1
Prerequisites
Confirm the following before proceeding:
- Microsoft Intune admin center access — Intune Administrator or equivalent role with permission to create configuration profiles, upload apps, and assign deployments.
- An Apple MDM Push Certificate active in Intune (Devices → Enrollment → Apple → Apple MDM push certificate). Without this, no macOS device can be managed.
- A valid Origin provisioning JWT — obtain from the Origin console under Settings → Provisioning Tokens.
- The Origin macOS installer — download from the Origin console under Settings → Installers. Delivered as
Origin.pkg. - The PPPC configuration profile and install scripts from the deployment package (see Step 3).
- Target macOS devices enrolled in Intune with User-Approved MDM (UAMDM). Devices enrolled via Company Portal or Apple Automated Device Enrollment satisfy this.
- An Entra ID security group containing your target devices — used during assignment in Step 5.
- A pilot device dedicated to validating the deployment chain end-to-end before broader rollout. The first device to receive a PKG app deployment in any tenant is at higher risk of agent-startup timing issues — see the IME warmup substep in Step 5.
The installer and the provisioning token live in two different Settings views — Installers for the
.pkg, Provisioning Tokens for the JWT. Tokens carry an expiry and a use limit, so confirm both cover your rollout before you begin.Deployment package download: drive.google.com/drive/folders/1r3PYJdVMgnTVjzyJqzKvys8rTFqWsKKF2
Scope of automation
Two macOS permissions stand between the installer and a fully registered agent. MDM pre-approves both — no user interaction is required for either.
Deploying the PPPC profile before the package installs ensures the agent registers silently without any user-facing prompts.
3
Files
Download from drive.google.com/drive/folders/1r3PYJdVMgnTVjzyJqzKvys8rTFqWsKKF. All files can be used as-is — no per-tenant customization is needed.Identifiers
The bundle may also contain a proxy root CA template, a system-extensions policy, and a VPN/transparent-proxy profile from Origin’s earlier proxy-based capture architecture. Do not deploy these — they are no longer required.
4
Deployment order
The configuration profile must land on the endpoint before the
.pkg installs — otherwise the agent hits permission prompts during registration and the silent-install chain breaks.- Privacy preferences (PPPC) (
origin-privacy.mobileconfig) — Grants Full Disk Access and Endpoint Security based on Team IDD3C73MWD7Yand bundle IDcom.origin.agent. Eliminates TCC prompts on first run. - JWT staging shell script (
intune-stage-jwt-origin.sh) — Stages the provisioning JWT to/var/tmp/origin-provisioning-jwtvia a standalone shell script policy at Devices → Scripts and remediations. Must show Succeeded on a target device before that device is added to the macOS app (PKG) assignment. Idempotent — safe to re-run. - The Origin
.pkg(Origin.pkg) — Deployed as a macOS app (PKG) with no pre-install script. The postinstall reads the JWT staged in step 2 and registers silently.
5
Intune walkthrough
The whole flow happens inside the Microsoft Intune admin center at On the device, verify the JWT was actually staged:
intune.microsoft.com.01. Upload the configuration profile
The.mobileconfig must be uploaded as a Custom configuration profile. Do not use Intune’s built-in PPPC template — it reconstructs the XML and breaks the code requirement that makes PPPC allow-listing work.Where to uploadIntune admin center → Devices → By platform → macOS → Configuration → Create → New Policy. Set Profile type to Templates, then choose Custom. This is the only profile type that ingests a raw
.mobileconfig without rewriting it.- Intune admin center → Devices → By platform → macOS → Configuration.
- Click + Create → New Policy.
- Set Profile type to Templates, select Custom, click Create.
- Basics: name the profile (e.g.
Origin — Privacy Preferences (PPPC)) and click Next. - Configuration settings:
- Custom configuration profile name: a friendly name shown on the device (e.g.
Origin Privacy Preferences). - Deployment channel: Device channel — required. The user channel will not allow the PPPC payload to take effect.
- Configuration profile file: upload
origin-privacy.mobileconfig.
- Custom configuration profile name: a friendly name shown on the device (e.g.
- Click Next.
- Assignments: add your Entra ID device group under Included groups. Click Next.
- Review + create → Create.
02. Verify Intune Management Agent reporting (warmup)
Before deploying the JWT staging script or the Origin.pkg, deploy a benign warmup script to confirm the Intune Management Agent (IME) is installed on your target devices and that result-reporting is healthy. The first PKG- or script-type assignment to a fresh tenant or device triggers the IME install, and the agent-startup window is the source of most “phantom failure” reports. Burning that timing budget on a no-op script is much cheaper than burning it on the JWT staging script and ending up with a cached failure to clean up.Why this step existsThe IME on macOS has two halves: a system-context daemon (
IntuneMdmDaemon) and a user-context agent (IntuneMdmAgent). Scripts execute via the daemon, but result-reporting back to the Intune service goes through the agent. On a fresh enrollment the daemon comes up first; the agent only starts after a user signs into Company Portal. If a real assignment fires during that gap, the script can succeed on disk while reporting as failed in the admin center — and the cached failure is sticky. The warmup script’s only job is to absorb that timing window with a no-op so subsequent real deployments report cleanly.- Intune admin center → Devices → Scripts and remediations → Platform scripts tab → + Add → macOS.
- Basics: Name
Origin — IME Warmup. Click Next. - Script settings: upload or paste the warmup script (below). Settings:
- Run script as signed-in user: No (run as root).
- Hide script notifications on devices: Yes.
- Script frequency: Not configured (run once).
- Max number of times to retry if script fails: 3.
- Assignments: add your Entra ID device group. Click Next.
- Review + add → Add.
- Force a sync from Company Portal on your pilot device. Wait for the script’s status to show Succeeded in Devices → Scripts and remediations → Origin — IME Warmup → Device status.
- Do not proceed to Substep 03 until status shows Succeeded. A Failed warmup means the IME isn’t healthy on this device — diagnose before continuing (see Step 7).
03. Deploy the JWT staging shell script
This script stages the provisioning JWT to/var/tmp/origin-provisioning-jwt so the Origin .pkg postinstall can read it silently. It is deployed as its own shell script policy — not as a pre-install script attached to the macOS PKG app.- Intune admin center → Devices → Scripts and remediations → Platform scripts tab → + Add → macOS.
- Basics: Name
Origin — Stage Provisioning JWT. Click Next. - Script settings: paste the script below, replacing the empty
JWT=""value with your provisioning token from Settings → Provisioning Tokens. Settings:- Run script as signed-in user: No (run as root).
- Hide script notifications on devices: Yes.
- Script frequency: Not configured (run once).
- Max number of times to retry if script fails: 3.
- Assignments: add your Entra ID device group. Click Next.
- Review + add → Add.
- Force a sync from Company Portal on your pilot device. Wait for status to show Succeeded.
sudo ls -la /var/tmp/origin-provisioning-jwt should show a 0600-mode file owned by root:wheel with content. Until this is confirmed, do not proceed to Substep 04.Why the token lives in the script bodyIntune doesn’t expose script parameters for macOS shell scripts the way it does for Windows Win32 apps — the script body is the only place to put the JWT. Any Intune admin with read permission on this script policy can see it. Scope admin permissions accordingly.
04. Add the Origin package as a macOS PKG app
The Origin.pkg is deployed using Intune’s macOS app (PKG) deployment type, with no pre-install or post-install script — JWT staging was handled in Substep 03. The postinstall reads the staged JWT directly when the package installs.Intune Management Agent prerequisiteThe macOS app (PKG) deployment type requires the Microsoft Intune Management Agent (version 2309.007 or greater) on the endpoint. The IME should already be present from Substep 02. If it isn’t, that’s a sign Substep 02 didn’t actually succeed — diagnose before continuing.
05. Configure requirements, detection, and assignment
- Intune admin center → Apps → All apps → + Create.
- Under Other, select macOS app (PKG), then click Select.
- App information → Select app package file: upload
Origin.pkg. Intune reads bundle ID and version from the package metadata. - Confirm the auto-populated values, fill in Publisher and any optional fields. Click Next.
- Program: leave both Pre-install script and Post-install script blank. This is critical — adding a pre-install script reintroduces the failure modes documented in Step 7.
- Set Ignore app version to No so Intune respects the version in the package metadata for upgrade decisions.
- Click Next to continue to Requirements.
Detection rules
Assignments
Review the values and click Create.
06. Trigger the install
Once a device is in scope for the macOS PKG app (with all upstream items already Succeeded), the install runs automatically on the next device check-in. To force it for testing:- From the Mac: open Company Portal → Devices → select the device → ⋯ → Check status. This forces an immediate sync.
- From the admin center: Devices → All devices → select the target device → Sync.
- From Terminal on the Mac (forces a profile check-in only — does not directly trigger app install):
sudo profiles renew -type enrollment
/var/tmp/origin-provisioning-jwt → Intune Management Agent installs the .pkg → the postinstall reads the staged JWT, registers silently, and deletes the file. No user interaction is required at any step.6
Verification
Run these on a target endpoint after the install completes.Profile installedShould return the Origin Privacy Preferences profile.Agent process runningReturns a PID when the agent is running.Review agent logJWT staging script logShould show a successful run with Confirms the package installed cleanly. Look for
JWT staged successfully (NNN bytes). or one of the idempotency no-op messages.Intune Management Agent logApp install succeeded for the Origin policy ID. If you see Cached app policy result matches repeatedly without resolution, see Step 7.Origin menu bar icon
Once the agent is running, the Origin menu bar icon appears. Click it to confirm the agent is active and to access two operator-friendly checks without dropping to Terminal:- Generate diagnostic report — bundles agent state, recent logs, and registration status into a single file you can hand to Origin support.
- View logs — opens the local log directory directly.
Origin console verificationIn the Origin console, go to Settings → Endpoint Inventory and search for the target hostname. A successfully registered endpoint appears with a recent last-seen time and its detected AI agents populated.
Intune admin center verificationDevices → All devices → select the target Mac → Managed Apps. The Origin app should show install status Installed. Under Device configuration, the Origin profile should show Succeeded.
7
Troubleshooting
Profile shows “Error” or “Conflict” in Intune
Check the per-device status in Devices → All devices → [device] → Device configuration → [profile name] → Per-setting status. The most common causes:- Profile uploaded with the wrong template type — if you used Intune’s built-in PPPC template instead of Templates → Custom, the XML was rebuilt and the code requirement no longer matches Origin’s signature. Delete the profile and re-create it as a Custom profile uploading the raw
.mobileconfig. - User channel selected instead of Device channel — the PPPC payload is device-scoped and silently no-ops when delivered through the user channel. Recreate the profile with Deployment channel: Device channel.
- Profile stuck in “Pending” — force a sync from Company Portal on the device, or use Sync in the admin center.
Full Disk Access not granted despite profile
- The PPPC profile’s code requirement matches Developer ID signed builds with Team ID
D3C73MWD7Y. Ad-hoc signed or internal development builds won’t match and Full Disk Access will not pre-grant. - Confirm the profile was uploaded as a Custom template — the built-in PPPC template will silently strip the code requirement.
JWT staging script reports “Failed” but the JWT file exists
- Verify the file exists with content:
sudo ls -la /var/tmp/origin-provisioning-jwt. A0600-mode file owned byroot:wheelwith non-zero size means the script succeeded — Intune is misreporting. - Check the script’s own log:
sudo cat /Library/Logs/Origin/intune-stage-jwt.log. If it showsJWT staged successfullyandexit 0, the script worked. - Recovery: if the JWT is staged correctly, simply assign the macOS PKG app to the device — the postinstall will consume the JWT regardless of what Intune thinks of the script’s status.
- If you need Intune to report success, toggle the script’s group assignment off, wait 5 minutes, then re-assign. This forces a fresh evaluation. The script’s idempotency check returns 0 cleanly.
PKG app reports “Pre-install script did not complete successfully (0X87D3014A)”
The macOS PKG app was configured with a pre-install script — which this guide explicitly avoids. Open the app in Apps → All apps → Origin app → Properties → Edit and confirm both Pre-install script and Post-install script fields are blank. If they aren’t, blank them, save, and re-sync.Cached failure persists across multiple sync attempts
Intune’s macOS app retry logic has a documented weakness: when theIntuneMDMDaemon’s cached policy result matches a prior failure (visible as Cached app policy result matches the current policy result in IntuneMDMDaemon*.log), it stops retrying meaningfully. Recovery options in order of preference:- Toggle the assignment. Apps → All apps → Origin → Properties → Assignments → remove the group → Save. Wait 5 minutes, force a sync from Company Portal, then re-add the assignment. Intune treats this as a brand-new policy and clears the cached result.
- Retire and re-enroll. If the assignment toggle doesn’t break the cache, retire the device from the admin center, manually clean
/Library/Intune/and/Library/Logs/Microsoft/Intune/, delete the device record from Intune, then re-enroll fresh via Company Portal. This is the only fully-clean reset for a poisoned policy state.
Warmup script fails on first deployment
The Intune Management Agent isn’t healthy on this device. Checkls /Library/Intune/ — if empty or missing the agent app bundle, force a sync and wait 5–10 minutes for the agent to install.App stays in “Pending” forever in Company Portal
- Confirm the device’s primary user has an Intune license assigned in M365 Admin Center. Without the license, agent installation requests get silently dropped.
- Check that the device hasn’t been added to a conflicting assignment that excludes it from the script policy.
- This is a known Intune cosmetic bug — Company Portal can show Pending even after the app has successfully installed. Verify with
pgrep -x originon the endpoint and the install status in the admin center, both of which are authoritative.