Articles on: Apps

macOS Silent App Installation Through Microsoft Intune

macOS Silent App Installation Through Microsoft Intune – SOP

1. Overview

This document provides the step-by-step procedure for installing the Workstatus macOS Silent App on a user’s Mac system through Microsoft Intune.
The process includes:

  • Mapping the user's Mac Machine ID.
  • Creating the user in Microsoft Intune.
  • Assigning an Intune license to the user.
  • Installing and enrolling the Microsoft Intune Company Portal on the Mac.
  • Creating and assigning the Workstatus macOS application in Intune.
  • Verifying the application installation on the user’s Mac.

2. Prerequisites

Before starting the installation, ensure the following requirements are available:

  • Microsoft Intune Administrator access.
  • Microsoft Admin Center access.
  • Admin access to the user's Mac system.
  • Microsoft Intune Company Portal application.
  • The previous version of the Workstatus app should be uninstalled.
  • Workstatus macOS Silent App .pkg file.
  • Workstatus Machine ID.
  • User account created in Microsoft Intune.
  • Intune license assigned to the user.
  • macOS 14.8 (Sonoma) or later.
  • Internet connection on the Mac system.

3. Admin System / IT System Actions

3.1 Map the User Machine ID with Workstatus

The Machine ID must be collected from the user's Mac system before configuring the Intune installation.
Step 1: Open Terminal :
On the user's Mac:

  • Open Terminal.
  • Run the following command: ioreg -rd1 -c IOPlatformExpertDevice | grep IOPlatformUUID

Example Output :
"IOPlatformUUID" = "7XXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXX7"
Copy the IOPlatformUUID / Machine ID and use it for the Workstatus member-to-machine mapping process.


How to map a user's Machine ID in Workstatus


3.2 Log in to Microsoft Intune

Open the Microsoft Intune portal:
Microsoft Intune Admin Center
Sign in using an account with the required Intune administrator permissions.

4. Create User in Microsoft Intune

Step 1: Open Intune

Log in to the Microsoft Intune Admin Center.



Step 2: Create the User

Go to:
Users → Create User → Create New User
Enter the following information:

  • User Principal Name
  • User Email
  • Display Name

Set or generate the required password.
Save/copy the credentials as required.
Click Review + Create / Create.





5. Assign Intune License to the User

The Intune license must be assigned to the user before the Mac can be enrolled through Company Portal.


Step 1: Open Microsoft Admin Center

Open: Microsoft Admin Center
Sign in using an administrator account.



Step 2: Open Active Users

Go to: Users → Active Users



Step 3: Search for the User

Search for the user created for Intune.


Step 4: Manage Product License

Click the three-dot menu (...) for the user.
Select:
Manage product licenses




Step 5: Open Licenses and Apps

Click:
Licenses and apps
Select the required Microsoft Intune license.


Step 6: Save

Click:
Save Changes
The user is now assigned the required Intune license.



6. Actions on the User's Mac System


6.1 Install Microsoft Intune Company Portal

Download the Microsoft Intune Company Portal application:
Download Microsoft Intune Company Portal
Install the application on the Mac.

6.2. Enroll the Mac Using Company Portal
Step 1: Open Company Portal

Open:
Applications → Company Portal


Step 2: Sign In to Microsoft Company Portal
  • Open the Microsoft Intune Company Portal application on the user's Mac.
  • Sign in using the same user account created in Microsoft Intune.
  • Enter the password provided when the user account was created in Microsoft Intune.
  • When prompted to update the password, enter a new password and complete the password update process.
  • When the Keep your account secure window appears, click Next.
  • When the Microsoft Authenticator setup window appears, install the Microsoft Authenticator application on your mobile device.
  • Open Microsoft Authenticator on your mobile device and follow the on-screen instructions to add your account.
  • Scan the QR code displayed on the computer screen using Microsoft Authenticator.
  • Complete the authentication process by following the on-screen instructions.
  • Once authentication is successful, the Your Authenticator is added confirmation window will appear.

Result: The user account is authenticated and ready to continue the Company Portal enrollment process.















Step 3: Begin Enrollment

Click:
Begin



Step 4: Continue

Click:
Continue



Step 5: Download Management Profile

Click:
Download Profile
The system will redirect you to the macOS Device Management settings.



Step 6: Open Management Profile

In Device Management:

  • Locate Management Profile.
  • Double-click the profile.

A confirmation window will appear:
Are you sure you want to install this profile?
Click:
Install


Step 7: Enter Mac Password

Enter the Mac administrator password when prompted.
Wait for the enrollment process to complete.

6.3. Verify Device Management Profiles

After successful enrollment, open:
System Settings → General → Device Management
Verify that the required profiles/settings are visible.
The following items should be available:

  • Intune MDM Agent PPPC Profile
  • Intune MDM Agent SCEP Profile
  • Management Profile

If the profiles are not visible, verify the Company Portal enrollment and Intune license assignment.



7. Workstatus macOS Silent App Installation – Intune Admin Action

After the Mac is successfully enrolled in Intune, the Workstatus Silent App can be configured for deployment.

7.1 Open Microsoft Intune

Log in to: Microsoft Intune Admin Center




7.2. Create macOS Application

Go to:
Apps → macOS → Create





7.3 Select App Type

Under Select App Type:

  • Select macOS app (PKG).
  • Click Select.






7.4. App Information

Enter the application information.


Step 1: Upload App Package

Click:
App package file
Upload the Workstatus macOS Silent App .pkg file provided by the Workstatus team.







Step 2: Enter Publisher
  • Enter the appropriate publisher name.

Example: Valuecoders

  • Complete the required application information.

Click: Next


7.5 Program
  • Review the Program settings.
  • No additional configuration is required:

Click: Next



7.6 Requirements

Under Requirements:

  • Open the macOS version dropdown.
  • Select:

macOS 14.0 (Sonoma)
Continue to the next step.



7.7 Detection Rules
  • Configure the application detection rules.
  • Bundle ID

Enter: io.workstatus.desktop

  • Version

Enter: 1.2

  • The detection rule allows Intune to determine whether the Workstatus application is installed on the target Mac.

Click: Next


7.8. Assignment

Assign the application to the required users or devices.
Available assignment options may include:

  • All Users
  • All Devices
  • Add Group

Select the appropriate assignment based on the organization's deployment requirement.
Click:
Next


7.9. Review and Create

Review all configured application details.
Verify:

  • App package
  • App name
  • Publisher
  • macOS requirement
  • Bundle ID
  • Version
  • Assignment
  • Installation configuration

If all information is correct:
Click:
Create
The Workstatus macOS Silent App is now configured for deployment through Microsoft Intune.



8. Installation Verification

After the application has been assigned, allow sufficient time for Intune to deploy the application to the Mac.
On the Intune Admin Center:
Apps → macOS → Workstatus Silent App → Device/User Install Status
Check the installation status.
Verify whether the application is:

  • Installed
  • Not Installed
  • Failed
  • Pending

On the user's Mac, verify that the Workstatus application has been installed successfully.



9. Important Information

  • The Machine ID must be collected from the target Mac before completing the machine mapping process.
  • The user must sign in to Company Portal using the same account configured in Intune.
  • The Mac must be successfully enrolled in Intune before application deployment.
  • The Workstatus .pkg file should be obtained from the authorized Workstatus team.
  • Ensure the configured Bundle ID matches the Workstatus application package.
  • Verify the application installation status from the Intune Admin Center after deployment.

Updated on: 10/10/2026

Was this article helpful?

Share your feedback

Cancel

Thank you!