Using Custom Attributes with macOS Devices in Intune: Compliance Policies and Conditional Access
Microsoft Intune is a cloud-based service that focuses on mobile device management (MDM) and mobile application management (MAM). With Intune, organizations can manage and secure mobile devices and applications, including macOS devices. One way to enhance the management and security of macOS devices in Intune is by using custom attributes.
What are Custom Attributes in Intune?
Custom attributes in Intune are key-value pairs that you can assign to devices, users, and groups. These attributes can be used to define compliance policies, conditional access rules, and other settings in Intune. Custom attributes can be assigned manually or using a script or configuration profile. For example, you can assign a custom attribute called "Department" to a group of macOS devices and use that attribute to define a compliance policy that applies only to devices in that department.
How to Assign Custom Attributes to macOS Devices in Intune
To assign custom attributes to macOS devices in Intune, you can use a configuration profile. A configuration profile is a file that contains settings and configurations for a device or group of devices. You can create a configuration profile in the Intune admin center and assign it to a group of devices. The configuration profile can include settings for custom attributes.
Here are the steps to assign custom attributes to macOS devices using a configuration profile:
- In the Intune admin center, go to
Devices > Configuration profiles > Create profile. - Select
macOSas the platform andTemplatesas the profile type. - Select a template, such as
Device restrictionsorCustom. - Configure the settings for the profile, including the custom attributes.
- Assign the profile to a group of devices.
Using Custom Attributes in Compliance Policies and Conditional Access
Once you have assigned custom attributes to macOS devices in Intune, you can use those attributes to define compliance policies and conditional access rules. Compliance policies ensure that devices meet certain requirements, such as having a passcode or being encrypted. Conditional access rules control access to resources, such as email or SharePoint, based on the compliance status of the device.
Here are some examples of how you can use custom attributes in compliance policies and conditional access:
- Create a compliance policy that applies only to macOS devices in a certain department.
- Create a conditional access rule that requires macOS devices to be compliant before accessing email.
- Create a compliance policy that requires macOS devices to have a certain version of the operating system before being marked as compliant.
References
- Configure custom attributes for devices in Microsoft Intune
- Get started with device compliance in Microsoft Intune
- Conditional access in Microsoft Intune
Note: The question mentions trying to use the figure use case in Tune, but it was not found. Also, there is no information provided about the types of references to include, so I have included general references for Intune custom attributes, compliance policies, and conditional access.