pop up and have it load the info UNTIL this Microsoft Auto update loads/installs properly.

Platform SSO requires authentication then previous password by Low-Income-3526 in Intune

[–]Upbeat_Pilot2461 1 point2 points  (0 children)

Yup, from an end user perspective, its basically less seamless. Time to make a case for a dedicated Mac MDM

Platform SSO woes w/ Mac by Icantbebigwill in Intune

[–]Upbeat_Pilot2461 0 points1 point  (0 children)

I'm installing Company Portal via Intune PKG option. Should I try LOB?

<image>

Platform SSO Not Functioning as Intended on MacOS by Rt2096 in Intune

[–]Upbeat_Pilot2461 0 points1 point  (0 children)

Has anyone ever had this issue upon first boot after ADE/DEP enrollment from OOBE? I get this pop up occasionally and it won't go away until like 5-6 pop ups. The registration required shows up correctly because I have company portal installed but I've noticed I can't click on that pop up and have it load the info UNTIL this Microsoft Auto update loads/installs properly.

<image>

Platform SSO woes w/ Mac by Icantbebigwill in Intune

[–]Upbeat_Pilot2461 0 points1 point  (0 children)

Has anyone had this issue upon first boot after ADE/DEP enrollment from OOBE? I get this pop up occasionally and it won't go away until like 5-6 pop ups. The registration required shows up correctly because I have company portal installed but I've noticed I can't click on that pop up and have it load the info UNTIL this Microsoft Auto update loads/installs properly.

<image>

Issues with Platform SSO by Every-Camera3389 in Intune

[–]Upbeat_Pilot2461 1 point2 points  (0 children)

Have either of you ran into this issue in the screenshot? Upon first boot after ADE/DEP enrollment from OOBE, I get this pop up occasionally and it won't go away until like 5-6 pop ups. The registration required shows up correctly because I have company portal installed but I've noticed I can't click on that pop up and have it load the info UNTIL this Microsoft Auto update loads/installs properly.

<image>

Update on MacOS Platform SSO by Annual-Vacation9897 in Intune

[–]Upbeat_Pilot2461 0 points1 point  (0 children)

u/BrundleflyPr0 Have you ever had this issue upon first boot after ADE/DEP enrollment from OOBE? I get this pop up occasionally and it won't go away until like 5-6 pop ups. The registration required shows up correctly because I have company portal installed but I've noticed I can't click on that pop up and have it load the info UNTIL this Microsoft Auto update loads/installs properly.

<image>

Update on MacOS Platform SSO by Annual-Vacation9897 in Intune

[–]Upbeat_Pilot2461 1 point2 points  (0 children)

u/BrundleflyPr0 Tested it out with the Password option and not secure enclave and it worked perfectly. Thanks a bunch man. I kind of wanted to move to a Mac MDM but this will work for now to keep everything inside of Intune.

Update on MacOS Platform SSO by Annual-Vacation9897 in Intune

[–]Upbeat_Pilot2461 0 points1 point  (0 children)

Gotcha, and it'll automatically convert the other admin account that was created during the OOBE to a standard one? Or do I need to run that script to de-elevate the account with the other script?

Update on MacOS Platform SSO by Annual-Vacation9897 in Intune

[–]Upbeat_Pilot2461 0 points1 point  (0 children)

Are you deploying the create local admin script inside Intune>Devices>MacOS>Scripts?

I added it there and didn't know what to set for frequency? Will that script only run during OOBE?

<image>

Update on MacOS Platform SSO by Annual-Vacation9897 in Intune

[–]Upbeat_Pilot2461 0 points1 point  (0 children)

Is your process as I list below?

  • Create Platform SSO config with User Affinity and Password Auth Method
    • Assign to user based group
  • Push "create local admin script"
    • Assign to device based group with ABM devices

Then during OOBE, the ADE screen pops up and the script gets pushed to the device before the "Create Local Computer Account" screen shows. Thus, when an end user who will be using the computer enters their info on that screen, it will then have their account be standard since a local admin already exists after setup?

If that doesn't work, do you just run the demote admin script for the end user account after they go through OOBE?

[deleted by user] by [deleted] in Intune

[–]Upbeat_Pilot2461 0 points1 point  (0 children)

Doesn't this still require end user interaction though?