> ## Documentation Index
> Fetch the complete documentation index at: https://docs.iru.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Getting Started with Microsoft Device Compliance

> Get started with the Microsoft Device Compliance integration in Iru Endpoint. Connect Intune, configure compliance policies, and validate device posture.

<Callout icon="list-check" color="#B84A7A" iconType="regular">This guide applies to Mac computers, iOS devices, and iPadOS devices</Callout>

### About Microsoft Device Compliance

Iru Endpoint's Microsoft Device Compliance (MSDC) integration combines Iru Endpoint's device management and compliance features with Microsoft's conditional access capabilities, ensuring only managed and compliant devices can access corporate resources.

### How It Works

Iru Endpoint's Microsoft Device Compliance (MSDC) integration combines Iru Endpoint's device management and compliance features with Microsoft's conditional access capabilities. Built through [Microsoft's device compliance partner program](https://learn.microsoft.com/en-us/mem/intune/protect/device-compliance-partners), this integration simplifies the setup and configuration process between Iru Endpoint and Microsoft and streamlines the deployment of required applications through the Iru Endpoint Library. Once configured and devices are registered with Microsoft, Iru Endpoint's device inventory and compliance data can be used in Microsoft Conditional Access policies. This ensures that only managed and compliant devices can access corporate resources. Iru Endpoint's MSDC integration supports macOS, iOS, and iPadOS devices.

### Prerequisites

#### All Devices

* Devices must be managed by Iru Endpoint
* A [Microsoft user directory integration](/en/endpoint/integrations/directory-services/user-directory-integration) must be set up in your Iru Endpoint tenant
* A user from the configured directory integration [must be assigned to the device record](/en/endpoint/devices/device-record-management/assigning-and-unassigning-users-to-devices)
* Device users must be assigned an Enterprise Mobility + Security license, which includes Microsoft Entra ID Premium and [Microsoft Intune](https://learn.microsoft.com/en-us/mem/intune/fundamentals/licenses)
* A Microsoft user account that can accept requested app permissions
* Iru Endpoint must be configured as a device compliance partner in Intune

### Configuration Overview

Below are the basic steps required to set up and deploy Microsoft Device Compliance with Iru Endpoint.

<Steps>
  <Step title="Configure Iru Endpoint as Device Compliance Partner">
    [Configure Iru Endpoint as a device compliance partner in Intune.](/en/endpoint/integrations/microsoft-device-compliance/microsoft-device-compliance-adding-iru-endpoint-as-a-device-compliance-partner-in-intune)
  </Step>

  <Step title="Set Up MSDC Integration">
    [Set up the MSDC integration in Iru Endpoint](/en/endpoint/integrations/microsoft-device-compliance/microsoft-device-compliance-integration-configuration).
  </Step>

  <Step title="Deploy Applications">
    Deploy Applications for end user device registration.

    * **macOS**

      * Configure the [Microsoft Company Portal Auto App Library Item](/en/endpoint/integrations/microsoft-device-compliance/microsoft-device-compliance-library-item-configuration)
    * **iOS and iPadOS**

      * The [Iru Self Service](/en/endpoint/settings/self-service/self-service-for-ios-ipados-and-visionos) app must be deployed using Apps and Books
      * The Microsoft Authenticator app from the Apple App Store must be [assigned to Iru Endpoint via Apps and Books](/en/endpoint/settings/apple-integrations/add-apps-from-apps-and-books-to-iru-endpoint) in Apple Business or Apple School Manager
      * Configure the [Microsoft Authenticator Apps and Books Library Item](/en/endpoint/integrations/microsoft-device-compliance/microsoft-device-compliance-library-item-configuration)
  </Step>

  <Step title="Deploy Single Sign-on Profiles">
    Deploy Single Sign-on Profiles.

    * **macOS**

      * If you use [Platform SSO with Microsoft Entra ID](/en/endpoint/library/library-items-profiles/configure-the-platform-sso-with-microsoft-entra-id-library-item), please make sure this is deployed first, and have the user register with Platform SSO before registering with Microsoft Device Compliance.
      * If you do not use Platform SSO with Microsoft Entra ID, deploy [Microsoft Single Sign-on Extension macOS settings](https://learn.microsoft.com/en-us/mem/intune/configuration/use-enterprise-sso-plug-in-macos-with-intune?tabs=prereq-other-mdm%2Ccreate-profile-other-mdm#create-a-single-sign-on-app-extension-configuration-policy) in the [Single Sign-On Extension Library Item](/en/endpoint/library/library-items-profiles/configure-the-single-sign-on-extension-library-item).

        * Inside the Library Item, set the **Installs On** field to only include Mac
    * **iOS & iPadOS**

      * Deploy [Microsoft Single Sign-on Extension iOS and iPadOS settings](https://learn.microsoft.com/en-us/intune/intune-service/configuration/use-enterprise-sso-plug-in-ios-ipados-with-intune?tabs=prereq-intune%2Ccreate-profile-other-mdm#create-a-single-sign-on-app-extension-configuration-policy) in the [Single Sign-On Extension Library Item](/en/endpoint/library/library-items-profiles/configure-the-single-sign-on-extension-library-item).
      * Inside the Library Item, set the **Installs On** field to only include iOS and iPadOS.
  </Step>
</Steps>

<Note>
  The Microsoft Single Sign-on Extension only needs to be deployed if it is not already deployed in your environment for the device platforms you have configured.
</Note>
