# macOS

## Configuration steps <a href="#before-creating-the-wi-fi-profile-create-a-trusted-root-certificate-profile-as-described-here-change" id="before-creating-the-wi-fi-profile-create-a-trusted-root-certificate-profile-as-described-here-change"></a>

1. Log in to [Microsoft Intune](https://intune.microsoft.com/)
2. Navigate to **Devices** and subsequently **Configuration profiles**
3. Then click **Create > New policy**
4. As **Platform** select **macOS**
5. Search the **Profile type** templates for **Wired network** and select it
6. Click **Create** and provide a descriptive name and optional **Description**
7. Choose your **Network Interface**
8. As **EAP type** choose **EAP - TLS**
9. Next, as **Certificate server names** add the **Subject Alternative Name (SAN)** of your *active* RADIUS [**Server Certificate.**](https://docs.radiusaas.com/admin-portal/settings/settings-server#server-certificates) This property can be found by expanding the active server certificate and copying the relevant values.

<figure><img src="https://1222554226-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FSWU1DQ4UGkqER7uGNUOm%2Fuploads%2F0n7K2XAYF0K4yK14zShb%2Fimage.png?alt=media&#x26;token=f0f7936a-f177-4514-9d8e-01056bbc0a71" alt=""><figcaption></figcaption></figure>

1. For the **Root certificates for server validation** select the Trusted certificate profile you have previously created for the RADIUS Server Certificate.
2. Finally, under **Client Authentication** select **Certificates as** **Authentication method**&#x20;

<figure><img src="https://1222554226-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FSWU1DQ4UGkqER7uGNUOm%2Fuploads%2F9qYLZwPkTb0pP04ZssJn%2Fimage.png?alt=media&#x26;token=abe0334e-0d3a-4e4f-920a-25f2416abf83" alt=""><figcaption><p>Showing wired network profile for macOS</p></figcaption></figure>
