Skip to main content

Configuring Entra ID for Platform SSO for macOS with Jamf School

This document outlines the minimum steps to configure Microsoft Entra ID Platform SSO for macOS in Jamf School using the App Extension SSO payload.

Updated today

Description

When integrated with Microsoft Entra ID, Platform Single Sign-on for macOS (Platform SSO) allows end users to authenticate to their computers using a smart card, their Microsoft Entra ID credentials, or with a secure enclave key.

When using secure enclave as the authentication method, a secure, hardware-bound, non-phishable authentication factor used by Microsoft Entra ID to access organization resources. In this "Secure Enclave key" mode, the local account credentials are unchanged and knowledge of the local account password fulfills the need for multiple factors for conditional access policies.

This article provides steps for a minimum viable configuration of Platform SSO on devices running macOS 14 or later.

Notes

  • This article assumes that creating new users at the login window is desired functionality.

  • This configuration can only be deployed to devices after the Microsoft Company Portal application has been installed.

  • A this time, Entra ID does not support Apple’s Simplified Setup process that handles first time registration during Setup Assistant.

Configuring the Profile

  1. In Jamf School navigate to Profiles > Overview.

  2. Click on the + Create Profile button in the upper right.

  3. Select macOS as the platform.

  4. Select Device Enrollment as the enrollment type and click Next.

  5. Enter a name and description for the profile and click Next.

  6. Click Finish to create the profile.

  7. In the list of payloads on the left click on the App Extension SSO payload.

  8. Scroll up to the top of the page and click the Configure button to populate the available settings.

  9. Adjust the following settings:

  10. Click the Save to save the changes to the configuration profile.

Deployment Notes

  • Once configuration is complete this profile can be deployed to devices where the Microsoft Company Portal application is already installed.

  • For best results deploy this configuration with a smart group that finds devices that already have the application installed. This will prevent the profile being deployed to devices that do not meet the prerequisite.

Did this answer your question?