Securing internet traffic from devices with identity-aware web filtering and threat protection
The Global Secure Access (GSA) client on macOS doesn’t require Microsoft Intune specifically, but it does require that the Mac is:
- Registered to Microsoft Entra through a Company Portal app, and
- Managed by an MDM that deploys the required system extension and transparent application proxy approvals.
In the current setup, the device state shows as Unregistered, so the ZTNA Policy Service Client sign-in is blocked.
To use Addigy instead of Intune:
- Ensure the Mac is Entra-registered
- Install the Company Portal app for macOS on the device.
- Sign in with the user’s Microsoft Entra account so the device is registered to the tenant.
- Confirm registration in Entra (device appears as a registered device).
- Deploy the GSA client with Addigy
- Download
GlobalSecureAccessClient.pkgfrom the Microsoft Entra admin center (Global Secure Access > Connect > Client download > macOS). - Use Addigy to deploy this
.pkgto the macOS devices.
- Download
- Approve system extensions via Addigy MDM
- In Addigy, create a configuration profile for macOS that allows the GSA system extensions.
- Under the System Extensions payload, add the following allowed extensions:
- Bundle identifier:
com.microsoft.globalsecureaccess.tunnel, Team identifier:UBF8T346G9 - Bundle identifier:
com.microsoft.globalsecureaccess, Team identifier:UBF8T346G9
- Bundle identifier:
- Assign this profile to the target Macs.
- Allow the transparent application proxy
- Create a custom configuration profile in Addigy that mirrors the Intune “Custom” profile used to allow the transparent application proxy for GSA.
- Deploy this profile to the same devices.
- (Optional but recommended) Deploy Microsoft Enterprise SSO plug-in
- Use Addigy to deploy the Microsoft Enterprise SSO plug-in for Apple devices and ensure the Company Portal app is installed.
- This enables SSO so the user can sign in to GSA using the same Entra credentials without repeated prompts.
- Retry sign-in
- After the profiles and client are deployed and the device is registered, restart the Mac.
- Launch the Global Secure Access client and sign in again. The device state should now be recognized, and sign-in should succeed.
If Addigy doesn’t yet have the required system extension and proxy approvals in place, the client will continue to show the device as unregistered and block sign-in, even though the GSA app is installed.
References: