This guide configures Microsoft Entra ID Platform SSO for macOS with the Secure Enclave key method, which Microsoft recommends. The Secure Enclave key method is phishing resistant and lets the Platform SSO credential act as a passkey for Entra ID sign-in.
Choose an Authentication Method
| Method | Use when | Notes |
|---|---|---|
| Secure Enclave key | 1:1 Macs, phishing-resistant and passwordless goals | Microsoft recommends. Does not sync the Entra ID password to the local account. |
| Password | You need the local password to match Entra ID, or you need login and FileVault policies | Not phishing resistant. A local password policy stricter than Entra ID breaks sync. |
| Smart card | You use PIV or CAC credentials | macOS 14 or later. Users cannot register in Setup Assistant. |
Changing the authentication method or the Use Shared Device Keys setting after deployment forces every Mac to register again. Decide before you deploy.
Requirements
- Microsoft Entra ID tenant
- Mac with Apple silicon and macOS 14 or later (macOS 26 or later for Simplified Setup)
- Jamf Pro 11.20 or later for Simplified Setup, and 11.26 or later for automatic Entra ID registration with Simplified Setup
- Microsoft Company Portal 5.2404.0 or later (5.2604.0 or later for Simplified Setup), deployed before you scope the Platform SSO profile
- Jamf Pro and Microsoft Entra ID device compliance integration, if you use conditional access
Step 1: Deploy Company Portal
- In Jamf Pro, go to Computers > Mac Apps, and click New.
- Select Jamf App Catalog, search for
Company Portal, and add it. - Scope the app to your target computers, enable deployment, and click Save.
Company Portal contains the Microsoft Enterprise SSO extension. Install it before the Platform SSO profile arrives so that registration starts without errors.
Step 2: Create the Platform SSO Configuration Profile
- Go to Computers > Configuration Profiles, and click New.
- Enter a name, description, and category. Set Level to
Computer Leveland Distribution Method toInstall Automatically. - Select the Single Sign-On Extensions payload, and click Add.
- Configure the following settings:
| Setting | Value |
|---|---|
| Payload Type | SSO |
| Extension Identifier | com.microsoft.CompanyPortalMac.ssoextension |
| Team Identifier | UBF8T346G9 |
| Sign-on Type | Redirect |
| URLs | https://login.microsoftonline.comhttps://login.microsoft.comhttps://sts.windows.net |
| Screen Locked Behavior | Do Not Handle |
| Use Platform SSO | Included |
| Authentication Method | User Secure Enclave Key |
| Use Shared Device Keys | Enabled |
| Account Display Name | Your organization name, such as Contoso Entra ID |
| Token To User Mapping: Account Name | com.apple.PlatformSSO.AccountShortName or preferred_username |
| Token To User Mapping: Full Name | name |
Add the sovereign cloud URLs only if your tenant uses them: https://login.partner.microsoftonline.cn, https://login.chinacloudapi.cn, https://login.microsoftonline.us, and https://login-us.microsoftonline.com.
- Scope the profile, and click Save.
The Associated Domains payload is not required for Microsoft Entra ID.
Optional Settings
- Enable Create User At Login: Creates local accounts at the login window for Entra ID users on shared Macs. Requires shared device keys.
- Kerberos TGT: Company Portal 2508 or later can retrieve on-premises and cloud Kerberos ticket-granting tickets. Pair it with a Kerberos SSO extension profile that sets
usePlatformSSOTGTtotrue. - Touch ID for the Secure Enclave key: Set
enable_se_key_biometric_policytotruein the extension data (Company Portal 2504 or later, macOS 14.6 or later). Enabling this after users register forces every user to register again.
Microsoft Entra ID does not send group claims to the Platform SSO extension, so the Administrator Groups and Authorization Groups settings do not grant rights from Entra ID groups. Use Self Service+ privilege elevation instead.
Step 3: Configure Simplified Setup (macOS 26 or Later)
- Edit the Platform SSO profile, and enable Enable Registration During Setup.
- If you use the password method, also enable Create First User During Setup.
- Go to Computers > PreStage Enrollments, and create or edit a PreStage enrollment.
- Under Enrollment Requirements, select Enable Simplified Setup for Platform Single Sign-on (macOS 26 or later).
- Set Set workflow method to
Identity firstorDevice first. See Simplified Setup: Identity First and Device First. - Set Minimum required macOS version to
26.0or later. - Include the Platform SSO profile in Configuration Profiles.
- For device first, set Platform Single Sign-on App Bundle ID to
com.microsoft.CompanyPortalMac, and include a Company Portal package (5.2604.0 or later) in Enrollment Packages. For identity first, Jamf Pro delivers Company Portal before enrollment. - Click Save.
For first account creation, use the Password new user authentication method. Do not enforce per-user MFA in Entra ID. Require MFA with Conditional Access instead.
With Jamf Pro 11.26 or later and the Entra ID device compliance integration, Jamf Pro registers the Mac with Entra ID automatically, so users do not act on a separate registration notification.
Step 4: Register an Existing Mac
On Macs that enrolled before you deployed Platform SSO, users register from the notification. Do not ask users to open Company Portal and sign in, because Company Portal can start a Microsoft Intune enrollment instead of Platform SSO registration.
- The user clicks Registration Required in Notification Center.
- The user enters the local account password.
- The user signs in to Entra ID and completes MFA.
- The user confirms registration. With the password method, macOS prompts for the Entra ID password if it differs from the local password.
Step 5: Enable the Passkey (Optional)
With the Secure Enclave key method, users can use the Platform SSO credential as a passkey in browsers.
- On the Mac, open the password options in System Settings. Microsoft documents the path as Passwords > Password Options. On recent macOS versions, the setting is under General > AutoFill & Passwords.
- Under Use passwords and passkeys from, turn on Company Portal.
If your Entra ID passkey policy restricts authenticators by AAGUID, add 7FD635B3-2EF9-4542-8D9D-164F2C771EFC.
Verify the Deployment
- Run
app-sso platform -sin Terminal. Confirm that the device and user registration states show as registered. - Open System Settings > Users & Groups, and confirm that Network Account Server shows Entra ID.
- In the Microsoft Entra admin center, confirm that the device appears under Devices > All devices.
Troubleshooting
The extension does not start after a macOS update
Run sudo killall swcd and then sudo swcutil reset, and restart the Mac.
Registration fails behind a proxy
Exclude app-site-association.cdn-apple.com, app-site-association.networking.apple, and the Entra ID sign-in URLs from TLS inspection. Platform SSO does not work with tenant restrictions v2 enforced through a proxy.
Users register again unexpectedly
Update to macOS 15.3 or later. macOS 15.0 through 15.2 contained a defect that corrupted the device configuration. Also confirm that the authentication method and shared device keys settings did not change.
Users must register again after a password reset
A password reset through FileVault recovery or MDM resets the Secure Enclave keys. Ask the user to register again from Notification Center.
For more help, see Troubleshooting Platform SSO and Troubleshoot the macOS Platform SSO extension (Microsoft).
Resources
- macOS Platform Single Sign-On overview (Microsoft)
- Integrate macOS Platform SSO into your MDM solution (Microsoft)
- Join a Mac with Platform SSO (Microsoft)
- Microsoft Enterprise SSO plug-in for Apple devices (Microsoft)
- Deploying macOS Platform SSO for Microsoft Entra ID with Jamf Pro (Jamf)
- Device Compliance and Platform SSO with Microsoft and Jamf (Jamf blog)
- Attested Device Compliance for Microsoft Entra (Jamf Concepts)
Demo Video
Platform SSO Registration with Secure Enclave and Microsoft Entra ID