Loading...
centrexIT
Knowledge Center

CentrexIT Remediate macOS Devices Not Checking in With Intune

KB00023286
Cory Walton Work Instruction Archived 1 min
ArchivedCory Waltonv2.0
Published Jul 12, 2024Expires Jul 12, 2025 (expired)

To remediate macOS noncompliant devices not checking in with Microsoft Intune (based on the policy’s noncompliant schedule, eg > 5 days)

NOTE: KP Enviornmental’s enviornment was used in this example


End-point management, monitoring, and security.


Service Delivery, IT Secuirty, vITM


  1. Last Check-In is the current date after remediation
  2. Device is Complaint in Microsoft Intune Center
  3. FileVault Recovery Key is visible in Microsoft Intune Center (If policy is applied to the tenant)

NA


  1. Click on user’s Desktop
  2. From the Mac Menu Bar select Go > Applications
  3. Open the Company Portal (If not already installed https://go.microsoft.com/fwlink/?linkid=853070)
    Description

  4. Sign into the Company Portal (if not already)
    Description

  5. Click Begin (If you don’t see the Company Dashboard)
    Description

  6. Click Continue
    Description

  7. Click Download Profile (This should open up the Profiles section of Apple > System Preferences)
    Description

  8. If there are multiple Management Profiles entries (delete the oldest)
    • This should remove all other Profiles associated with the old Management Profile
      Description

  9. Click Install… from Downloaded > Management Profile
    Description

  10. Click Install from the pop
    Description

  11. Go back to the Company Portal app and review device settings being applied
    Description

  12. Click Done once complete
    Description

  13. If client has MS Defender for Endpoint, click Allow on the Filter Network Content pop-up
    Description

  14. Confirm last checked matches with Intune Management Console on Device tab of the Company Portal Dashboard
    Description

  15. If endpoint already has FileVault enabled on their device please follow the steps below to ensure Recovery Keys are backed up to Intune:
    • Open Terminal app from /Applications
    • Enter the following command: cd /Applications/Utilities
    • Enter the following command (if user is an admin): sudo fdesetup changerecovery -personal
      • If user is not an admin run this command first, then the one above: login [local_admin_account_username] (eg login localuser)
      • [password_for_local_admin_account]
    • Enter the username of the currently signed in user.
    • Enter the password of the currently signed in user.
      Description

  16. Force a Compliance check from Intune and confirm Recovery Keys backed up (ETA 10min)
    Description
    Description

NA