This guide covers deploying Enpass Password Manager to macOS endpoints using Microsoft Intune via a PKG installer.
Step 1: Prepare the Installer
Download the latest Enpass macOS installer (.pkg) from enpass.io/downloads.
Step 2: Add the App in Intune
-
Open the Microsoft Intune admin center.
-
Navigate to Apps → macOS and select Add.
-
In the Select app type window, select macOS app (PKG) from the App type dropdown.
-
Click Select.
Step 3: App Information
-
On the App information screen, select Select app package file.
-
Use the file explorer to select your
Enpass.pkginstaller and click OK. -
Note the app name and version displayed, then click Next.
Step 4: Program (Optional Scripts)
On the Program screen, specify pre-install or post-install scripts if required by your environment. Click Next.
Step 5: Requirements
|
Setting |
Value |
|---|---|
|
Minimum operating system |
macOS Ventura 13.0 |
Click Next.
Step 6: Detection Rules
Confirm the following values on the Detection rules screen:
|
Field |
Value |
|---|---|
|
App bundle ID |
|
|
App version |
Confirm the version displayed matches your installer |
Click Next.
Step 7: Assignments
Add the appropriate groups or users, then click Next.
Step 8: Review + Create
Review your settings and click Create.
Configuring App Policy
To apply policy-enforced and policy-email configuration, deploy the custom configuration profile (.mobileconfig) via a separate Intune configuration policy.
Step 1: Prepare the Configuration Profile
-
Download the base configuration file from here.
-
Open the file in a text editor and replace the placeholder values:
-
Set
policy-enforcedtotrue. -
Set
policy-emailto the dynamic variable for the user's email address in your UEM solution.
-
-
Save the file.
Step 2: Create the Configuration Policy in Intune
-
In the Intune Portal, navigate to Devices → macOS and select Configuration.
-
Click Create → New Policy.
-
The Platform is pre-selected as macOS.
-
Select Templates as the Profile type.
-
Select Custom as the Template name, then click Create.
-
On the Basics screen, enter a name and click Next.
-
On the Configuration settings screen:
-
Enter a Custom configuration profile name.
-
Select a Deployment channel.
-
Upload your edited
.mobileconfigfile as the Configuration profile file.
-
-
Click Next.
-
On the Assignments screen, add your groups and click Next.
-
On the Review + create screen, click Create.