Intune-MacOS
Configure EAP-TLS on Foxpass
Please follow the EAP-TLS initial setup guide to create client CA, server CA and SCEP endpoint if not configured already.
Configure Intune for Initial Setup
If you are configuring SCEP certificates for both Windows and macOS, you only need to follow the initial setup documentation once
Please refer the Intune for Initial Setup documentation to configure the Intune initially.
Upload Apple MDM Push Certificate
-
In the Endpoint manager, now go to devices → macOS enrollment.
-
Click on Apple MDM Push Certificate.
-
A dialog box will open at the right side to configure MDM Push certificate.
Configure MDM Push Certificate
-
Click on Download your CSR link.
Download your CSR
-
Click on Create your MDM push certificate./
Create your MDM push certificate
-
Sign in to your Apple account and click Create a certificate button.
Create a certificate
-
Upload previously downloaded CSR.
Upload CSR
-
You will see a confirmation message of certificate created. Click on 'Download' button.
Download certificate
-
Upload the downloaded certificate in Intune.
Upload push certificate
Create Configuration Profiles
- Go to the configuration profiles of macOS. Click on Create > New Policy.
![Click 'Create'](https://files.readme.io/31840fa-Screenshot_2024-01-12_at_1.46.01_PM.png)
Click 'Create'
Create a Client CA Profile
- Create a new Client CA profile for macOS using the Trusted certificate template. Upload the Foxpass Client CA cert in the client profile.
![Review and Click Create profile](https://files.readme.io/c21179d-Screenshot_2024-01-12_at_2.07.35_PM.png)
Review and Click Create profile
Create a Server CA profile
- Create a new profile for macOS using the Trusted certificate template. Upload the Foxpass Server CA cert in the server profile.
![Foxpass Server CA Profile](https://files.readme.io/1fbbc39-Screenshot_2024-01-12_at_2.28.56_PM.png)
Foxpass Server CA Profile
Create a SCEP profile
- Make sure the SCEP endpoint is configured correctly in Foxpass.
- Create another new profile for macOS using the SCEP certificate template with these settings:
You need to make sure that every user has an EmailAddress set in their Azure User Profile. If not, SCEP the profiles will not install.
-
Name: Foxpass SCEP
-
Certificate type: User
-
Subject name format: CN={{UserName}},E={{EmailAddress}}
-
Subject alternative name: Add 1 attribute:
- Email address as {{EmailAddress}}
-
Certificate Validity period: Years: 1
-
Key usage: Digital Signature
-
Key size: 4096
-
Hash algorithm: SHA2
-
Root certificate: Select cert from Foxpass Client CA from first item in this section
-
Extended key usage: Add both
- Any Purpose (2.5.29.37.0)* (optional)
- Client Authentication (1.3.6.1.5.5.7.3.2)*
-
Renewal threshold (%): 10
-
SCEP server URL: Foxpass SCEP endpoint from the SCEP page
![Sample SCEP Profile](https://files.readme.io/7270118-Screenshot_2024-08-12_at_12.07.35_PM.png)
Sample SCEP Profile
Create a Wi-Fi Profile
- Go to Configuration Profiles of macOS devices > Create New Policy > Profile Type > Templates > Choose WiFi as the template name.
- Name: Foxpass Wi-Fi
- Wi-Fi Type - Enterprise
- SSID -
- Connect automatically: (your choice)
- Hidden network: Disable
- Security Type: WPA/WPA2 Enterprise
- Proxy settings: None
- EAP-Type: EAP-TLS
- Root certificates for server validation: (Choose Foxpass Server CA uploaded previously in this step)
- Client Authentication - Certificates: Foxpass SCEP
![Review Wi-Fi profile](https://files.readme.io/1c9e4c3-Screenshot_2024-01-16_at_11.45.08_AM.png)
Review Wi-Fi profile
Now, setup your Macbook
- Download and install Intune Company Portal from the App Store.
![Install Company Portal](https://files.readme.io/646e49d-Screenshot_2024-01-16_at_11.48.51_AM.png)
Install Company Portal
- Open the Company Portal app and sign in. Click 'Begin' > Continue.
![Click Begin](https://files.readme.io/8f666b1-Screenshot_2024-01-16_at_11.50.36_AM.png)
Click Begin
- Click on the Download Profile.
- Go to System settings > Profile > Management Profile
- Install the management profile.
![Install the management profile](https://files.readme.io/524386d-WhatsApp_Image_2024-01-16_at_5.29.42_PM.jpeg)
Install the management profile
If all goes well, you will now be able to see your device enrolled in Intune and the Foxpass Console's EAP-TLS.
![macoS device enrolled in Intune](https://files.readme.io/abb9757-Screenshot_2024-01-16_at_5.34.42_PM.png)
macoS device enrolled in Intune
![Foxpass SCEP - Intune](https://files.readme.io/5adadbb-Screenshot_2023-08-29_at_11.07.59_AM.png)
Client Certificate - Foxpass
You can see Foxpass Client CA, Server CA and Client Certificate in Keychain Access on your Macbook.
![Certificate and CA's in Keychain Access](https://files.readme.io/1822b3b-WhatsApp_Image_2024-01-16_at_6.07.24_PM.jpeg)
Certificate and CA's in Keychain Access
You can also see successful/unsuccessful logs on the RADIUS logs page.
![RADIUS logs page](https://files.readme.io/c9de99e-Screenshot_2023-08-29_at_2.10.00_PM.png)
RADIUS logs page
Still having problems?
Updated 11 days ago