# Intune documentation
*OS:* MacOS
*Version:* v1.0
*Generated:* 2024-08-30
## Table of Contents
- [Device configuration](#section-1)
- [Settings Catalog](#section-2)
- [MacOS - OIB - Authentication - D - Platform SSO - v1.0](#section-3)
- [MacOS - OIB - Defender Antivirus - D - Antivirus Configuration - v1.0](#section-4)
- [MacOS - OIB - Defender Antivirus - D - MDE Configuration - v1.0](#section-5)
- [MacOS - OIB - Device Security - D - Accounts and Login - v1.0](#section-6)
- [MacOS - OIB - Device Security - D - Restrictions - v1.0](#section-7)
- [MacOS - OIB - Disk Encryption - D - FileVault - v1.0](#section-8)
- [MacOS - OIB - Firewall - D - Gatekeeper - v1.0](#section-9)
- [MacOS - OIB - Microsoft AutoUpdate - D - MAU Configuration - v1.0](#section-10)
- [MacOS - OIB - Microsoft Edge - D - Password Management - v1.0](#section-11)
- [MacOS - OIB - Microsoft Edge - D - Security - v1.0](#section-12)
- [MacOS - OIB - Microsoft Edge - U - Extensions - v1.0](#section-13)
- [MacOS - OIB - Microsoft Edge - U - Profiles, Sign-In and Sync - v1.0](#section-14)
- [MacOS - OIB - Microsoft Edge - U - Updates - v1.0](#section-15)
- [MacOS - OIB - Microsoft Office - D - Office Configuration - v1.0](#section-16)
- [MacOS - OIB - Microsoft OneDrive - D - Service and Access - v1.0](#section-17)
- [MacOS - OIB - Microsoft OneDrive - U - Known Folder Move - v1.0](#section-18)
- [MacOS - OIB - Updates - D - Update Configuration - v1.0](#section-19)
| Top Level Setting Group Collection |
Not configured |
| Extension Identifier |
com.microsoft.CompanyPortalMac.ssoextension |
| Team Identifier |
UBF8T346G9 |
| Type |
Redirect |
| Extension Data |
Not configured |
| Type |
String |
| Value |
com.microsoft.,com.apple. |
| Key |
AppPrefixAllowList |
| Type |
Integer |
| Value |
1 |
| Key |
browser_sso_interaction_enabled |
| Type |
Integer |
| Value |
1 |
| Key |
disable_explicit_app_prompt |
| URLs |
https://login.microsoftonline.com;https://login.microsoft.com;https://sts.windows.net |
| Screen Locked Behavior |
Do Not Handle |
| Authentication Method (Deprecated) |
UserSecureEnclaveKey |
| Registration Token |
{{DEVICEREGISTRATION}} |
| Platform SSO |
Not configured |
| Authentication Method |
UserSecureEnclaveKey |
| Use Shared Device Keys |
Enabled |
| Enable Create User At Login |
Enabled |
| Enable Authorization |
Enabled |
| Token To User Mapping |
Not configured |
| Account Name |
preferred_username |
| Full Name |
name |
| New User Authorization Mode |
Standard |
| User Authorization Mode |
Standard |
###### Table 2. Settings - MacOS - OIB - Authentication - D - Platform SSO - v1.0
| Disallowed threat actions |
allow;restore |
| Enforcement level |
real_time |
| Exclusions merge |
admin_only |
| Run a scan after definitions are updated |
Enabled |
| Scanning inside archive files |
True |
| Threat type settings |
Not configured |
| Threat type |
potentially_unwanted_application |
| Action to take |
block |
| Threat type |
archive_bomb |
| Action to take |
block |
| Threat type settings merge |
admin_only |
| Automatic security intelligence updates |
Enabled |
| Cloud Block Level |
normal |
| Diagnostic collection level |
optional |
| Enable / disable automatic sample submissions |
Enabled |
| Enable / disable cloud delivered protection |
Enabled |
| Enable / disable early preview |
Disabled |
| Use System Extensions |
enabled |
| Enforcement level |
block |
| Enforcement level |
block |
| Process exclusions |
Not configured |
| Process path |
/Library/Intune/Microsoft Intune Agent.app/Contents/MacOS/IntuneMdmDaemon |
| Process's TeamIdentifier |
UBF8T346G9 |
| Process's Signing Identifier |
IntuneMdmDaemon |
| Control sign-in to consumer version |
disabled |
| Show / hide status menu icon |
Disabled |
###### Table 4. Settings - MacOS - OIB - Defender Antivirus - D - Antivirus Configuration - v1.0
| Top Level Setting Group Collection |
Not configured |
| Rules |
Not configured |
| Rule Type |
Label Prefix |
| Rule Value |
com.microsoft.fresno |
| Rule Type |
Label Prefix |
| Rule Value |
com.microsoft.dlp |
| Applications |
Not configured |
| Microsoft Defender |
Not configured |
| Microsoft Defender Application ID |
WDAV00 |
| Microsoft Defender LCID |
1033 |
| Update channel override |
Current Channel |
| Top Level Setting Group Collection |
Not configured |
| Services |
Not configured |
| Accessibility |
Not configured |
| Identifier |
com.microsoft.dlp.daemon |
| Identifier Type |
bundle ID |
| Code Requirement |
identifier "com.microsoft.dlp.daemon" and anchor apple generic and certificate 1[field.1.2.840.113635.100.6.2.6] /`* exists `*/ and certificate leaf[field.1.2.840.113635.100.6.1.13] /`* exists `*/ and certificate leaf[subject.OU] = UBF8T346G9 |
| Static Code |
False |
| Allowed |
True |
| Authorization |
Allow |
| System Policy All Files |
Not configured |
| Identifier |
com.microsoft.wdav |
| Identifier Type |
bundle ID |
| Code Requirement |
identifier "com.microsoft.wdav" and anchor apple generic and certificate 1[field.1.2.840.113635.100.6.2.6] /`* exists `*/ and certificate leaf[field.1.2.840.113635.100.6.1.13] /`* exists `*/ and certificate leaf[subject.OU] = UBF8T346G9 |
| Static Code |
False |
| Allowed |
True |
| Authorization |
Allow |
| Identifier |
com.microsoft.wdav.epsext |
| Identifier Type |
bundle ID |
| Code Requirement |
identifier "com.microsoft.wdav.epsext" and anchor apple generic and certificate 1[field.1.2.840.113635.100.6.2.6] /`* exists `*/ and certificate leaf[field.1.2.840.113635.100.6.1.13] /`* exists `*/ and certificate leaf[subject.OU] = UBF8T346G9 |
| Static Code |
False |
| Allowed |
True |
| Authorization |
Allow |
| Identifier |
com.microsoft.dlp.daemon |
| Identifier Type |
bundle ID |
| Code Requirement |
identifier "com.microsoft.dlp.daemon" and anchor apple generic and certificate 1[field.1.2.840.113635.100.6.2.6] /`* exists `*/ and certificate leaf[field.1.2.840.113635.100.6.1.13] /`* exists `*/ and certificate leaf[subject.OU] = UBF8T346G9 |
| Static Code |
False |
| Allowed |
True |
| Authorization |
Allow |
| Bluetooth Always |
Not configured |
| Identifier |
com.microsoft.dlp.daemon |
| Identifier Type |
bundleID |
| Code Requirement |
identifier "com.microsoft.dlp.daemon" and anchor apple generic and certificate 1[field.1.2.840.113635.100.6.2.6] /`* exists `*/ and certificate leaf[field.1.2.840.113635.100.6.1.13] /`* exists `*/ and certificate leaf[subject.OU] = UBF8T346G9 |
| Static Code |
Disabled |
| Allowed |
Allowed |
| Authorization |
Allow |
| Top Level Setting Group Collection |
Not configured |
| Allowed System Extensions |
Not configured |
| Allowed System Extensions |
com.microsoft.wdav.epsext;com.microsoft.wdav.netext |
| Team Identifier |
UBF8T346G9 |
| Top Level Setting Group Collection |
Not configured |
| Notification Settings |
Not configured |
| Bundle Identifier |
com.microsoft.wdav.tray |
| Notifications Enabled |
True |
| Show In Notification Center |
True |
| Show In Lock Screen |
False |
| Alert Type |
Temporary Banner |
| Badges Enabled |
True |
| Sounds Enabled |
True |
| Critical Alert Enabled |
False |
| Top Level Setting Group Collection |
Not configured |
| User Defined Name |
Microsoft Defender Content Filter |
| Plugin Bundle ID |
com.microsoft.wdav |
| Organization |
JAMF Software |
| Filter Sockets |
True |
| Filter Data Provider Designated Requirement |
identifier "com.microsoft.wdav.netext" and anchor apple generic and certificate 1[field.1.2.840.113635.100.6.2.6] /`* exists `*/ and certificate leaf[field.1.2.840.113635.100.6.1.13] /`* exists `*/ and certificate leaf[subject.OU] = UBF8T346G9 |
| Filter Data Provider Bundle Identifier |
com.microsoft.wdav.netext |
| Filter Packets |
False |
| Filter Grade |
inspector |
###### Table 6. Settings - MacOS - OIB - Defender Antivirus - D - MDE Configuration - v1.0
| Top Level Setting Group Collection |
Not configured |
| Disabled Preference Panes |
com.apple.AirDrop-Handoff-Settings.extension;com.apple.Family-Settings.extension;com.apple.Game-Center-Settings.extension;com.apple.Siri-Settings.extension;com.apple.Startup-Disk-Settings.extension;com.apple.Time-Machine-Settings.extension;com.apple.WalletSettingsExtension;com.apple.systempreferences.AppleIDSettings |
| Top Level Setting Group Collection |
Not configured |
| Allow Account Modification |
False |
| Allow Activity Continuation |
False |
| Allow Adding Game Center Friends |
False |
| Allow AirDrop |
False |
| Allow Air Play Incoming Requests |
Disabled |
| Allow Apple Personalized Advertising |
False |
| Allow Assistant |
False |
| Allow Auto Unlock |
False |
| Allow Bluetooth Sharing Modification |
False |
| Allow Cloud Address Book |
False |
| Allow Cloud Bookmarks |
False |
| Allow Cloud Calendar |
False |
| Allow Cloud Desktop And Documents |
False |
| Allow Cloud Document Sync |
False |
| Allow Cloud Freeform |
False |
| Allow Cloud Keychain Sync |
False |
| Allow Cloud Mail |
False |
| Allow Cloud Notes |
False |
| Allow Cloud Photo Library |
False |
| Allow Cloud Private Relay |
False |
| Allow Cloud Reminders |
False |
| Allow Device Name Modification |
False |
| Allow Erase Content And Settings |
False |
| Allow File Sharing Modification |
False |
| Allow Find My Device |
False |
| Allow Find My Friends |
False |
| Allow Game Center |
False |
| Allow Internet Sharing Modification |
False |
| Allow iTunes File Sharing |
False |
| Allow Local User Creation |
False |
| Allow Multiplayer Gaming |
False |
| Allow Password Proximity Requests |
False |
| Allow Password Sharing |
False |
| Allow Printer Sharing Modification |
False |
| Allow Startup Disk Modification |
False |
| Safari Allow Autofill |
False |
###### Table 10. Settings - MacOS - OIB - Device Security - D - Restrictions - v1.0
| Top Level Setting Group Collection |
Not configured |
| Enable |
On |
| Force Enable In Setup Assistant |
True |
| Recovery Key Rotation In Months |
6 months |
| Top Level Setting Group Collection |
Not configured |
| Prevent FileVault From Being Disabled |
True |
| Top Level Setting Group Collection |
Not configured |
| Location |
You can retrieve the personal recovery key for your macOS device from the Microsoft Intune app, Company Portal website, or Company Portal apps for Android and iOS/iPadOS. Support cannot access recovery keys that belong to personal devices. |
###### Table 12. Settings - MacOS - OIB - Disk Encryption - D - FileVault - v1.0
| Top Level Setting Group Collection |
Not configured |
| Rules |
Not configured |
| Rule Type |
Bundle Identifier |
| Rule Value |
com.microsoft.autoupdate2 |
| Comment |
MAU |
| Automatically acknowledge data collection policy |
Acknowledge - send required data |
| Days before forced updates |
14 |
| Deferred updates |
Defer 3 days |
| Disable Office Insider membership |
True |
| Enable AutoUpdate |
True |
| Enable check for updates |
True |
| Guard against app modification |
Disabled |
| Register app on launch |
True |
| Update cache server |
https://officecdn.microsoft.com/pr/C1297A47-86C4-4C1F-97FA-950631F94777/OfficeMac/ |
| Update channel |
Current Channel |
| Updater optimization technique |
Lower network overhead |
###### Table 16. Settings - MacOS - OIB - Microsoft AutoUpdate - D - MAU Configuration - v1.0
| Microsoft Edge |
| Ads setting for sites with intrusive ads |
Block ads on sites with intrusive ads. (Default value) |
| Allow download restrictions |
Block dangerous downloads |
| Allow importing of browser settings |
Disabled |
| Allow importing of browsing history |
Disabled |
| Allow importing of home page settings |
Disabled |
| Allow importing of payment info |
Disabled |
| Allow importing of saved passwords |
Disabled |
| Allow importing of search engine settings |
Disabled |
| Allow managed extensions to use the Enterprise Hardware Platform API |
Disabled |
| Allow personalization of ads, search and news by sending browsing history to Microsoft |
Disabled |
| Allow queries to a Browser Network Time service |
Enabled |
| Allow user-level native messaging hosts (installed without admin permissions) |
Disabled |
| Automatically import another browser's data and settings at first run |
Disables automatic import, and the import section of the first-run experience is skipped |
| Block tracking of users' web-browsing activity |
Balanced (blocks harmful trackers and trackers from sites user has not visited; content and ads will be less personalized) |
| Clear browsing data when Microsoft Edge closes |
Disabled |
| Clear cached images and files when Microsoft Edge closes |
Disabled |
| Configure Microsoft Defender SmartScreen |
Enabled |
| Configure Microsoft Defender SmartScreen to block potentially unwanted apps |
Enabled |
| Control communication with the Experimentation and Configuration Service |
Disable communication with the Experimentation and Configuration Service |
| DNS interception checks enabled |
Enabled |
| Enable AutoFill for addresses |
Disabled |
| Enable AutoFill for credit cards |
Disabled |
| Enable Google Cast |
Disabled |
| Enable Proactive Authentication |
Disabled |
| Hide the First-run experience and splash screen |
Enabled |
| Minimum TLS version enabled |
TLS 1.2 |
| Prevent bypassing Microsoft Defender SmartScreen prompts for sites |
Enabled |
| Prevent bypassing of Microsoft Defender SmartScreen warnings about downloads |
Enabled |
| Supported authentication schemes |
ntlm,negotiate |
###### Table 20. Settings - MacOS - OIB - Microsoft Edge - D - Security - v1.0
| Top Level Setting Group Collection |
Not configured |
| Rules |
Not configured |
| Rule Type |
Label Prefix |
| Rule Value |
com.microsoft.OneDrive |
| Comment |
OneDrive (Standalone) |
| Rule Type |
Bundle Identifier |
| Rule Value |
com.microsoft.OneDriveLauncher |
| Comment |
OneDrive Launcher |
| Top Level Setting Group Collection |
Not configured |
| Services |
Not configured |
| System Policy All Files |
Not configured |
| Identifier |
com.microsoft.OneDrive |
| Identifier Type |
bundle ID |
| Code Requirement |
identifier "com.microsoft.OneDrive" and anchor apple generic and certificate 1[field.1.2.840.113635.100.6.2.6] /`* exists `*/ and certificate leaf[field.1.2.840.113635.100.6.1.13] /`* exists `*/ and certificate leaf[subject.OU] = UBF8T346G9 |
| Static Code |
False |
| Allowed |
True |
| Authorization |
Allow |
| Top Level Setting Group Collection |
Not configured |
| Allowed System Extensions |
Not configured |
| Allowed System Extensions |
com.microsoft.OneDrive.FinderSync |
| Team Identifier |
UBF8T346G9 |
###### Table 30. Settings - MacOS - OIB - Microsoft OneDrive - D - Service and Access - v1.0
| Automatically and silently enable the Folder Backup feature (Known Folder Move) |
%OrganizationId% |
| Block external sync |
True |
| Disable automatic sign in |
False |
| Disable personal accounts |
True |
| Disable tutorial |
True |
| Display a notification to users once their folders have been redirected |
False |
| Enable Files On-Demand |
True |
| Enable simultaneous edits for Office apps |
True |
| Force users to use the Folder Backup feature (Known Folder Move) |
True |
| Hide dock icon |
True |
| Ignore named files |
`*.lnk;`*.pst;`*.pkg;`*.dmg |
| Include ~/Desktop in Folder Backup (Known Folder Move) |
True |
| Include ~/Documents in Folder Backup (Known Folder Move) |
True |
| Open at login |
True |
| Prompt users to enable the Folder Backup feature (Known Folder Move) |
%OrganizationId% |
###### Table 32. Settings - MacOS - OIB - Microsoft OneDrive - U - Known Folder Move - v1.0