macOS Silent App Installation Through Microsoft Intune
macOS Silent App Installation Through Microsoft Intune – SOP
1. Overview
This document provides the step-by-step procedure for installing the Workstatus macOS Silent App on a user’s Mac system through Microsoft Intune.
The process includes:
- Mapping the user's Mac Machine ID.
- Creating the user in Microsoft Intune.
- Assigning an Intune license to the user.
- Installing and enrolling the Microsoft Intune Company Portal on the Mac.
- Creating and assigning the Workstatus macOS application in Intune.
- Verifying the application installation on the user’s Mac.
2. Prerequisites
Before starting the installation, ensure the following requirements are available:
- Microsoft Intune Administrator access.
- Microsoft Admin Center access.
- Admin access to the user's Mac system.
- Microsoft Intune Company Portal application.
- The previous version of the Workstatus app should be uninstalled.
- Workstatus macOS Silent App
.pkgfile. - Workstatus Machine ID.
- User account created in Microsoft Intune.
- Intune license assigned to the user.
- macOS 14.8 (Sonoma) or later.
- Internet connection on the Mac system.
3. Admin System / IT System Actions
3.1 Map the User Machine ID with Workstatus
The Machine ID must be collected from the user's Mac system before configuring the Intune installation.
Step 1: Open Terminal :
On the user's Mac:
- Open Terminal.
- Run the following command: ioreg -rd1 -c IOPlatformExpertDevice | grep IOPlatformUUID
Example Output :
"IOPlatformUUID" = "7XXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXX7"
Copy the IOPlatformUUID / Machine ID and use it for the Workstatus member-to-machine mapping process.
How to map a user's Machine ID in Workstatus
3.2 Log in to Microsoft Intune
Open the Microsoft Intune portal:
Microsoft Intune Admin Center
Sign in using an account with the required Intune administrator permissions.
4. Create User in Microsoft Intune
Step 1: Open Intune
Log in to the Microsoft Intune Admin Center.

Step 2: Create the User
Go to:
Users → Create User → Create New User
Enter the following information:
- User Principal Name
- User Email
- Display Name
Set or generate the required password.
Save/copy the credentials as required.
Click Review + Create / Create.



5. Assign Intune License to the User
The Intune license must be assigned to the user before the Mac can be enrolled through Company Portal.
Step 1: Open Microsoft Admin Center
Open: Microsoft Admin Center
Sign in using an administrator account.

Step 2: Open Active Users
Go to: Users → Active Users

Step 3: Search for the User
Search for the user created for Intune.
Step 4: Manage Product License
Click the three-dot menu (...) for the user.
Select:
Manage product licenses

Step 5: Open Licenses and Apps
Click:
Licenses and apps
Select the required Microsoft Intune license.
Step 6: Save
Click:
Save Changes
The user is now assigned the required Intune license.

6. Actions on the User's Mac System
6.1 Install Microsoft Intune Company Portal
Download the Microsoft Intune Company Portal application:
Download Microsoft Intune Company Portal
Install the application on the Mac.
6.2. Enroll the Mac Using Company Portal
Step 1: Open Company Portal
Open:
Applications → Company Portal

Step 2: Sign In to Microsoft Company Portal
- Open the Microsoft Intune Company Portal application on the user's Mac.
- Sign in using the same user account created in Microsoft Intune.
- Enter the password provided when the user account was created in Microsoft Intune.
- When prompted to update the password, enter a new password and complete the password update process.
- When the Keep your account secure window appears, click Next.
- When the Microsoft Authenticator setup window appears, install the Microsoft Authenticator application on your mobile device.
- Open Microsoft Authenticator on your mobile device and follow the on-screen instructions to add your account.
- Scan the QR code displayed on the computer screen using Microsoft Authenticator.
- Complete the authentication process by following the on-screen instructions.
- Once authentication is successful, the Your Authenticator is added confirmation window will appear.
Result: The user account is authenticated and ready to continue the Company Portal enrollment process.










Step 3: Begin Enrollment
Click:
Begin

Step 4: Continue
Click:
Continue

Step 5: Download Management Profile
Click:
Download Profile
The system will redirect you to the macOS Device Management settings.

Step 6: Open Management Profile
In Device Management:
- Locate Management Profile.
- Double-click the profile.
A confirmation window will appear:
Are you sure you want to install this profile?
Click:
Install

Step 7: Enter Mac Password
Enter the Mac administrator password when prompted.
Wait for the enrollment process to complete.
6.3. Verify Device Management Profiles
After successful enrollment, open:
System Settings → General → Device Management
Verify that the required profiles/settings are visible.
The following items should be available:
- Intune MDM Agent PPPC Profile
- Intune MDM Agent SCEP Profile
- Management Profile
If the profiles are not visible, verify the Company Portal enrollment and Intune license assignment.
7. Workstatus macOS Silent App Installation – Intune Admin Action
After the Mac is successfully enrolled in Intune, the Workstatus Silent App can be configured for deployment.
7.1 Open Microsoft Intune
Log in to: Microsoft Intune Admin Center

7.2. Create macOS Application
Go to:
Apps → macOS → Create


7.3 Select App Type
Under Select App Type:
- Select macOS app (PKG).
- Click Select.


7.4. App Information
Enter the application information.
Step 1: Upload App Package
Click:
App package file
Upload the Workstatus macOS Silent App .pkg file provided by the Workstatus team.




Step 2: Enter Publisher
- Enter the appropriate publisher name.
Example: Valuecoders
- Complete the required application information.
Click: Next

7.5 Program
- Review the Program settings.
- No additional configuration is required:
Click: Next

7.6 Requirements
Under Requirements:
- Open the macOS version dropdown.
- Select:
macOS 14.0 (Sonoma)
Continue to the next step.


7.7 Detection Rules
- Configure the application detection rules.
- Bundle ID
Enter: io.workstatus.desktop
- Version
Enter: 1.2
- The detection rule allows Intune to determine whether the Workstatus application is installed on the target Mac.
Click: Next

7.8. Assignment
Assign the application to the required users or devices.
Available assignment options may include:
- All Users
- All Devices
- Add Group
Select the appropriate assignment based on the organization's deployment requirement.
Click:
Next

7.9. Review and Create
Review all configured application details.
Verify:
- App package
- App name
- Publisher
- macOS requirement
- Bundle ID
- Version
- Assignment
- Installation configuration
If all information is correct:
Click:
Create
The Workstatus macOS Silent App is now configured for deployment through Microsoft Intune.

8. Installation Verification
After the application has been assigned, allow sufficient time for Intune to deploy the application to the Mac.
On the Intune Admin Center:
Apps → macOS → Workstatus Silent App → Device/User Install Status
Check the installation status.
Verify whether the application is:
- Installed
- Not Installed
- Failed
- Pending
On the user's Mac, verify that the Workstatus application has been installed successfully.

9. Important Information
- The Machine ID must be collected from the target Mac before completing the machine mapping process.
- The user must sign in to Company Portal using the same account configured in Intune.
- The Mac must be successfully enrolled in Intune before application deployment.
- The Workstatus
.pkgfile should be obtained from the authorized Workstatus team. - Ensure the configured Bundle ID matches the Workstatus application package.
- Verify the application installation status from the Intune Admin Center after deployment.
Updated on: 10/10/2026
Thank you!