Files
2025-05-19 15:02:55 -04:00

72 KiB

Intune documentation

OS: MacOS

Version: v1.0

Generated: 2024-08-30

Table of Contents

Device configuration

Settings Catalog

MacOS - OIB - Authentication - D - Platform SSO - v1.0

Name Value
Basics
Name MacOS - OIB - Authentication - D - Platform SSO - v1.0
Description
Profile type Settings catalog
Platform supported macOS
Created 22 August 2024 19:52:01
Last modified 22 August 2024 19:52:01
Scope tags Default
Table 1. Basics - MacOS - OIB - Authentication - D - Platform SSO - v1.0
Name Value
Top Level Setting Group Collection Not configured
Extension Identifier com.microsoft.CompanyPortalMac.ssoextension
Team Identifier UBF8T346G9
Type Redirect
Extension Data Not configured
Type String
Value com.microsoft.,com.apple.
Key AppPrefixAllowList
Type Integer
Value 1
Key browser_sso_interaction_enabled
Type Integer
Value 1
Key disable_explicit_app_prompt
URLs https://login.microsoftonline.com;https://login.microsoft.com;https://sts.windows.net
Screen Locked Behavior Do Not Handle
Authentication Method (Deprecated) UserSecureEnclaveKey
Registration Token {{DEVICEREGISTRATION}}
Platform SSO Not configured
Authentication Method UserSecureEnclaveKey
Use Shared Device Keys Enabled
Enable Create User At Login Enabled
Enable Authorization Enabled
Token To User Mapping Not configured
Account Name preferred_username
Full Name name
New User Authorization Mode Standard
User Authorization Mode Standard
Table 2. Settings - MacOS - OIB - Authentication - D - Platform SSO - v1.0

MacOS - OIB - Defender Antivirus - D - Antivirus Configuration - v1.0

Name Value
Basics
Name MacOS - OIB - Defender Antivirus - D - Antivirus Configuration - v1.0
Description
Profile type Settings catalog
Platform supported macOS
Created 30 August 2024 11:15:48
Last modified 30 August 2024 11:15:48
Scope tags Default
Table 3. Basics - MacOS - OIB - Defender Antivirus - D - Antivirus Configuration - v1.0
Name Value
Disallowed threat actions allow;restore
Enforcement level real_time
Exclusions merge admin_only
Run a scan after definitions are updated Enabled
Scanning inside archive files True
Threat type settings Not configured
Threat type potentially_unwanted_application
Action to take block
Threat type archive_bomb
Action to take block
Threat type settings merge admin_only
Automatic security intelligence updates Enabled
Cloud Block Level normal
Diagnostic collection level optional
Enable / disable automatic sample submissions Enabled
Enable / disable cloud delivered protection Enabled
Enable / disable early preview Disabled
Use System Extensions enabled
Enforcement level block
Enforcement level block
Process exclusions Not configured
Process path /Library/Intune/Microsoft Intune Agent.app/Contents/MacOS/IntuneMdmDaemon
Process's TeamIdentifier UBF8T346G9
Process's Signing Identifier IntuneMdmDaemon
Control sign-in to consumer version disabled
Show / hide status menu icon Disabled
Table 4. Settings - MacOS - OIB - Defender Antivirus - D - Antivirus Configuration - v1.0

MacOS - OIB - Defender Antivirus - D - MDE Configuration - v1.0

Name Value
Basics
Name MacOS - OIB - Defender Antivirus - D - MDE Configuration - v1.0
Description
Profile type Settings catalog
Platform supported macOS
Created 17 August 2024 16:20:18
Last modified 19 August 2024 15:05:16
Scope tags Default
Table 5. Basics - MacOS - OIB - Defender Antivirus - D - MDE Configuration - v1.0
Name Value
Top Level Setting Group Collection Not configured
Rules Not configured
Rule Type Label Prefix
Rule Value com.microsoft.fresno
Rule Type Label Prefix
Rule Value com.microsoft.dlp
Applications Not configured
Microsoft Defender Not configured
Microsoft Defender Application ID WDAV00
Microsoft Defender LCID 1033
Update channel override Current Channel
Top Level Setting Group Collection Not configured
Services Not configured
Accessibility Not configured
Identifier com.microsoft.dlp.daemon
Identifier Type bundle ID
Code Requirement identifier "com.microsoft.dlp.daemon" and anchor apple generic and certificate 1[field.1.2.840.113635.100.6.2.6] /`* exists `*/ and certificate leaf[field.1.2.840.113635.100.6.1.13] /`* exists `*/ and certificate leaf[subject.OU] = UBF8T346G9
Static Code False
Allowed True
Authorization Allow
System Policy All Files Not configured
Identifier com.microsoft.wdav
Identifier Type bundle ID
Code Requirement identifier "com.microsoft.wdav" and anchor apple generic and certificate 1[field.1.2.840.113635.100.6.2.6] /`* exists `*/ and certificate leaf[field.1.2.840.113635.100.6.1.13] /`* exists `*/ and certificate leaf[subject.OU] = UBF8T346G9
Static Code False
Allowed True
Authorization Allow
Identifier com.microsoft.wdav.epsext
Identifier Type bundle ID
Code Requirement identifier "com.microsoft.wdav.epsext" and anchor apple generic and certificate 1[field.1.2.840.113635.100.6.2.6] /`* exists `*/ and certificate leaf[field.1.2.840.113635.100.6.1.13] /`* exists `*/ and certificate leaf[subject.OU] = UBF8T346G9
Static Code False
Allowed True
Authorization Allow
Identifier com.microsoft.dlp.daemon
Identifier Type bundle ID
Code Requirement identifier "com.microsoft.dlp.daemon" and anchor apple generic and certificate 1[field.1.2.840.113635.100.6.2.6] /`* exists `*/ and certificate leaf[field.1.2.840.113635.100.6.1.13] /`* exists `*/ and certificate leaf[subject.OU] = UBF8T346G9
Static Code False
Allowed True
Authorization Allow
Bluetooth Always Not configured
Identifier com.microsoft.dlp.daemon
Identifier Type bundleID
Code Requirement identifier "com.microsoft.dlp.daemon" and anchor apple generic and certificate 1[field.1.2.840.113635.100.6.2.6] /`* exists `*/ and certificate leaf[field.1.2.840.113635.100.6.1.13] /`* exists `*/ and certificate leaf[subject.OU] = UBF8T346G9
Static Code Disabled
Allowed Allowed
Authorization Allow
Top Level Setting Group Collection Not configured
Allowed System Extensions Not configured
Allowed System Extensions com.microsoft.wdav.epsext;com.microsoft.wdav.netext
Team Identifier UBF8T346G9
Top Level Setting Group Collection Not configured
Notification Settings Not configured
Bundle Identifier com.microsoft.wdav.tray
Notifications Enabled True
Show In Notification Center True
Show In Lock Screen False
Alert Type Temporary Banner
Badges Enabled True
Sounds Enabled True
Critical Alert Enabled False
Top Level Setting Group Collection Not configured
User Defined Name Microsoft Defender Content Filter
Plugin Bundle ID com.microsoft.wdav
Organization JAMF Software
Filter Sockets True
Filter Data Provider Designated Requirement identifier "com.microsoft.wdav.netext" and anchor apple generic and certificate 1[field.1.2.840.113635.100.6.2.6] /`* exists `*/ and certificate leaf[field.1.2.840.113635.100.6.1.13] /`* exists `*/ and certificate leaf[subject.OU] = UBF8T346G9
Filter Data Provider Bundle Identifier com.microsoft.wdav.netext
Filter Packets False
Filter Grade inspector
Table 6. Settings - MacOS - OIB - Defender Antivirus - D - MDE Configuration - v1.0

MacOS - OIB - Device Security - D - Accounts and Login - v1.0

Name Value
Basics
Name MacOS - OIB - Device Security - D - Accounts and Login - v1.0
Description
Profile type Settings catalog
Platform supported macOS
Created 30 August 2024 11:16:06
Last modified 30 August 2024 11:16:06
Scope tags Default
Table 7. Basics - MacOS - OIB - Device Security - D - Accounts and Login - v1.0
Name Value
Top Level Setting Group Collection Not configured
Disable Guest Account True
Top Level Setting Group Collection Not configured
Hide Admin Users False
Admin Host Info HostName
Disable Console Access True
Top Level Setting Group Collection Not configured
Disable Login Items Suppression True
Table 8. Settings - MacOS - OIB - Device Security - D - Accounts and Login - v1.0

MacOS - OIB - Device Security - D - Restrictions - v1.0

Name Value
Basics
Name MacOS - OIB - Device Security - D - Restrictions - v1.0
Description
Profile type Settings catalog
Platform supported macOS
Created 17 August 2024 17:03:25
Last modified 17 August 2024 17:19:11
Scope tags Default
Table 9. Basics - MacOS - OIB - Device Security - D - Restrictions - v1.0
Name Value
Top Level Setting Group Collection Not configured
Disabled Preference Panes
com.apple.AirDrop-Handoff-Settings.extension;com.apple.Family-Settings.extension;com.apple.Game-Center-Settings.extension;com.apple.Siri-Settings.extension;com.apple.Startup-Disk-Settings.extension;com.apple.Time-Machine-Settings.extension;com.apple.WalletSettingsExtension;com.apple.systempreferences.AppleIDSettings
Top Level Setting Group Collection Not configured
Allow Account Modification False
Allow Activity Continuation False
Allow Adding Game Center Friends False
Allow AirDrop False
Allow Air Play Incoming Requests Disabled
Allow Apple Personalized Advertising False
Allow Assistant False
Allow Auto Unlock False
Allow Bluetooth Sharing Modification False
Allow Cloud Address Book False
Allow Cloud Bookmarks False
Allow Cloud Calendar False
Allow Cloud Desktop And Documents False
Allow Cloud Document Sync False
Allow Cloud Freeform False
Allow Cloud Keychain Sync False
Allow Cloud Mail False
Allow Cloud Notes False
Allow Cloud Photo Library False
Allow Cloud Private Relay False
Allow Cloud Reminders False
Allow Device Name Modification False
Allow Erase Content And Settings False
Allow File Sharing Modification False
Allow Find My Device False
Allow Find My Friends False
Allow Game Center False
Allow Internet Sharing Modification False
Allow iTunes File Sharing False
Allow Local User Creation False
Allow Multiplayer Gaming False
Allow Password Proximity Requests False
Allow Password Sharing False
Allow Printer Sharing Modification False
Allow Startup Disk Modification False
Safari Allow Autofill False
Table 10. Settings - MacOS - OIB - Device Security - D - Restrictions - v1.0

MacOS - OIB - Disk Encryption - D - FileVault - v1.0

Name Value
Basics
Name MacOS - OIB - Disk Encryption - D - FileVault - v1.0
Description
Profile type Settings catalog
Platform supported macOS
Created 30 August 2024 11:16:22
Last modified 30 August 2024 11:16:22
Scope tags Default
Table 11. Basics - MacOS - OIB - Disk Encryption - D - FileVault - v1.0
Name Value
Top Level Setting Group Collection Not configured
Enable On
Force Enable In Setup Assistant True
Recovery Key Rotation In Months 6 months
Top Level Setting Group Collection Not configured
Prevent FileVault From Being Disabled True
Top Level Setting Group Collection Not configured
Location You can retrieve the personal recovery key for your macOS device from the Microsoft Intune app, Company Portal website, or Company Portal apps for Android and iOS/iPadOS. Support cannot access recovery keys that belong to personal devices.
Table 12. Settings - MacOS - OIB - Disk Encryption - D - FileVault - v1.0

MacOS - OIB - Firewall - D - Gatekeeper - v1.0

Name Value
Basics
Name MacOS - OIB - Firewall - D - Gatekeeper - v1.0
Description
Profile type Settings catalog
Platform supported macOS
Created 30 August 2024 11:16:37
Last modified 30 August 2024 11:16:37
Scope tags Default
Table 13. Basics - MacOS - OIB - Firewall - D - Gatekeeper - v1.0
Name Value
Top Level Setting Group Collection Not configured
Enable Firewall True
Block All Incoming False
Enable Stealth Mode True
Enable Logging True
Top Level Setting Group Collection Not configured
Enable Assessment True
Allow Identified Developers True
Enable XProtect Malware Upload Disabled
Table 14. Settings - MacOS - OIB - Firewall - D - Gatekeeper - v1.0

MacOS - OIB - Microsoft AutoUpdate - D - MAU Configuration - v1.0

Name Value
Basics
Name MacOS - OIB - Microsoft AutoUpdate - D - MAU Configuration - v1.0
Description
Profile type Settings catalog
Platform supported macOS
Created 17 August 2024 15:54:53
Last modified 19 August 2024 15:32:58
Scope tags Default
Table 15. Basics - MacOS - OIB - Microsoft AutoUpdate - D - MAU Configuration - v1.0
Name Value
Top Level Setting Group Collection Not configured
Rules Not configured
Rule Type Bundle Identifier
Rule Value com.microsoft.autoupdate2
Comment MAU
Automatically acknowledge data collection policy Acknowledge - send required data
Days before forced updates 14
Deferred updates Defer 3 days
Disable Office Insider membership True
Enable AutoUpdate True
Enable check for updates True
Guard against app modification Disabled
Register app on launch True
Update cache server https://officecdn.microsoft.com/pr/C1297A47-86C4-4C1F-97FA-950631F94777/OfficeMac/
Update channel Current Channel
Updater optimization technique Lower network overhead
Table 16. Settings - MacOS - OIB - Microsoft AutoUpdate - D - MAU Configuration - v1.0

MacOS - OIB - Microsoft Edge - D - Password Management - v1.0

Name Value
Basics
Name MacOS - OIB - Microsoft Edge - D - Password Management - v1.0
Description
Profile type Settings catalog
Platform supported macOS
Created 17 August 2024 17:22:39
Last modified 17 August 2024 17:22:39
Scope tags Default
Table 17. Basics - MacOS - OIB - Microsoft Edge - D - Password Management - v1.0
Name Value
Microsoft Edge
Allow Microsoft Edge to monitor user passwords Allowed
Configure password protection warning trigger Password protection warning is triggered by password reuse
Enable saving passwords to the password manager Enabled
Table 18. Settings - MacOS - OIB - Microsoft Edge - D - Password Management - v1.0

MacOS - OIB - Microsoft Edge - D - Security - v1.0

Name Value
Basics
Name MacOS - OIB - Microsoft Edge - D - Security - v1.0
Description
Profile type Settings catalog
Platform supported macOS
Created 17 August 2024 17:22:54
Last modified 19 August 2024 15:41:58
Scope tags Default
Table 19. Basics - MacOS - OIB - Microsoft Edge - D - Security - v1.0
Name Value
Microsoft Edge
Ads setting for sites with intrusive ads Block ads on sites with intrusive ads. (Default value)
Allow download restrictions Block dangerous downloads
Allow importing of browser settings Disabled
Allow importing of browsing history Disabled
Allow importing of home page settings Disabled
Allow importing of payment info Disabled
Allow importing of saved passwords Disabled
Allow importing of search engine settings Disabled
Allow managed extensions to use the Enterprise Hardware Platform API Disabled
Allow personalization of ads, search and news by sending browsing history to Microsoft Disabled
Allow queries to a Browser Network Time service Enabled
Allow user-level native messaging hosts (installed without admin permissions) Disabled
Automatically import another browser's data and settings at first run Disables automatic import, and the import section of the first-run experience is skipped
Block tracking of users' web-browsing activity Balanced (blocks harmful trackers and trackers from sites user has not visited; content and ads will be less personalized)
Clear browsing data when Microsoft Edge closes Disabled
Clear cached images and files when Microsoft Edge closes Disabled
Configure Microsoft Defender SmartScreen Enabled
Configure Microsoft Defender SmartScreen to block potentially unwanted apps Enabled
Control communication with the Experimentation and Configuration Service Disable communication with the Experimentation and Configuration Service
DNS interception checks enabled Enabled
Enable AutoFill for addresses Disabled
Enable AutoFill for credit cards Disabled
Enable Google Cast Disabled
Enable Proactive Authentication Disabled
Hide the First-run experience and splash screen Enabled
Minimum TLS version enabled TLS 1.2
Prevent bypassing Microsoft Defender SmartScreen prompts for sites Enabled
Prevent bypassing of Microsoft Defender SmartScreen warnings about downloads Enabled
Supported authentication schemes ntlm,negotiate
Table 20. Settings - MacOS - OIB - Microsoft Edge - D - Security - v1.0

MacOS - OIB - Microsoft Edge - U - Extensions - v1.0

Name Value
Basics
Name MacOS - OIB - Microsoft Edge - U - Extensions - v1.0
Description
Profile type Settings catalog
Platform supported macOS
Created 17 August 2024 17:23:16
Last modified 17 August 2024 17:23:16
Scope tags Default
Table 21. Basics - MacOS - OIB - Microsoft Edge - U - Extensions - v1.0
Name Value
Microsoft Edge
Allow specific extensions to be installed odfafepnkmbhccpbejgmiehpchacaeak
Blocks external extensions from being installed Enabled
Control which extensions are installed silently nkbndigcebkoaejohleckhekfmcecfja;ofefcgjbeghpigppfmkologfjadafddi
Control which extensions cannot be installed `*
Table 22. Settings - MacOS - OIB - Microsoft Edge - U - Extensions - v1.0

MacOS - OIB - Microsoft Edge - U - Profiles, Sign-In and Sync - v1.0

Name Value
Basics
Name MacOS - OIB - Microsoft Edge - U - Profiles, Sign-In and Sync - v1.0
Description
Profile type Settings catalog
Platform supported macOS
Created 17 August 2024 17:23:32
Last modified 17 August 2024 17:23:32
Scope tags Default
Table 23. Basics - MacOS - OIB - Microsoft Edge - U - Profiles, Sign-In and Sync - v1.0
Name Value
Microsoft Edge
Browser sign-in settings Force users to sign-in to use the browser
Enable profile creation from the Identity flyout menu or the Settings page Disabled
Enable use of ephemeral profiles Disabled
Force synchronization of browser data and do not show the sync consent prompt Enabled
Table 24. Settings - MacOS - OIB - Microsoft Edge - U - Profiles, Sign-In and Sync - v1.0

MacOS - OIB - Microsoft Edge - U - Updates - v1.0

Name Value
Basics
Name MacOS - OIB - Microsoft Edge - U - Updates - v1.0
Description
Profile type Settings catalog
Platform supported macOS
Created 19 August 2024 15:42:43
Last modified 19 August 2024 15:42:43
Scope tags Default
Table 25. Basics - MacOS - OIB - Microsoft Edge - U - Updates - v1.0
Name Value
Top Level Setting Group Collection Not configured
Rules Not configured
Rule Type Label Prefix
Rule Value com.microsoft.EdgeUpdater
Comment Edge Updater
Microsoft Edge
Enable component updates in Microsoft Edge Enabled
Notify a user that a browser restart is recommended or required for pending updates Required - Show a recurring prompt to the user indicating that a restart is required
Table 26. Settings - MacOS - OIB - Microsoft Edge - U - Updates - v1.0

MacOS - OIB - Microsoft Office - D - Office Configuration - v1.0

Name Value
Basics
Name MacOS - OIB - Microsoft Office - D - Office Configuration - v1.0
Description
Profile type Settings catalog
Platform supported macOS
Created 17 August 2024 17:23:48
Last modified 19 August 2024 15:44:03
Scope tags Default
Table 27. Basics - MacOS - OIB - Microsoft Office - D - Office Configuration - v1.0
Name Value
Top Level Setting Group Collection Not configured
Rules Not configured
Rule Type Bundle Identifier
Rule Value com.microsoft.office.licensingV2.helper
Comment Office Licensing Helper
Enable automatic sign-in True
Office Activation Email Address {{userprincipalname}}
Table 28. Settings - MacOS - OIB - Microsoft Office - D - Office Configuration - v1.0

MacOS - OIB - Microsoft OneDrive - D - Service and Access - v1.0

Name Value
Basics
Name MacOS - OIB - Microsoft OneDrive - D - Service and Access - v1.0
Description
Profile type Settings catalog
Platform supported macOS
Created 30 August 2024 11:16:55
Last modified 30 August 2024 11:16:55
Scope tags Default
Table 29. Basics - MacOS - OIB - Microsoft OneDrive - D - Service and Access - v1.0
Name Value
Top Level Setting Group Collection Not configured
Rules Not configured
Rule Type Label Prefix
Rule Value com.microsoft.OneDrive
Comment OneDrive (Standalone)
Rule Type Bundle Identifier
Rule Value com.microsoft.OneDriveLauncher
Comment OneDrive Launcher
Top Level Setting Group Collection Not configured
Services Not configured
System Policy All Files Not configured
Identifier com.microsoft.OneDrive
Identifier Type bundle ID
Code Requirement identifier "com.microsoft.OneDrive" and anchor apple generic and certificate 1[field.1.2.840.113635.100.6.2.6] /`* exists `*/ and certificate leaf[field.1.2.840.113635.100.6.1.13] /`* exists `*/ and certificate leaf[subject.OU] = UBF8T346G9
Static Code False
Allowed True
Authorization Allow
Top Level Setting Group Collection Not configured
Allowed System Extensions Not configured
Allowed System Extensions com.microsoft.OneDrive.FinderSync
Team Identifier UBF8T346G9
Table 30. Settings - MacOS - OIB - Microsoft OneDrive - D - Service and Access - v1.0

MacOS - OIB - Microsoft OneDrive - U - Known Folder Move - v1.0

Name Value
Basics
Name MacOS - OIB - Microsoft OneDrive - U - Known Folder Move - v1.0
Description
Profile type Settings catalog
Platform supported macOS
Created 30 August 2024 11:17:13
Last modified 30 August 2024 11:17:13
Scope tags Default
Table 31. Basics - MacOS - OIB - Microsoft OneDrive - U - Known Folder Move - v1.0
Name Value
Automatically and silently enable the Folder Backup feature (Known Folder Move) %OrganizationId%
Block external sync True
Disable automatic sign in False
Disable personal accounts True
Disable tutorial True
Display a notification to users once their folders have been redirected False
Enable Files On-Demand True
Enable simultaneous edits for Office apps True
Force users to use the Folder Backup feature (Known Folder Move) True
Hide dock icon True
Ignore named files `*.lnk;`*.pst;`*.pkg;`*.dmg
Include ~/Desktop in Folder Backup (Known Folder Move) True
Include ~/Documents in Folder Backup (Known Folder Move) True
Open at login True
Prompt users to enable the Folder Backup feature (Known Folder Move) %OrganizationId%
Table 32. Settings - MacOS - OIB - Microsoft OneDrive - U - Known Folder Move - v1.0

MacOS - OIB - Updates - D - Update Configuration - v1.0

Name Value
Basics
Name MacOS - OIB - Updates - D - Update Configuration - v1.0
Description
Profile type Settings catalog
Platform supported macOS
Created 19 August 2024 15:21:27
Last modified 19 August 2024 15:21:27
Scope tags Default
Table 33. Basics - MacOS - OIB - Updates - D - Update Configuration - v1.0
Name Value
Top Level Setting Group Collection Not configured
Restrict Software Update Require Admin To Install False
Automatically Install Mac OS Updates True
Automatically Install App Updates True
Automatic Check Enabled True
Automatic Download True
Critical Update Install True
Config Data Install True
Table 34. Settings - MacOS - OIB - Updates - D - Update Configuration - v1.0