Thursday
Morning All
I have been working for sometime on getting our macs compliant with intune. It does seem to work.
The process seems extremely clunky with users running through the steps in company portal which seems very user driven.
I'm sure I have read somewhere this process has become obsolete, is that right? Is there a better way?
Thanks
Thursday
i use this profile, send it out to all of your target machines, then run your device compliance install
Thursday
what does it do?
I assume you still have push company portal down to the device
Thursday
yes, push company portal, then this profile, which bypasses the users browser settings.
Thursday
So they dont have to go through the config process with company portal or just makes it easier. Sorry for all the questions thanks
Thursday
yes they do, but when the device compliance is initiated, it uses this profile to control it, the end user has to sign in and verify.
Thursday
Are you in Intune or Entra? The Intune Conditional Access was replaced with Entra Device Compliance when Microsoft made API updates last year. Devices should not have live Objects in Intune anymore, everything should be in Entra.
I completely agree this is a very clunky user driven process, mainly because Entra (and Intune before it) are driven by user identity, and there is no way to automate sorting out user identity so the user must be directly involved for just about all troubleshooting.
Thursday
yep entra I belive we had to make some changes when the update was done
Thursday
On your question about whether there’s a better way: We moved away from the Entra Device Compliance workflow earlier this year because its functionality can be replicated more efficiently through other means that are far simpler to troubleshoot.
For example:
Posture Checking via Security Clients:
Jamf App Restrictions:
I plan to revisit Device Compliance in a few months as part of my 2025 review of Microsoft Defender and Purview for macOS. Until then, the alternative workflows have proven faster and less user-driven for us.
What we do may not be ideal for many organizations. However, we really have no need to have our Macs registered in Entra for anything else so it's an easy hassle to not deal with for me.
Saturday
This is the config profile that we used. Users still do have to do the "Register with EntraID", but this configuration script makes life a little easier.