Runbook — Provision a New MacBook Pro with Intune
| Version | 1.0 |
| Date | 2026-06-22 |
| Employee | Ben Scully → bscully@mptwork.com |
| Device | MacBook Pro (corporate, enrolled via Apple Business Manager + Automated Device Enrollment) |
| Tenant | mptwork.com (mptwork.onmicrosoft.com) |
| Consoles | Intune intune.microsoft.com · M365 admin admin.microsoft.com · Entra entra.microsoft.com |
| Companion SOPs | Intune device management — sop-manage-devices-intune-mptwork.md · Apple Business/APNs — sop-get-apple-id-abm-google-managed-play-mptwork.md |
Assumes the tenant prerequisites are already in place: Intune is the MDM authority, the Apple APNs certificate is valid, Apple Business is linked to Intune with an ADE token, a macOS enrollment profile exists, and macOS compliance/configuration policies and apps are assigned to a staff group. This runbook provisions one device for one new hire.
Phase A — Pre-provisioning (IT, before powering on the Mac)
A1. Create Ben's identity and license
- M365 admin center → Users → Add a user:
- Display name: Ben Scully
- Username:
bscully@mptwork.com - Usage location, job title, department, and manager.
- Assign the Microsoft 365 Business Premium license (includes Intune + Defender for Business). Confirm under the user's Licenses.
- Set a temporary password and require change at first sign-in.
A2. Add Ben to the right groups
- Entra → Groups → add
bscully@mptwork.comto:- the licensing group (if you use group-based licensing),
- the macOS staff group that compliance policies, configuration profiles, and required apps are assigned to (e.g.,
Staff-macOS).
- Membership drives policy/app targeting at enrollment, so confirm it before the device is turned on.
A3. Confirm the MacBook Pro is ready for zero-touch
- Verify the MacBook Pro's serial number appears in Apple Business and is assigned to the Intune MDM server token.
- If bought through Apple/an authorized reseller, it should appear automatically.
- If bought retail and not present, add it with Apple Configurator, or fall back to manual Company Portal enrollment (Phase B, alternate).
- Intune → Devices → Enrollment → Apple → Enrollment program tokens → open the token → Devices → confirm the serial is assigned to the macOS enrollment profile (the profile with user affinity / "Enroll with user affinity," locked enrollment, and Setup Assistant options). If not, assign it.
A4. Pre-flight checks
- APNs certificate is not near expiry.
- VPP (Apps & Books) token valid (for App Store apps).
- Compliance policy, configuration profiles (incl. FileVault disk encryption with key escrow), and required apps (Microsoft 365, Edge, Company Portal, Microsoft Defender) are assigned to
Staff-macOS.
Phase B — Enrollment at the device (Setup Assistant)
This can be done by IT first or handed to Ben. The Mac must reach the internet.
- Power on the MacBook Pro; choose language and region; connect to Wi-Fi (or Ethernet).
- The Mac contacts Apple, sees it's supervised, and shows Remote Management branded MPT Work.
- At the sign-in prompt, enter
bscully@mptwork.comand the temporary password, then complete MFA if prompted. (With user affinity, this ties the device to Ben.) - The device enrolls into Intune as supervised, corporate-owned. Setup Assistant follows the enrollment profile (skips configured panes, creates the local account).
- Setup Assistant finishes to the macOS desktop; the management profile and Company Portal are present.
Alternate (not in Apple Business): have Ben open Company Portal (or the enrollment URL), sign in as bscully@mptwork.com, and install the management profile (System Settings → Device Management → approve). Then in Intune set the device's ownership = Corporate.
Phase C — Automatic configuration and apps (verify, don't rush)
Intune now applies the assigned policies. Allow several minutes and keep the Mac online.
- Configuration profiles apply: security baseline, FileVault (encryption begins; the recovery key escrows to Intune), Platform SSO, Wi-Fi/VPN, restrictions.
- Required apps install: Microsoft 365 for macOS, Microsoft Edge, Microsoft Defender, Company Portal.
- Defender for Business onboards the Mac (verify later in the Defender portal).
- Compliance policy evaluates (FileVault on, minimum macOS version, firewall on, Defender healthy).
Phase D — Verify and enforce (IT)
- Intune → Devices → macOS → open Ben's MacBook Pro:
- Enrolled = yes, Ownership = Corporate, Primary user = Ben Scully (set under Properties if needed).
- Compliance = Compliant (wait out any grace period; if non-compliant, open the policy to see which setting failed).
- Confirm FileVault is On and the recovery key is stored in Intune (device → Monitor → Recovery keys).
- Confirm required apps installed (device → Managed Apps) and that Ben can install optional apps from Company Portal.
- Confirm Defender shows the Mac onboarded (Defender portal → Devices).
- Confirm Conditional Access: from this compliant Mac Ben can reach Microsoft 365; a non-compliant/unmanaged device is blocked.
Phase E — Hand off to Ben
Provide Ben with:
- Sign-in:
bscully@mptwork.com+ temporary password (change at first sign-in). - MFA enrollment: register at
https://aka.ms/mfasetup(Microsoft Authenticator recommended). - Company Portal: where to install approved apps and see device status.
- What's already set up: email/Teams/OneDrive, FileVault encryption, security software.
- IT support contact and the acceptable-use / device policy to acknowledge.
Ben's quick start:
- Sign in, complete MFA registration, change the password.
- Open Outlook/Teams to confirm mail and chat.
- Open Company Portal to see the device is compliant and browse optional apps.
Phase F — Record and close out
- Set/confirm Primary user = Ben Scully in Intune.
- Update the asset register: serial number, model, assigned to Ben Scully, issue date, enrollment date.
- Note the FileVault recovery key location (in Intune) for support.
- Close the onboarding ticket.
Quick checklists
IT pre-provisioning
| ✔ | Item |
|---|---|
| ☐ | bscully@mptwork.com created, licensed (Business Premium) |
| ☐ | Added to Staff-macOS (+ licensing group) |
| ☐ | MacBook serial in Apple Business, assigned to Intune token + macOS enrollment profile |
| ☐ | APNs/VPP valid; compliance, config (FileVault), and apps assigned |
Post-enrollment verification
| ✔ | Item |
|---|---|
| ☐ | Enrolled, Corporate, Primary user = Ben Scully |
| ☐ | Compliant; FileVault on, key escrowed |
| ☐ | Required apps installed; Defender onboarded |
| ☐ | Conditional Access enforced; Company Portal works |
Notes
- User affinity (signing in as Ben during Setup Assistant) is what binds the device to Ben and applies his user-targeted policies — don't skip it for a personally-assigned Mac.
- If the Mac wasn't in Apple Business, it can't do zero-touch ADE; use Apple Configurator to add it or enroll manually and set ownership to Corporate.
- Verify current steps against Microsoft Learn — the Intune portal and macOS enrollment flow change periodically.