The macOS counterpart of the Intune Management Extension. It is installed silently at /Library/Intune/Microsoft Intune Agent.app once a device is assigned a shell script, app or custom attribute, and never appears in Applications.
Two processes write logs. IntuneMDMDaemon runs as root and handles PKG and DMG installs and scripts run as root; IntuneMDMAgent runs as the signed-in user and handles scripts run as that user.
Each log line has six pipe-delimited columns: timestamp, process, thread, level, component and message.
The user folder is reported absent on some macOS 15 devices even when they are enrolled and managed.
Where Intune MDM Agent keeps its logs
Intune MDM Agent logs to /Library/Logs/Microsoft/Intune/ on macOS. 1 other macOS log location is recorded below. These paths were verified for pkg installs - a different installer, or a portable copy, can put them somewhere else.
Paths are printed exactly as Intune MDM Agent writes them. Environment variables like %LOCALAPPDATA% and $XDG_STATE_HOME are never expanded, so a path can be pasted straight into a shell. Where a path differs between installer types or shipping flavours, each one is racked as its own card below - why that happens.
In the Intune admin center, go to Devices > macOS, select the device and choose Collect diagnostics. The agent uploads both log folders, plus any file paths the admin lists.
On the device, copy /Library/Logs/Microsoft/Intune/ and ~/Library/Logs/Microsoft/Intune/. The newest IntuneMDMDaemon file updates in real time during a sync, so force one from Company Portal > Settings > Sync first.
For the Company Portal side of the story, open Company Portal, choose Help > Save diagnostic report; the zip holds CompanyPortal.log.