Set up Device Trust with Microsoft Intune on macOS
Complete the Microsoft Intune setup before deploying these profiles.
Deploy all macOS certificate and VPN profiles through the Device channel,
not the User channel. For custom profiles, set PayloadScope to System.
Firezone needs the identity in the system Keychain.
Deploy the profiles
-
Create a macOS Trusted certificate policy using the Device deployment channel. Name it Firezone Root and upload the root CA certificate.
-
Create another macOS trusted certificate policy using the Device channel. Name it Firezone Issuer and upload the issuing CA certificate.
-
Create a macOS SCEP certificate policy using the Device deployment channel and Device certificate type. Enter the device identity certificate values, select Firezone Root as the root certificate, and enter your CA’s SCEP URI (Firezone Issuer if using Cloud PKI). Allow all apps to access the private key and keep the key non-exportable.
-
Create a macOS VPN policy using the Device deployment channel. Select Custom VPN as the connection type and enter these values:
Setting Value Connection name FirezoneVPN server address 127.0.0.1Authentication method CertificatesAuthentication certificate The Firezone SCEP profile created in step 3 VPN identifier dev.firezone.firezone -
Add
accountSlugand any other managed configuration values as custom key-value pairs in the VPN profile. -
Assign the trusted certificate, SCEP, VPN, and Firezone app profiles to the same device group. Sync a test Mac and connect Firezone.
Also allowlist the Firezone macOS System Extension to avoid requiring users to approve it manually.
If the identity was installed without access for all apps, reissue it. Changing that setting later does not repair the private key's Keychain access control.
Settings supplied through a managed policy, including accountSlug, become
read-only in the Firezone Client. Users cannot change those values while the
policy is applied.
Allow connections through the macOS firewall
Deploy a firewall policy so macOS allows Firezone connections without asking users for approval.
-
In the Intune admin center, go to Devices → macOS → Configuration and create a Settings catalog policy named Firezone Firewall.
-
Select Add settings → Networking → Firewall.
-
Set Enable Firewall to True.
-
Under Applications, select Add and enter:
Setting Value Allowed TrueBundle ID dev.firezone.firezone.network-extension -
Save the application entry and assign the policy to the same Mac device group as the Firezone profiles.
See Microsoft's macOS firewall settings reference for additional firewall options.
Verify access
Connect the test Client and open a Resource protected by Require attestation. Test again after renewing the certificate.
Need help? See all support options.