maciejrebisz.com

IT

Important Action Required: Secure your MacOS devices with conditional access – Mobile-First Cloud-First

maximios March 23, 2023

This message showed up in the message center for Office 365 – and we have been waiting for this for a long time. Soon we can start testen Conditional Access for MacOS.

If you already have Conditional Access rules setup for device platforms and are using “All platforms” then when Microsoft is enabling support for MacOS you need to take action.

Conditional access is expanding the coverage of platforms that can be secured by adding support for MacOS. Public preview of MacOS Conditional Access support will be introduced by the end of August. Conditional access policies that are defined for “All platforms” will now also support MacOS platform.

How does this affect me?

To secure access of MacOS devices with conditional access, you are required to create a compliance policy for MacOS devices in your tenant. In the absence of a compliance policy, users who enroll the devices with Intune will be considered compliant and get access to the resources protected by conditional access.

First you need to create a Intune Compliance Policy for MacOS

There are 3 different categories for MacOS compliance settings

  • Device health
  • Device properties
  • System Security

Device health

Require a system integrity protection : Set this to Require to check if your macOS devices have system integrity protection enabled. This requires OS X El Capitan or later.

About System Integrity Protection on your Mac

Device properties

Minimum OS version : When a device does not meet the minimum OS version requirement, it is reported as noncompliant. A link with information on how to upgrade appears. The user can choose to upgrade their device. After that, they can access company resources.
Maximum OS version : When a device is using an OS version later than the one specified in the rule, access to company resources is blocked and the user is asked to contact their IT admin. Until there is a change in rule to allow the OS version, this device cannot be used to access company resources.

System security settings

Password

Require a password to unlock mobile devices : Set this to Require so users need to enter a password before they can access their device.
Simple passwords : Set this to Block so user can’t create a simple password like 1234 or 1111.
Minimum password length : Specify the minimum number of digits or characters that the password must have.
Password type : Specify whether the user must create an Alphanumeric password or a Numeric password.
Number of non-alphanumeric character in password : If you set Required password type to Alphanumeric , use this setting to specify the minimum number of character sets that the password must have.

Maximum minutes of inactivity before password is required : Specify the idle time before the user must reenter their password. Password expiration (days): Select the number of days (between 1 and 250) before the password expires and they must create a new one.

Number of previous passwords to prevent reuse : Specify the number of previously used passwords that cannot be reused.

Read more at :

Create a device compliance policy for macOS devices (preview) with Intune

Related Posts

IT /

Intune – Windows device enrollment restrictions – Cloud First

IT /

How to add “hidden” Windows UWP to Windows Store for Business – Cloud First

IT /

Office 2016 Active Directory-Based activation – Cloud First

‹ New Java 1.8.60 has been released – How to upgrade with psappdeploytoolkit – Mobile-First Cloud-First › How to setup Windows Defender Advanced Protection – Windows 10 Enterprise E5 – Cloud First

Recent Posts

  • Intune – Windows device enrollment restrictions – Cloud First
  • How to add “hidden” Windows UWP to Windows Store for Business – Cloud First
  • Office 2016 Active Directory-Based activation – Cloud First
  • How to deploy Windows Local Experience Packs with Intune – Cloud First
  • Conditional Access for Outlook Web Access (OWA) – Cloud First

Recent Comments

No comments to show.

Archives

  • November 2025
  • October 2025
  • August 2025
  • July 2025
  • June 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • November 2024
  • September 2024
  • July 2024
  • June 2024
  • March 2024
  • December 2023
  • August 2023
  • June 2023
  • March 2023
  • February 2023
  • December 2022
  • September 2022
  • August 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • January 2022
  • December 2021
  • October 2021
  • September 2021
  • August 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • February 2020
  • January 2020
  • December 2019
  • October 2019
  • September 2019
  • June 2019
  • April 2019
  • March 2019
  • February 2019
  • March 2018
  • February 2018
  • December 2017
  • October 2017
  • August 2017

Categories

  • IT

Back to Top

© maciejrebisz.com 2026
Powered by WordPress • Themify WordPress Themes