Body
⚠️ Before You Begin
Please ensure the following prerequisites are met before starting this guide:
- The Mac is properly assigned to the correct MDM enrollment server in Apple School Manager
- In Intune, the Mac is placed in the correct profile under that enrollment server
Step 1: Initial Setup & Device Enrollment
When you first power on your new Mac, you will be greeted by the setup screen. Follow the on-screen prompts to configure your language and any accessibility features you may require.
You will then arrive at the Device Management screen, which will display a message indicating that your Mac is owned by Case Western Reserve University.

Click Enroll to proceed.
The device will cycle through the following messages:
- Retrieving enrollment profile...
- Deploying managed profiles...
Once completed, you will be guided through a few additional setup screens.
Step 2: Creating Your Account
You will be prompted to create a local account. Please follow the standard naming convention used for Case accounts (e.g., abc123).
Note: The password you set here is temporary. Later in this guide, we will configure Platform SSO, which will automatically sync your password with CWRU's system.

Step 3: Remaining Setup Prompts
You will be asked to configure the following settings. Follow the on-screen prompts for each:
- 📍 Enable Location Services
- 🤖 Set Up Apple Intelligence
- 🔔 Summarize Notifications
- 🎙️ Siri Setup
- 🗣️ Siri Voice
- 📝 Improve Siri & Dictation
- 🖥️ Screen Appearance
Once complete, you will be greeted by the Welcome Screen. Click OK to proceed to your desktop.

Step 4: Software Deployment
Upon reaching the desktop, you may notice notifications indicating that programs are being deployed to your machine. This is expected behavior as Intune pushes managed applications and configurations to the device.
⏱️ This process takes approximately 15 minutes. If you are a technician setting up multiple machines, use this time to begin the setup process on other devices.
The following applications will be automatically installed:
| Application |
Reason |
| Microsoft Defender |
Required by Information Security |
| Qualys Agent |
Required by Information Security |
| Microsoft Office |
Standard CWRU Program |
| Google Chrome |
Standard CWRU Program |
| Zoom |
Standard CWRU Program |
| Company Portal |
Required for Intune & Platform SSO |
Step 5: Registering with Platform SSO
After approximately 15 minutes, a pop-up notification will appear in the upper right-hand corner of your screen for Platform SSO. This is used to register your macOS device with Microsoft Entra, enabling you and other users to log in using their Case ID.

Click Register to proceed.
<PICTURE>
Step 6: Completing the Platform SSO Registration
A new screen titled "Single Sign-On for Mac" will appear. Review the description if you wish, then click Continue.

You will first be prompted to enter the local macOS account password you created earlier.

Next, you will be prompted to sign in to Microsoft Entra. Enter your CWRU email address and password. If prompted to set up Multi-Factor Authentication (MFA), please complete that process.

The device will begin registering your connection. A final macOS prompt will appear requesting your credentials:
- Username: Your CWRU email address (e.g., abc123@case.edu)
- Password: Your CWRU email passphrase

Once entered, you will see the confirmation message: "Registration Complete."
Step 7: Enabling FileVault Disk Encryption
When you log out for the first time, you will be prompted to enter your password to enable FileVault. Please enter your credentials when prompted.

Upon logging back in, you will receive another prompt to enable FileVault. Click Enable to encrypt your disk.
🔒 FileVault encryption is an important security measure and cannot not be skipped.
✅ Setup Complete
Your shared Apple device is now fully configured. Other users can now log in to this computer using their CWRU credentials.
If you counter any issues during setup, please contact Endpoint Management for assistance.