This article discusses how to configure Azure Intune to deploy and update macOS Clients for SDP users in your account.
This feature is supported for macOS Client v5.0 and higher.
Starting with macOS Client v5.0, you can configure the Cato Management Application to use an MDM to manage the deployment and updates for macOS Clients in your organization. All Client updates are controlled using the MDM and end users don't receive notifications of new Client versions.
This is an overview of the workflow to implement an MDM solution for macOS Clients in your account.
-
From the navigation menu, click Access > Client Rollout.
-
Click the Upgrade Policy tab.
-
For the macOS Client, choose Managed by Admin.
-
Import the macOS package.
-
Configure Azure Intune to create a policy that allows the DMG extension and VPN profiles for end users.
Otherwise, end users need to manually approve and allow the above items in the macOS.
-
In Azure Intune, distribute the new macOS Client version to the end users in your account.
Use the Microsoft Intune Admin Center to add the Client package you want to distribute.
Import the macOS package to Intune
-
From the navigation menu, select Apps > macOS.
-
Click Add and under App type, select macOS app (PKG).
-
Click Select and select the Cato Client package you want to upload. You will have to provide the following information:
-
Name
-
Description
-
Publisher Name
-
-
Under Category, select the Business and Computer management checkboxes, respectively.
-
Click Next and in the Program page, click Next again.
-
In the Requirements page, select the minimum required macOS operating system as required for the Cato Client version you are deploying.
-
In the Detection rules page, make sure you set Ignore app version to No, and click Next.
-
On the Assignments page, determine who will receive this package (for example, All Users), and click Next.
-
Click Create.
The macOS Client package is imported to Intune and is available in the Apps page for macOS packages.
Starting with the macOS Client v5.0, the following permissions are required to install the Client on a macOS host:
-
Allow the Cato Client to create a VPN profile
-
Allow system extensions for the Cato Client
You can configure Intune to automatically allow these permissions for end user as part of the installation process for the new Client version. Otherwise, the end user must manually configure the macOS settings as part of the installation process.
Create a custom VPN profile.
-
Download the custom profile attached to this article, or create your own custom profile.
-
From the Microsoft Intune Admin Center, navigate to Devices > macOS > Configuration to create a policy for the macOS Client
-
Click Create and select New Policy. (based on the data in the table above):
-
In Create a profile, under Profile type select Custom.
-
Click Create.
-
-
In the Basics page, enter a Name and optional Description for the profile, and click Next.
-
In the Configuration settings page, enter the following:
-
Provide a descriptive name for the custom profile
-
Under Configuration profile file, upload the custom profile you downloaded above
-
Click Next
-
-
In the Assignments page, click Add all devices and click Next.
-
Click Create.
This article comes with a preconfigured, customized VPN profile that you can upload to Intune. If you want to create a custom VPN profile, you will need to download the Apple Configurator tool, and create a profile using the information in the table, below.
|
Setting |
Value |
|---|---|
|
Connection Name |
Cato Networks VPN |
|
Connection Type |
Custom SSL (from the drop-down menu) |
|
Identifier |
com.catonetworks.mac.CatoClient |
|
Server |
vpn.catonetworks.net |
|
Account |
CatoClientVPN |
|
Provider Bundle Identifier |
com.catonetworks.mac.CatoClient.CatoClientSysExtension |
|
User Authentication |
|
|
Provider Type |
Packet Tunnel |
|
Provider Designated Requirement |
anchor apple generic and identifier "com.catonetworks.mac.CatoClient" and (certificate leaf[field.1.2.840.113635.100.6.1.9] /* exists */ or certificate 1[field.1.2.840.113635.100.6.2.6] /* exists */ and certificate leaf[field.1.2.840.113635.100.6.1.13] /* exists */ and certificate leaf[subject.OU] = CKGSB8CH43) |
Create the new profile and then configure the VPN settings for that profile.
-
From the Microsoft Intune Admin Center, navigate to Devices > macOS > Configuration to create a policy for the macOS Client:
-
Click Create and select New Policy. (based on the data in the table above):
-
In Create a profile, under Profile type select Settings catalog.
-
Click Create.
-
-
In the Basics page, enter a Name and Description for the profile, and click Next.
-
In the Configuration settings page, click Add settings.
-
Using the Search box, enter managed login items and verify that the Rules setting is selected
-
Using the search box, enter system extensions and verify that Allowed System Extensions is selected
-
Using the search box, enter notifications and under User Experience > Notifications, verify that Notification Settings is selected
-
Close the Add settings pane
-
-
In the Configuration page, under Rules, click Edit ins.
-
In the Comment field enter an optional comment describing the instance
-
In the Rule Value field, enter the following value from the allowed system extensions:
com.catonetworks.mac.CatoClient
-
Click Save.
-
-
In the Configuration page, under Allowed System Extensions, click Edit instance.
-
Enter the values listed in the Allowed System Extensions, below:
-
com.catonetworks.mac.CatoClient
-
com.catonetworks.mac.CatoClient.CatoClientSysExtension
-
-
Under Team Identifier, enter the value as listed below, CKGSB8CH43
-
Click Save
-
-
In the Configuration page, under Notification Settings, click Edit instance.
-
Under Bundle Identifier, enter com.catonetworks.mac.CatoClient
-
Verify that Critical Alert Enabled is set to True
-
Click Save
-
-
Click Next, and on the Scope tags page, click Next again.
-
In the Assignments page, determine who should receive this package, for example, click Add all devices or select a specific group of users, and click Next.
-
Click Create.
0 comments
Article is closed for comments.