Jamf Concepts

Guías

Jamf Connect and Platform SSO

~4 min read
¿Te resultó útil?

Platform SSO and Jamf Connect overlap more with each macOS release. Both can create local accounts from IdP identities and keep the local password in sync with the IdP. They still differ in IdP coverage, MFA at the login window, and the workflows around the login.

This comparison covers the Jamf Connect login and password sync functions. It does not cover Jamf Connect zero-trust network access (ZTNA).

Feature Comparison

Capability Platform SSO Jamf Connect
Supported IdPs IdPs with a Platform SSO extension, such as Microsoft Entra ID, Okta, and Ping Identity Microsoft Entra ID, Okta, Google, IBM Security Verify, OneLogin, PingFederate, RapidIdentity, and custom OpenID Connect IdPs
Account creation in Setup Assistant Yes, with Simplified Setup (macOS 26 or later) Yes, after Setup Assistant
Account creation at the login window Yes (macOS 14 or later) Yes
Local password sync with the IdP Yes, with the password method Yes
Phishing-resistant, passwordless sign-in Yes, with Secure Enclave key or smart card No
SSO to apps after login Yes, through the IdP extension No (use the IdP extension)
MFA at the login window macOS 27 web sign-in, or Touch ID requirement Yes, including offline MFA
Migration of existing local accounts Registration links the existing account Yes, with account migration settings
Privilege elevation Administrator rights from IdP groups, when the IdP sends group claims (Microsoft Entra ID does not) Yes, through Self Service+
Kerberos Yes, with IdP-issued TGTs Yes, through Self Service+
Login window branding Limited Yes
Shared Mac features Authenticated Guest Mode and Tap to Login (macOS 26 or later) Account creation for each user
Changing IdPs Requires a new extension and registration Supported

The Jamf Connect menu bar app was deprecated in Jamf Connect 3.0.0. Password sync, privilege elevation, and Kerberos now run in Self Service+ 2.0.0 or later.

Which Should You Use?

Use Platform SSO when your IdP supports it, your Macs run Apple silicon, and you want phishing-resistant sign-in, Simplified Setup, or SSO to apps from the same credential.

Use Jamf Connect when your IdP has no Platform SSO extension, you need MFA at the login window on macOS versions earlier than 27, you need offline MFA, or you plan to change IdPs.

Do Not Combine Login and Password Sync

Do not run Jamf Connect login or password sync on a Mac that uses Platform SSO, in any authentication mode. This includes pairing Jamf Connect password sync with the Microsoft Entra ID extension in Secure Enclave key mode. Apple and Microsoft do not support this configuration, and it causes Platform SSO to lose its registration and FileVault password mismatches.

On a Mac that uses Platform SSO:

  • Use Self Service+ for privilege elevation, and do not configure an IdP in Jamf Connect. When an IdP is configured, Jamf Connect attempts to sync the password.
  • Use Jamf Connect 3.6.0 or later if any Jamf Connect component remains. In this version, authchanger -reset recognizes the Microsoft Platform SSO configuration and does not break it.
  • Jamf Connect ZTNA is not affected and can run alongside Platform SSO.

Moving From Jamf Connect to Platform SSO

Use an opt-in group so each Mac moves from Jamf Connect to Platform SSO in one step.

  1. Inventory the Macs, macOS versions, and IdPs in your environment. Platform SSO requires Apple silicon for most features.
  2. Decide which features Jamf Connect provides today that you still need, such as offline MFA or privilege elevation.
  3. Create a static or smart computer group for migrating Macs.
  4. Exclude the group from the Jamf Connect login and password sync configuration profiles, and scope the IdP extension and the Platform SSO profile to the group.
  5. Run authchanger -reset on migrating Macs to restore the macOS login window, if your Jamf Connect removal process does not already do this.
  6. Have users register from the Registration Required notification. Existing local accounts link to the IdP identity.
  7. Confirm registration with app-sso platform -s, and confirm that no orphaned local accounts remain.
  8. Expand the group in phases, and use Simplified Setup for new Macs.

Existing local accounts do not become MDM-enabled users through migration. If you need user-channel management for the IdP user, erase the Mac and enroll it again with Simplified Setup.

Resources

¿Te resultó útil?