InstallIntermediateTutorialsUpdated July 5, 2026

How to Install Microsoft Intune Company Portal on Mac Devices

Download and install the Microsoft Intune Company Portal on macOS, then enroll your Mac step by step: sign in, install the management profile, and confirm compliance.

Emanuel De Almeida June 19, 2026 15 min read
Difficulty
Intermediate
Time
15-20 minutes
Steps
8
Last tested
July 5, 2026

The Company Portal app is how a Mac enrolls itself into Microsoft Intune when it isn't provisioned through Apple Automated Device Enrollment. You download a single universal installer, sign in with your work or school account, and then install a management profile that registers the device with your organization's Intune tenant. Once enrolled, IT can deliver apps, enforce compliance settings such as FileVault and OS updates, and grant access to resources behind Conditional Access. This guide walks through the full path - install, sign-in, profile installation, and verification - and flags the few places where the macOS UI differs between versions so the steps hold up on Sonoma, Sequoia, and Tahoe.

Before you start

What you will learn

  • How to download and install the Microsoft Intune Company Portal on a Mac, then enroll the device so it can receive your organization's apps and policies.
  • Company Portal is the manual and BYOD enrollment path for macOS. Without it, a personal or unmanaged Mac can't register with Intune or reach resources protected by Conditional Access.

Requirements

  • You need a work or school account that has an Intune license assigned, the login (device) password for the Mac so you can install the profile, and a network connection. Your organization must already have Apple MDM push configured in Intune for enrollment to succeed.
  • A Mac running a supported macOS version. For new enrollments, treat macOS 14 (Sonoma) or later as the practical minimum: Intune supports the three most recent macOS releases (currently Sonoma, Sequoia, and Tahoe). Admin-side, an Apple MDM push certificate must be configured in the Intune tenant.

Good to know

  • Most of the time is the download and the compliance checks, not the install itself.
  • Steps verified against current Microsoft Learn and Apple Support documentation in July 2026.

Quick answer

Go to Enroll My Mac, download and run the Company Portal .pkg installer, then open Company Portal and sign in with your work or school account. Follow the in-app prompt to download and install the management profile in System Settings, return to Company Portal, and resolve any compliance items until the device shows as compliant.

https://aka.ms/EnrollMyMac > download .pkg > install > Company Portal > Sign in > install management profile

Step-by-step tutorial

8 steps
1

Download the Company Portal installer from Enroll My Mac

Get the current, official Company Portal installer package for macOS.

https://aka.ms/EnrollMyMac

Open a browser on the Mac and go to https://aka.ms/EnrollMyMac. Wait while the Company Portal installer .pkg file downloads, then open it once it's ready.

This page always serves the latest universal installer, which runs natively on both Apple Silicon and Intel Macs, so you don't need to pick an architecture. If your organization prefers the Company Portal website instead, users can also sign in at https://portal.manage.microsoft.com/EnrollmentRedirect.aspx and choose Get the App to download the same installer.

Expected resultA Company Portal installer .pkg file appears in your Downloads folder.

Bookmark aka.ms/EnrollMyMac - Microsoft keeps it pointed at the newest installer, so it's reusable across devices and future reinstalls.

2

Run the Company Portal installer package

Install the Company Portal app into the Applications folder.

Double-click the downloaded .pkg to launch the installer. macOS verifies the package signature before it runs. Then work through the wizard:

  1. On the Introduction page, select Continue.
  2. On the License page, read the Microsoft Application License Terms, select Continue, then select Agree.
  3. On the Installation Type page, select Install.
  4. When prompted, enter your device password or use your registered fingerprint (Touch ID) to authorize the installation.

When the installer finishes, you can move the .pkg to the Trash - it isn't needed after installation.

Expected resultThe installer reports a successful installation and Company Portal appears in your Applications folder.

Company Portal is kept current through Microsoft AutoUpdate (MAU), the same mechanism that updates Microsoft 365 apps. MAU may launch after installation to check for updates - let it finish. You can also update later from Company Portal via Help in the menu bar.

3

Open Company Portal and sign in

Authenticate with your organization account so Company Portal knows which tenant to enroll into.

Open Company Portal from Applications, Launchpad, or Spotlight, then select Sign in. Enter your work or school email address (for example name@company.com), select Next, and enter your password. Complete any multi-factor authentication challenge your organization requires.

Expected resultAfter authentication, Company Portal opens and displays your organization's name.

If sign-in loops or is blocked, the account may be missing an Intune license, or a Conditional Access policy may be requiring enrollment before it grants access - which is exactly what the next steps complete.

4

Start enrollment and download the management profile

Begin device registration and obtain the management profile that enrolls the Mac.

In Company Portal, follow the prompt to enroll - this is usually Begin or Set up access / Enroll this device. Review the privacy information that explains what your organization can and cannot see, then select Continue.

Company Portal generates a management profile for your account and downloads it. It opens your macOS system settings so you can install it, and shows in-app instructions to help you find it.

Expected resultThe management profile downloads (to your Downloads folder) and macOS system settings open to the profile.

The downloaded enrollment profile is only offered in System Settings for about 10 minutes. If it disappears, double-click the .mobileconfig file in your Downloads folder to try again.

5

Verify and install the management profile

Confirm the profile is legitimate, then install it to enroll the device.

System Settings > Privacy & Security > Profiles (Sonoma) - or - System Settings > General > Device Management (Sequoia/Tahoe)

Open the downloaded profile in System Settings. Where you find it depends on your macOS version:

  • macOS 14 (Sonoma): System Settings > Privacy & Security > Profiles
  • macOS 15 (Sequoia) and macOS 26 (Tahoe): System Settings > General > Device Management

Select the downloaded profile and review it. Confirm the status shows Verified and that it is signed by a Microsoft signing authority before continuing. Then select Install, enter your device password, and select Enroll to finish. Wait while the management profile installs and enrolls the device.

Expected resultThe profile installs and the enrollment profile appears under your installed profiles / Device Management as an active MDM profile.

The signer is commonly displayed as IOSProfileSigning.manage.microsoft.com; the exact string can change, so treat the Verified status plus a Microsoft-owned signer as the real check rather than matching one fixed name.

6

Confirm enrollment and resolve compliance requirements

Complete registration in Company Portal and bring the device into a compliant state.

Return to the Company Portal app. It detects the installed profile and shows a green checkmark next to *Install management profile*. If it doesn't register automatically, reopen the app to complete device registration.

Select your device and review the Status list of required changes. For each item, select Learn more or How to resolve this for guidance, make the change, then select Retry to re-check. Once every item passes, the device reports as compliant.

Expected resultCompany Portal shows the management profile as installed and, once all items pass, the device shows as compliant.

Common requirements are enabling FileVault encryption, installing pending macOS updates, and password rules. Some checks take a few minutes to refresh - if you've made a change but still see the item, wait and select Retry again.

7

Approve keychain access prompts correctly

Grant Company Portal the keychain access it needs without triggering repeated prompts.

During installation and enrollment, macOS may ask Company Portal to use confidential information stored in your keychain. When a prompt appears, type your login keychain password (the password you use to sign in to the Mac) and select Always Allow.

Don't press Enter or Return to dismiss the prompt - that selects Allow instead of Always Allow, which means you'll keep getting prompted.

Expected resultThe keychain prompt is dismissed with Always Allow and does not reappear repeatedly.

If prompts keep returning, you most likely selected Allow (or pressed Return) previously. Reopen Company Portal and choose Always Allow the next time it asks.

8

Verify the installation and enrollment

Confirm the app is installed and the Mac is actually enrolled in Intune.

Check three things:

  1. Company Portal shows your organization's name and a green checkmark on the management profile.
  2. In System Settings, the MDM enrollment profile is present (Privacy & Security > Profiles on Sonoma, or General > Device Management on Sequoia/Tahoe).
  3. In Terminal, confirm MDM enrollment status:

profiles status -type enrollment

Bash
profiles status -type enrollment
Expected resultThe command reports an MDM enrollment of Yes (User Approved), and the device appears in the Intune admin center under Devices.

Admins can confirm from the other side in the Microsoft Intune admin center at Devices > All devices, filtering by macOS. Registration in Microsoft Entra ID completes when you reach the Company Portal home screen after enrollment.

How to Confirm the Mac Is Enrolled and Managed

A healthy result has two halves: the app is installed and signed in, and the device is enrolled. In Company Portal you should see your organization's name and a green checkmark on the management profile. In System Settings, the MDM enrollment profile should be listed as installed and active. From Terminal, profiles status -type enrollment should report that MDM enrollment is enabled and User Approved. On the admin side, the Mac appears in the Intune admin center under Devices, where its compliance state and inventory are visible. If the device shows as non-compliant, that's normal immediately after enrollment - work through the compliance items Company Portal lists until they all pass.

  • Company Portal shows the organization name and a green checkmark; the MDM profile is installed; profiles status -type enrollment reports MDM enrollment: Yes (User Approved); the device is listed in the Intune admin center.
  • No profile appears in System Settings, Company Portal keeps asking you to enroll, or the Terminal command reports no MDM enrollment - usually meaning the profile wasn't installed within its 10-minute window, sign-in used a personal account, or a Conditional Access / license issue is blocking the account.
  • Output from profiles status -type enrollment on a successfully enrolled Mac.
  • Shown in Company Portal once all required changes (FileVault, updates, password) are satisfied.

Troubleshooting

Sign-in is rejected or loops back to the login screen

Cause: The account has no Intune license, or you signed in with a personal Microsoft account instead of a work or school account.

Sign in with your organizational account (for example name@company.com) and confirm with your IT team that an Intune license is assigned to it. Personal Microsoft accounts cannot enroll into enterprise Intune management.

No profile appears in System Settings after downloading it

Cause: The enrollment profile is only offered in System Settings for about 10 minutes, and the window may have expired.

Open your Downloads folder and double-click the .mobileconfig file to re-open it in System Settings, then install it promptly.

You can't find the Profiles section in System Settings

Cause: Apple moved the location between macOS versions, so the path differs.

On Sonoma, look under System Settings > Privacy & Security > Profiles. On Sequoia and Tahoe, look under System Settings > General > Device Management. If there's still nothing listed, the profile likely didn't download - return to Company Portal and start enrollment again.

Keychain access prompts keep reappearing

Cause: Allow (or pressing Return) was selected instead of Always Allow, so macOS re-asks on each access.

When the prompt returns, type your login keychain password and click Always Allow rather than pressing Return. If it persists, reopening Company Portal and re-approving usually clears it.

Device stays non-compliant after enrollment

Cause: One or more required settings (FileVault, OS updates, password policy) haven't been satisfied yet, or the compliance state hasn't refreshed.

In Company Portal, open the device and address each listed item using How to resolve this, then select Retry. Some checks take several minutes to update - make the change, wait, and retry.

Frequently asked questions

Which macOS versions can enroll with Intune Company Portal?

For new enrollments, treat macOS 14 (Sonoma) or later as the minimum: Intune supports the three most recent macOS releases (currently Sonoma, Sequoia, and Tahoe). Devices already enrolled on older versions generally stay enrolled, but new Macs on unsupported versions can't enroll. Note that Microsoft's end-user help page still cites an older macOS 11 minimum, so go by the current supported-platforms policy.

Can I install Company Portal on a personal Mac?

Yes. Company Portal supports BYOD and manual enrollment on personal Macs, but you must sign in with a work or school account that has an Intune license. Personal Microsoft accounts can't be used for enterprise enrollment.

Where do I download Company Portal for Mac?

Use Microsoft's official Enroll My Mac page at https://aka.ms/EnrollMyMac, which serves the latest universal .pkg installer for both Apple Silicon and Intel Macs. Signed-in users can alternatively get it from the Company Portal website.

How do I verify the management profile is legitimate before installing it?

In System Settings, open the downloaded profile and confirm its status reads Verified and that it's signed by a Microsoft signing authority (commonly shown as IOSProfileSigning.manage.microsoft.com). Never install a profile marked Unverified or signed by an unknown entity.

How do I confirm my Mac is actually enrolled in Intune?

Check that Company Portal shows your organization name and a green checkmark, that the MDM profile is present in System Settings, and run profiles status -type enrollment in Terminal, which should report MDM enrollment as Yes (User Approved). Admins can confirm the device under Devices in the Intune admin center.

How does Company Portal stay up to date on macOS?

It updates through Microsoft AutoUpdate (MAU), the same tool that updates Microsoft 365 apps. MAU may run automatically after install, or you can check for updates from Company Portal's Help menu.

Reader reviews

Rate this articleBe the first to rate
No written reviews yetRate the article above, or be the first to share your experience.

Related articles