Agent skill

macOS Intune Baseline

by vinayaklatthe in vinayaklatthe/microsoft-security-skills

Guidance for hardening macOS endpoints managed by Microsoft Intune — automated device enrollment via Apple Business Manager (ABM), platform single sign-on (PSSO) with Entra ID, FileVault disk…

MITAuto-check passedBackend & APIs

Install macOS Intune Baseline

skills CLI
$ npx skills add vinayaklatthe/microsoft-security-skills --skill macos-intune-baseline -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install vinayaklatthe/microsoft-security-skills macos-intune-baseline --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/vinayaklatthe/microsoft-security-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/macos-intune-baseline .claude/skills/macos-intune-baseline && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
macos-intune-baseline
GitHub stars
175
Token cost
~2.4k tokens
SKILL.md length
969 words
Files
1
Skills in repo
50
Repo updated
First seen
Licence
MIT

At a glance

Guidance for hardening macOS endpoints managed by Microsoft Intune — automated device enrollment via Apple Business Manager (ABM), platform single sign-on (PSSO) with Entra ID, FileVault disk…

  • Works in 9 steps: Enroll via ABM + Automated Device… → Platform SSO (PSSO) with Entra ID is the… → FileVault profile with escrow to Intune.… → …
  • General Intune device management end-to-end (use intune-device-mgmt)
  • SKILL.md covers When to use, Capability map, Approach and Guardrails, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

macOS Intune Baseline is an agent skill from vinayaklatthe/microsoft-security-skills. Guidance for hardening macOS endpoints managed by Microsoft Intune — automated device enrollment via Apple Business Manager (ABM), platform single sign-on (PSSO) with Entra ID, FileVault disk encryption escrow, security configuration profiles (Gatekeeper, XProtect, system extensions allowlist, firewall, login window, Privacy Preferences Policy Control / PPPC), Microsoft Defender for Endpoint on macOS, app management (VPP / managed apps / shell scripts via Intune), patching strategy (managed software updates /…

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Authentication and Shell scripting. It works with macOS, Microsoft Defender, Microsoft Entra ID and iOS. The repository describes itself as: Curated Microsoft Security skills for AI agents - Defender, Sentinel, Entra, Purview, Intune, Security Copilot. The licence is MIT.

When your agent uses it

  • General Intune device management end-to-end (use intune-device-mgmt)
  • MDE config alone (use defender-for-endpoint)
  • IOS device management

Example prompts

  • “/macos-intune-baseline”

Workflow steps

9 steps, taken from the first numbered list in SKILL.md.

  1. Enroll via ABM + Automated Device Enrollment. Manual enrollment is fine for
  2. Platform SSO (PSSO) with Entra ID is the modern macOS SSO. User signs into
  3. FileVault profile with escrow to Intune. Keys are recoverable by IT (with
  4. Defender for Endpoint on macOS via Intune app deployment + onboarding profile.
  5. **Configuration profiles — start with the Microsoft macOS security baseline (or
  6. App management. Apps via VPP (Apple Volume Purchase Program) for App Store
  7. Patching: Managed Software Updates / DDM. Apple's modern patch model uses
  8. Compliance policy → Conditional Access.
  9. Operate.

What it can do on your machine

Read from SKILL.md and the folder at commit 15f16df. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • learn.microsoft.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

macOS Intune Baseline loads about 2.4k tokens when it runs. Until then it costs about 252 tokens; SKILL.md has 969 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~252
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from vinayaklatthe/microsoft-security-skills at commit 15f16df, republished under its MIT licence (© vinayaklatthe). 969 words, ~2,399 tokens.

Download SKILL.mdSave it as .claude/skills/macos-intune-baseline/SKILL.md (or your agent's skills folder).
name
macos-intune-baseline
description
Guidance for hardening macOS endpoints managed by Microsoft Intune — automated device enrollment via Apple Business Manager (ABM), platform single sign-on (PSSO) with Entra ID, FileVault disk encryption escrow, security configuration profiles (Gatekeeper, XProtect, system extensions allowlist, firewall, login window, Privacy Preferences Policy Control / PPPC), Microsoft Defender for Endpoint on macOS, app management (VPP / managed apps / shell scripts via Intune), patching strategy (managed software updates / DDM), Conditional Access compliance signal, and cross-platform identity model. WHEN: Mac Intune baseline, macOS hardening Intune, FileVault escrow, ABM Apple Business Manager, Platform SSO macOS, PSSO Entra, MDE on Mac, Gatekeeper Intune, system extensions Intune, PPPC Intune, macOS compliance Conditional Access. DO NOT USE for general Intune device management end-to-end (use intune-device-mgmt), MDE config alone (use defender-for-endpoint), or iOS device management.
license
MIT
metadata.author
Microsoft
metadata.version
0.1.0

macOS Hardening with Microsoft Intune

Mac fleets in Microsoft-shop enterprises are usually under-governed compared to Windows. Intune-managed macOS with the right configuration profiles, FileVault escrow, Defender for Endpoint, and Platform SSO with Entra ID closes most of the gap and gives you a Conditional Access compliance signal that actually means something.

When to use

Designing or hardening macOS endpoint management in an Intune + Entra ID environment (workforce devices, BYOD via user-enrollment is a separate model).

Do not use this skill for end-to-end Intune (intune-device-mgmt), MDE policy authoring (defender-for-endpoint), or iOS / iPadOS management.

Capability map

LayerTool / Profile
ProvisioningApple Business Manager + Intune Automated Device Enrollment
Identity / SSOPlatform SSO (Entra ID), Enterprise SSO plug-in
Disk encryptionFileVault enabled + escrow recovery key to Intune
App controlGatekeeper, XProtect (Apple-managed), notarized apps allowlist via system extensions
Endpoint protectionMicrosoft Defender for Endpoint on macOS
ConfigurationSettings catalog profiles (preferred), legacy templates where required
Privacy / kernelPrivacy Preferences Policy Control (PPPC), System Extensions, Notification Center policy
UpdatesManaged Software Updates / Declarative Device Management (DDM)
ComplianceIntune compliance policy → Conditional Access

Approach

  1. Enroll via ABM + Automated Device Enrollment. Manual enrollment is fine for pilots; production needs ABM so devices arrive supervised, can't be unenrolled by the user, and pick up policy at first boot.

  2. Platform SSO (PSSO) with Entra ID is the modern macOS SSO. User signs into the Mac with their Entra credentials (password, smart card, or passkey-style secure enclave). Replaces the older Enterprise SSO plug-in for sign-in scenarios. Requires deployment of the Microsoft Enterprise SSO plug-in package + a PSSO configuration profile.

  3. FileVault profile with escrow to Intune. Keys are recoverable by IT (with audit). Don't deploy FileVault without escrow — locked-out users brick devices.

  4. Defender for Endpoint on macOS via Intune app deployment + onboarding profile. Includes:

    • Real-time AV.
    • Network protection.
    • EDR.
    • Vulnerability assessment. Validate via mdatp health post-onboarding.
  5. Configuration profiles — start with the Microsoft macOS security baseline (or CIS macOS benchmark) and adapt. Critical settings:

    • Gatekeeper: Mac App Store + identified developers.
    • System extensions allowlist — required for Defender, your VPN, your DLP agent. Without explicit allowlist, users see prompts and may deny.
    • Privacy Preferences Policy Control (PPPC) — pre-approve required accessibility / full-disk-access for management tools (Defender, Intune management agent). Without this, MDE EDR coverage is partial.
    • Firewall on with stealth mode.
    • Screen lock + passcode complexity + password age aligned with policy.
    • Disable login as root, disable guest user, disable iCloud sync of passwords for managed devices (or scope by user group).
    • Block USB mass storage for restricted populations (Defender device control).
  6. App management. Apps via VPP (Apple Volume Purchase Program) for App Store apps; PKG/DMG for non-store apps via Intune; shell scripts for the long tail. Maintain an "approved apps" catalogue.

  7. Patching: Managed Software Updates / DDM. Apple's modern patch model uses Declarative Device Management — deferral windows, target OS versions, force-install deadlines. Replaces the older "deferral days" model. Roll out:

    • Major version: deferral 30 days, target n-1 supported.
    • Minor / security: deferral 7 days, target latest within supported.
  8. Compliance policy → Conditional Access.

    • FileVault on.
    • System integrity protection (SIP) enabled.
    • OS version ≥ supported floor.
    • Defender threat agent healthy + real-time protection on.
    • Encryption + screen lock conformant. Mark non-compliant devices and enforce via CA on M365 and Azure resources.
  9. Operate.

    • Defender for Endpoint device inventory + vulnerability management prioritization for Mac.
    • Quarterly review of system extensions and PPPC allowlist (apps come and go).
    • Monthly compliance trend.
Show full SKILL.md (406 more words)Show less

Guardrails

  • FileVault without escrow is a help-desk disaster. Escrow first, enforce later.
  • System extensions and PPPC allowlists must be deployed before the agents that need them. Otherwise users get prompts and click Deny — agents become ineffective.
  • Don't ship the Enterprise SSO plug-in and Platform SSO simultaneously without understanding the precedence. PSSO is the strategic direction; coexist carefully.
  • Don't mix CIS and Microsoft baselines without harmonization. Conflicting settings.
  • VPP apps require ABM linkage. Without ABM, you're stuck with user Apple IDs.
  • MDE coverage on Mac depends on accessibility + full-disk-access PPPC. Verify; otherwise EDR is partial.
  • Managed Software Updates needs supervised devices. User-enrolled BYOD has different capabilities.
  • Compliance grace periods of 14+ days defeat the model. Tighten as fleet matures.
  • Don't allow iCloud Drive personal accounts to sync corporate data. Restrict via policy or BYOD-grade user enrollment for those users.

Common anti-patterns

  • "FileVault rolled out, escrow on the to-do list" — users locked out, IT can't recover.
  • "Defender installed, no PPPC profile" — EDR sees user-mode events but not full-disk-access events.
  • "System extensions prompt the user; some users approved Defender, some didn't" — fragmented coverage. Allowlist via profile.
  • "Compliance check skipped OS version floor" — devices on 2-major-versions-back with unpatched CVEs marked compliant.
  • "Manual enrollment in production" — users can unenroll, policy isn't enforced.
  • "App store apps via personal Apple IDs" — license sprawl, no removal on offboard.
  • "Patching policy = trust users to update" — fleet drifts; CVE backlog grows.
  • "Conditional Access for Mac applied 'All users + All cloud apps'" — break-glass outage. Stage like Windows rollout.

Example prompts

  • Stand up macOS management for a 5,000-device creative workforce: ABM + Intune ADE + PSSO + FileVault escrow + MDE + baseline.
  • Build the system extensions and PPPC allowlist for Defender, our VPN, and our DLP agent.
  • Migrate from the older Enterprise SSO plug-in to Platform SSO with Entra ID password / Smart Card use case.
  • Compliance policy mapping macOS to Conditional Access for M365 and Azure portal.
  • Patching policy with Managed Software Updates / DDM for Sonoma → Sequoia cutover.
  • Compare Microsoft macOS baseline with CIS macOS benchmark and reconcile conflicts.
  • BYOD user-enrollment design vs corporate-owned ADE — capability and trade-off table.
  • MDE on Mac: confirm EDR coverage via PPPC, validate vulnerability assessment pipeline.

Microsoft Learn

© vinayaklatthe, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/macos-intune-baseline of vinayaklatthe/microsoft-security-skills.

Open the folder on GitHubat commit 15f16df

Compare with similar skills

macOS Intune Baseline next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

macOS Intune Baseline compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
macOS Intune Baseline this skillvinayaklatthe/microsoft-security-skills175—~2.4kAutomated safety check: PassMIT
Maui Authenticationdavidortinau/maui-skills175—~1.5kAutomated safety check: PassMIT
Web3authWeb3Auth/web3auth-examples144—~1.4kAutomated safety check: PassMIT
Stellar iOS Mac SDKSoneso/stellar-ios-mac-sdk132—~4.3kAutomated safety check: PassApache-2.0
Msal Client CredentialsAzureAD/microsoft-authentication-library-for-dotnet1.5k—~1.1kAutomated safety check: PassMIT
Azure APIM Policy Authoringthomast1906/github-copilot-agent-skills202—~1.5kAutomated safety check: PassMIT

Similar skills

  • Maui Authentication

    davidortinau/maui-skills

    Add authentication to .NET MAUI apps. An agent skill from davidortinau/maui-skills.

    175 GitHub stars~1.5k tokensUpdated 3 mo ago
    Backend & APIsAuto-check passed
  • Web3auth

    Web3Auth/web3auth-examples

    Integrates MetaMask Embedded Wallets (Web3Auth) for non-custodial wallets via social login or custom JWT (Firebase, Auth0, Cognito).

    144 GitHub stars~1.4k tokensUpdated 7 days ago
    Backend & APIsAuto-check passed
  • Stellar iOS Mac SDK

    Soneso/stellar-ios-mac-sdk

    Guides Stellar blockchain development in Swift using stellar-ios-mac-sdk.

    132 GitHub stars~4.3k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Msal Client Credentials

    AzureAD/microsoft-authentication-library-for-dotnet

    Client Credentials Flow for service-to-service (daemon) authentication in MSAL.NET without user involvement

    1.5k GitHub stars~1.1k tokensUpdated 3 days ago
    Backend & APIsAuto-check passed
  • Azure APIM Policy Authoring

    thomast1906/github-copilot-agent-skills

    Generates Azure API Management policy XML for authentication, rate limiting, CORS, error handling and transformations, consulting Azure best-practice and documentation tools first.

    202 GitHub stars~1.5k tokensUpdated 3 days ago
    Backend & APIsAuto-check passed

More from vinayaklatthe/microsoft-security-skills

All 50 skills in this repo
  • API Security Design

    vinayaklatthe/microsoft-security-skills

    Guidance for designing secure APIs on Azure - authentication, authorization, gateway controls, input validation, rate limiting, secret management, and runtime threat detection - aligned to OWASP API…

    175 GitHub stars~2.2k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure App Service Security

    vinayaklatthe/microsoft-security-skills

    Guidance for securing Azure App Service web apps and APIs — managed identity, Easy Auth with Microsoft Entra ID, network isolation via private endpoints + VNet integration, HTTPS / TLS hardening…

    175 GitHub stars~1.9k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Arc

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure Arc — projecting on-premises, multicloud (AWS/GCP), and edge servers, Kubernetes, and data services into Azure Resource Manager for unified governance, security, and management.

    175 GitHub stars~1.9k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Bastion Jit

    vinayaklatthe/microsoft-security-skills

    Guidance for secure remote VM management in Azure using Azure Bastion combined with Defender for Cloud just-in-time (JIT) VM access.

    175 GitHub stars~2.2k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Confidential Computing

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure Confidential Computing — protecting data in use through hardware-based Trusted Execution Environments (TEEs).

    175 GitHub stars~2.4k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Ddos Protection

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure DDoS Protection — Network Protection (per-VNet) and IP Protection (per public IP) tiers built on the same always-on Microsoft platform.

    175 GitHub stars~2k tokensUpdated 3 mo ago
    Auto-check passed

Categories

Questions about macOS Intune Baseline

What does macOS Intune Baseline do?

Guidance for hardening macOS endpoints managed by Microsoft Intune — automated device enrollment via Apple Business Manager (ABM), platform single sign-on (PSSO) with Entra ID, FileVault disk…. macOS Intune Baseline is an agent skill from vinayaklatthe/microsoft-security-skills.

When should I use macOS Intune Baseline?

macOS Intune Baseline fits situations like: general Intune device management end-to-end (use intune-device-mgmt); MDE config alone (use defender-for-endpoint); IOS device management.

How do I install macOS Intune Baseline in Claude Code?

Run `npx skills add vinayaklatthe/microsoft-security-skills --skill macos-intune-baseline -a claude-code`. Or copy the skill folder (skills/macos-intune-baseline in vinayaklatthe/microsoft-security-skills) into .claude/skills/macos-intune-baseline in your project. Claude Code loads it when a task matches its description.

How do I install macOS Intune Baseline in Codex?

Run `npx skills add vinayaklatthe/microsoft-security-skills --skill macos-intune-baseline -a codex`. Or copy the skill folder (skills/macos-intune-baseline in vinayaklatthe/microsoft-security-skills) into .agents/skills/macos-intune-baseline in your project. Codex loads it when a task matches its description.

Can I use macOS Intune Baseline in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vinayaklatthe/microsoft-security-skills --skill macos-intune-baseline -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/macos-intune-baseline, .gemini/skills/macos-intune-baseline, .github/skills/macos-intune-baseline and .opencode/skills/macos-intune-baseline in your project.

What does macOS Intune Baseline need to run?

SKILL.md names no scripts, command-line tools or credentials: macOS Intune Baseline is instructions for the agent only.

Does macOS Intune Baseline access the network?

SKILL.md names 1 domain. As links in the text: learn.microsoft.com. This is read from the text; nothing was executed.

Is macOS Intune Baseline safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does macOS Intune Baseline use?

macOS Intune Baseline is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does macOS Intune Baseline use?

About 2.4k tokens (SKILL.md is roughly 9.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to macOS Intune Baseline?

Skills that share tags, products or a category with macOS Intune Baseline: Maui Authentication (davidortinau/maui-skills, 175 stars), Web3auth (Web3Auth/web3auth-examples, 144 stars), Stellar iOS Mac SDK (Soneso/stellar-ios-mac-sdk, 132 stars) and Msal Client Credentials (AzureAD/microsoft-authentication-library-for-dotnet, 1.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains macOS Intune Baseline?

vinayaklatthe (a GitHub user) maintains it in vinayaklatthe/microsoft-security-skills, which has 175 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on June 18, 2026.

Source: vinayaklatthe/microsoft-security-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.