Runbook — Provision a New MacBook Pro with Intune

Version 1.0
Date 2026-06-22
Employee Ben Scully → bscully@mptwork.com
Device MacBook Pro (corporate, enrolled via Apple Business Manager + Automated Device Enrollment)
Tenant mptwork.com (mptwork.onmicrosoft.com)
Consoles Intune intune.microsoft.com · M365 admin admin.microsoft.com · Entra entra.microsoft.com
Companion SOPs Intune device management — sop-manage-devices-intune-mptwork.md · Apple Business/APNs — sop-get-apple-id-abm-google-managed-play-mptwork.md
Assumes the tenant prerequisites are already in place: Intune is the MDM authority, the Apple APNs certificate is valid, Apple Business is linked to Intune with an ADE token, a macOS enrollment profile exists, and macOS compliance/configuration policies and apps are assigned to a staff group. This runbook provisions one device for one new hire.

Phase A — Pre-provisioning (IT, before powering on the Mac)

A1. Create Ben's identity and license

  1. M365 admin center → Users → Add a user:
    • Display name: Ben Scully
    • Username: bscully@mptwork.com
    • Usage location, job title, department, and manager.
  2. Assign the Microsoft 365 Business Premium license (includes Intune + Defender for Business). Confirm under the user's Licenses.
  3. Set a temporary password and require change at first sign-in.

A2. Add Ben to the right groups

  1. Entra → Groups → add bscully@mptwork.com to:
    • the licensing group (if you use group-based licensing),
    • the macOS staff group that compliance policies, configuration profiles, and required apps are assigned to (e.g., Staff-macOS).
  2. Membership drives policy/app targeting at enrollment, so confirm it before the device is turned on.

A3. Confirm the MacBook Pro is ready for zero-touch

  1. Verify the MacBook Pro's serial number appears in Apple Business and is assigned to the Intune MDM server token.
    • If bought through Apple/an authorized reseller, it should appear automatically.
    • If bought retail and not present, add it with Apple Configurator, or fall back to manual Company Portal enrollment (Phase B, alternate).
  2. Intune → Devices → Enrollment → Apple → Enrollment program tokens → open the token → Devices → confirm the serial is assigned to the macOS enrollment profile (the profile with user affinity / "Enroll with user affinity," locked enrollment, and Setup Assistant options). If not, assign it.

A4. Pre-flight checks

  1. APNs certificate is not near expiry.
  2. VPP (Apps & Books) token valid (for App Store apps).
  3. Compliance policy, configuration profiles (incl. FileVault disk encryption with key escrow), and required apps (Microsoft 365, Edge, Company Portal, Microsoft Defender) are assigned to Staff-macOS.

Phase B — Enrollment at the device (Setup Assistant)

This can be done by IT first or handed to Ben. The Mac must reach the internet.

  1. Power on the MacBook Pro; choose language and region; connect to Wi-Fi (or Ethernet).
  2. The Mac contacts Apple, sees it's supervised, and shows Remote Management branded MPT Work.
  3. At the sign-in prompt, enter bscully@mptwork.com and the temporary password, then complete MFA if prompted. (With user affinity, this ties the device to Ben.)
  4. The device enrolls into Intune as supervised, corporate-owned. Setup Assistant follows the enrollment profile (skips configured panes, creates the local account).
  5. Setup Assistant finishes to the macOS desktop; the management profile and Company Portal are present.

Alternate (not in Apple Business): have Ben open Company Portal (or the enrollment URL), sign in as bscully@mptwork.com, and install the management profile (System Settings → Device Management → approve). Then in Intune set the device's ownership = Corporate.


Phase C — Automatic configuration and apps (verify, don't rush)

Intune now applies the assigned policies. Allow several minutes and keep the Mac online.

  1. Configuration profiles apply: security baseline, FileVault (encryption begins; the recovery key escrows to Intune), Platform SSO, Wi-Fi/VPN, restrictions.
  2. Required apps install: Microsoft 365 for macOS, Microsoft Edge, Microsoft Defender, Company Portal.
  3. Defender for Business onboards the Mac (verify later in the Defender portal).
  4. Compliance policy evaluates (FileVault on, minimum macOS version, firewall on, Defender healthy).

Phase D — Verify and enforce (IT)

  1. Intune → Devices → macOS → open Ben's MacBook Pro:
    • Enrolled = yes, Ownership = Corporate, Primary user = Ben Scully (set under Properties if needed).
    • Compliance = Compliant (wait out any grace period; if non-compliant, open the policy to see which setting failed).
  2. Confirm FileVault is On and the recovery key is stored in Intune (device → Monitor → Recovery keys).
  3. Confirm required apps installed (device → Managed Apps) and that Ben can install optional apps from Company Portal.
  4. Confirm Defender shows the Mac onboarded (Defender portal → Devices).
  5. Confirm Conditional Access: from this compliant Mac Ben can reach Microsoft 365; a non-compliant/unmanaged device is blocked.

Phase E — Hand off to Ben

Provide Ben with:

  1. Sign-in: bscully@mptwork.com + temporary password (change at first sign-in).
  2. MFA enrollment: register at https://aka.ms/mfasetup (Microsoft Authenticator recommended).
  3. Company Portal: where to install approved apps and see device status.
  4. What's already set up: email/Teams/OneDrive, FileVault encryption, security software.
  5. IT support contact and the acceptable-use / device policy to acknowledge.

Ben's quick start:

  • Sign in, complete MFA registration, change the password.
  • Open Outlook/Teams to confirm mail and chat.
  • Open Company Portal to see the device is compliant and browse optional apps.

Phase F — Record and close out

  1. Set/confirm Primary user = Ben Scully in Intune.
  2. Update the asset register: serial number, model, assigned to Ben Scully, issue date, enrollment date.
  3. Note the FileVault recovery key location (in Intune) for support.
  4. Close the onboarding ticket.

Quick checklists

IT pre-provisioning

Item
bscully@mptwork.com created, licensed (Business Premium)
Added to Staff-macOS (+ licensing group)
MacBook serial in Apple Business, assigned to Intune token + macOS enrollment profile
APNs/VPP valid; compliance, config (FileVault), and apps assigned

Post-enrollment verification

Item
Enrolled, Corporate, Primary user = Ben Scully
Compliant; FileVault on, key escrowed
Required apps installed; Defender onboarded
Conditional Access enforced; Company Portal works

Notes

  • User affinity (signing in as Ben during Setup Assistant) is what binds the device to Ben and applies his user-targeted policies — don't skip it for a personally-assigned Mac.
  • If the Mac wasn't in Apple Business, it can't do zero-touch ADE; use Apple Configurator to add it or enroll manually and set ownership to Corporate.
  • Verify current steps against Microsoft Learn — the Intune portal and macOS enrollment flow change periodically.

Read more

SOP — Create and Manage Microsoft Azure for Enterprise

Version 1.0 Date 2026-06-22 Domain mptwork.com Model Identity rooted in the existing Microsoft Entra tenant; hierarchy of Management Groups → Subscriptions → Resource Groups → Resources Consoles Azure portal portal.azure.com · Entra admin center entra.microsoft.com Companion SOPs M365/Entra — sop-subscribe-manage-m365-mptwork.md, sop-entra-id-authentication-sso-mptwork.md · Network/IPAM — enterprise-ipam-reference-architecture.md · AWS

By admin

SOP — Create and Manage a Google Cloud (GCP) Account

Version 1.0 Date 2026-06-22 Domain mptwork.com Model GCP Organization rooted in Cloud Identity / Google Workspace for mptwork.com; hierarchy of Folders → Projects; workforce access via Google Groups, optionally federated to Microsoft Entra Companion SOPs Google Workspace — sop-subscribe-manage-google-workspace-mptwork.md · Entra auth & SSO — sop-entra-id-authentication-sso-mptwork.md · Network/IPAM — enterprise-ipam-reference-architecture.md

By admin