Set up Device Trust with Microsoft Intune on macOS

Complete the Microsoft Intune setup before deploying these profiles.

Deploy all macOS certificate and VPN profiles through the Device channel, not the User channel. For custom profiles, set PayloadScope to System. Firezone needs the identity in the system Keychain.

Deploy the profiles

  1. Create a macOS Trusted certificate policy using the Device deployment channel. Name it Firezone Root and upload the root CA certificate.

  2. Create another macOS trusted certificate policy using the Device channel. Name it Firezone Issuer and upload the issuing CA certificate.

  3. Create a macOS SCEP certificate policy using the Device deployment channel and Device certificate type. Enter the device identity certificate values, select Firezone Root as the root certificate, and enter your CA’s SCEP URI (Firezone Issuer if using Cloud PKI). Allow all apps to access the private key and keep the key non-exportable.

  4. Create a macOS VPN policy using the Device deployment channel. Select Custom VPN as the connection type and enter these values:

    SettingValue
    Connection nameFirezone
    VPN server address127.0.0.1
    Authentication methodCertificates
    Authentication certificateThe Firezone SCEP profile created in step 3
    VPN identifierdev.firezone.firezone
  5. Add accountSlug and any other managed configuration values as custom key-value pairs in the VPN profile.

  6. Assign the trusted certificate, SCEP, VPN, and Firezone app profiles to the same device group. Sync a test Mac and connect Firezone.

Also allowlist the Firezone macOS System Extension to avoid requiring users to approve it manually.

If the identity was installed without access for all apps, reissue it. Changing that setting later does not repair the private key's Keychain access control.

Settings supplied through a managed policy, including accountSlug, become read-only in the Firezone Client. Users cannot change those values while the policy is applied.

Allow connections through the macOS firewall

Deploy a firewall policy so macOS allows Firezone connections without asking users for approval.

  1. In the Intune admin center, go to Devices → macOS → Configuration and create a Settings catalog policy named Firezone Firewall.

  2. Select Add settings → Networking → Firewall.

  3. Set Enable Firewall to True.

  4. Under Applications, select Add and enter:

    SettingValue
    AllowedTrue
    Bundle IDdev.firezone.firezone.network-extension
  5. Save the application entry and assign the policy to the same Mac device group as the Firezone profiles.

See Microsoft's macOS firewall settings reference for additional firewall options.

Verify access

Connect the test Client and open a Resource protected by Require attestation. Test again after renewing the certificate.


Need help? See all support options.