Intune - MacOS - Company portal after domain join attempting to re-enrol in MDM

Aron Johnson 1 Reputation point

I've configured Intune with a custom configuration profile to enrol MacOS devices into an AD domain. You login with a local account, install Company Portal, the Domain Join profile runs and the device is joined to AD. You can then login to the device with the domain credential.

However, when I open up the Company Portal app on the device as the domain user, it is going through the setup again. It tries to install the MDM profile again, and then fails because it is already installed.

Is there anyway around this?

Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,771 questions
Microsoft Intune Enrollment
Microsoft Intune Enrollment
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Enrollment: The process of requesting, receiving, and installing a certificate.
1,283 questions
0 comments No comments
{count} votes

3 answers

Sort by: Most helpful
  1. Crystal-MSFT 44,931 Reputation points Microsoft Vendor

    @Aron Johnson , Thanks for posting in our Q&A.

    For the re-enroll issue, could you confirm if it starts after we sign in to Company Portal with the same work or school account?

    For the macOS device which is join AD manually, will it get the same issue?

    Please check the above information and if there's any update, feel free to let us know.

    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

  2. Aron Johnson 1 Reputation point

    So what I did was:

    1. Login to the fresh Mac (OS 12).
    2. Enroll with a 365 account (which is the domain user also the domain user I will login with next).
    3. Once the Domain Join policy had applied, I then logged out and back in as the domain user.
    4. When I then open up the Company Portal, it asks for login credentials (same credentials as step 2) and then goes through the initial setup again.
    5. The policy window pops up and you put in the admin credentials from the local account, it then fails saying that the machine is already enrolled and only the machine has permissions to
      update the enrollment policy on the machine.

    I haven't tried a manual join, I'll see if I can find a way to test that and let you know.

  3. Aron Johnson 1 Reputation point

    FYI I think I found the source of the problem. When I was initially testing this the device was enrolled using a standard user account. However, if I enrol the device using a DEM and then switch to a domain user, you can login to the Company Portal without any issues. So you need to enrol it as corporate with a DEM to make this work.