Jamf Concepts

Guías

Platform SSO FAQ

~6 min read
¿Te resultó útil?

Simplified Setup

Which Simplified Setup workflow should I use?

Jamf Pro offers two workflow methods. Identity first (Jamf Pro 11.29 or later, formerly called attended) installs the IdP app and Platform SSO profile before enrollment, so the user registers with the IdP before enrollment completes. It does not support enrollment customizations or dynamic SCEP challenges. Device first (Jamf Pro 11.20 or later, formerly called unattended) enrolls the Mac first and then holds Setup Assistant at registration. It requires the IdP app in the PreStage enrollment packages. Use Jamf Pro 11.32.1 or later for either. See Simplified Setup: Identity First and Device First.

What happened to attended and unattended?

Jamf renamed them. Attended is now identity first, and unattended is now device first. The workflows are the same.

Can I use Simplified Setup with Jamf Setup Manager or one-touch staging?

Yes, with limits. To stage a Mac and shut it down for the user to finish setup, do not create a managed local administrator account in the PreStage enrollment. Otherwise, macOS creates that account first and Platform SSO cannot create the first user. After the user completes setup, run an inventory update or a login policy so that Jamf Pro records the username.

Can I change Simplified Setup settings after a Mac enrolls?

No. macOS applies Simplified Setup settings in Setup Assistant only. To apply changes, erase the Mac and enroll it again.

Jamf Connect

Can I keep Jamf Connect password sync and add Platform SSO in Secure Enclave key mode?

No. Do not run Jamf Connect login or password sync on a Mac that uses Platform SSO, in any authentication mode. Apple and Microsoft do not support the combination, and it causes lost registrations and FileVault password mismatches. See Jamf Connect and Platform SSO.

Can I still use Jamf Connect for privilege elevation?

Yes. Use Self Service+ for privilege elevation, and do not configure an IdP in Jamf Connect.

Do migrated users become MDM-enabled users?

No. Existing local accounts link to the IdP identity when they register, but they do not become MDM-enabled users. To get user-channel management, erase the Mac and enroll it again with Simplified Setup.

Registration

Why do users have to register again?

Changes to the Platform SSO payload can trigger registration again. Changes to the authentication method or the Use Shared Device Keys setting always do. Batch profile changes, avoid redeploying the profile, and test changes on a pilot group. Password resets through FileVault recovery or MDM also reset Secure Enclave keys.

How do I trigger registration again?

Have the user open System Settings > Users & Groups, click Edit next to Network Account Server, and click Repair. The Microsoft Entra ID extension also prompts again periodically until registration completes.

Should users open Company Portal to register?

No. Users register from the Registration Required notification. Signing in to Company Portal can start a Microsoft Intune enrollment instead of Platform SSO registration.

Passwords and Login

Why does a temporary IdP password fail at the login window?

Platform SSO cannot sync a temporary password. Have the user sign in to the IdP from a browser on another device, set a permanent password, and then sign in to the Mac.

Should I set login policies to Attempt or Require?

Use Attempt Authentication unless every Mac can reach the IdP at the login window. Require Authentication blocks sign-in when the Mac is offline or when the network needs a VPN, Jamf network relay, or 802.1X. For recovery steps, see Troubleshooting Platform SSO.

What is the "PIN" that Microsoft Entra ID asks for?

In Secure Enclave key mode, the Entra ID "PIN" prompt refers to the local account password, or Touch ID when you enable the biometric policy. It is not a separate PIN.

What does FileVault still require?

FileVault unlock uses the local account password. Passkeys are not available at FileVault unlock. With the password method, the local password matches the IdP password after sync.

Can users sign in with a FIDO2 security key or passkey at the login window?

Only on macOS 27 with web sign-in, and only when your IdP supports it. Check your IdP's roadmap.

Shared Macs

How do I configure Authenticated Guest Mode?

Authenticated Guest Mode requires macOS 26 or later and these settings in the Single Sign-On Extensions payload:

Setting Value
Authentication Method Password
Use Shared Device Keys Enabled
Enable Create User At Login Enabled
New User Authorization Mode Temporary
Quick login for temporary session (TemporarySessionQuickLogin) Optional. Removes only selected folders after each session and removes the full home folder every 8 hours.

The Mac also needs a bootstrap token, a local administrator created in Setup Assistant, FileVault unlocked, and network access at the login window. MFA is not available at the login window before macOS 27. Confirm support with your IdP. Jamf does not yet publish an Okta guide for Authenticated Guest Mode.

Which IdPs support Tap to Login?

As of October 2026, no major IdP ships Tap to Login. Support depends on the IdP's SSO extension. Check with your IdP.

Identity Providers

Can Platform SSO grant administrator rights from Microsoft Entra ID groups?

No. Microsoft Entra ID does not send group claims to the Platform SSO extension. Use Self Service+ privilege elevation.

Does Google Workspace support Platform SSO?

No. Google does not provide a Platform SSO extension. Use Jamf Connect, or evaluate third-party options such as XPSSO from Twocanoes.

Does Okta support Secure Enclave keys?

Yes. Okta added Secure Enclave key authentication in May 2026. It requires Device-Bound SSO and the Secure Enclave feature enabled in your Okta org. See Configure Platform SSO with a Secure Enclave key (Okta).

Do I need one Okta SCEP certificate or two?

Platform SSO requires only the Okta Device Access SCEP certificate. The Okta endpoint management certificate supports Okta device assurance policies. Many organizations deploy both.

Does Ping Identity support Platform SSO?

Yes. Ping released Platform SSO in July 2026 for PingOne and PingFederate. It requires a PingOne for Workforce license and PingID desktop 2.0 or later.

¿Te resultó útil?