Jamf Concepts
Guides

Guides

Troubleshooting Platform SSO

~5 min read
Cela vous a-t-il été utile ?

Check Registration Status

Run the following command as the signed-in user:

app-sso platform -s

The output shows the device configuration, the user configuration, and the state of the device and user registration. Confirm that both registrations completed and that the extension identifier matches your IdP.

You can also check status in System Settings > Users & Groups. Select the user to repair the user registration, or click Edit next to Network Account Server and click Repair to repair the device registration.

The Jamf Concepts PSSO Utility shows the same information from the menu bar on macOS 26 or later.

Collect Logs

Stream Platform SSO logs:

log stream --level debug --predicate 'subsystem == "com.apple.AppSSO"'

Show only high-level requests and results:

log stream --level debug --predicate 'subsystem == "com.apple.AppSSO" AND category == "PODiagnostics"'

Persist debug logs, reproduce the issue, and capture a sysdiagnose:

sudo log config --mode "level:debug,persist:debug" --subsystem "com.apple.AppSSO"
sudo sysdiagnose
sudo log config --reset --subsystem "com.apple.AppSSO"

To capture a sysdiagnose in Setup Assistant, press Control-Option-Command-Shift-Period. macOS saves the file in /private/var/tmp.

Common Errors

Symptom Cause Resolution
"The single sign-on extension could not validate the domain" macOS cannot validate the extension's associated domain For Okta and Ping, confirm the Associated Domains payload and Team ID prefix. For all IdPs, exclude app-site-association.cdn-apple.com and app-site-association.networking.apple from TLS inspection.
"SSO application missing" in Setup Assistant The IdP app installed after the profile Click retry. Confirm that the PreStage enrollment includes the IdP app package and the correct bundle ID.
409 "Ambiguous SSO provider" with the identity first workflow A defect in Jamf Pro 11.29 through 11.32 Update to Jamf Pro 11.32.1 or later.
Registration never starts The profile requests an authentication method that the IdP does not support Change the authentication method to one your IdP supports.
Unexpected registration prompts A defect in macOS 15.0 through 15.2, or a change to the authentication method or shared device keys Update to macOS 15.3 or later. Do not change these settings after deployment.
Password sync fails The local password policy is stricter than the IdP policy, or the user has a temporary IdP password Align the local password policy with the IdP. Have the user set a permanent IdP password.
Secure Enclave registration lost after a password reset FileVault or MDM password recovery resets the Secure Enclave keys Have the user register again from Notification Center.
Changes to the profile have no effect in Setup Assistant macOS applies Simplified Setup settings only at enrollment Erase the Mac and enroll again.

Recover From a Login Policy Lockout

When a login or FileVault policy requires IdP authentication and the Mac cannot reach the IdP:

  1. At the FileVault unlock screen, press Option-Shift-Return, and enter the personal recovery key.
  2. If that fails, start up in macOS Recovery and run:
security platformsso bypass-login-policy

This command requires the personal recovery key and, if set, the Recovery Lock password. It removes the IdP requirement for 12 hours or until the next successful IdP authentication.

Before you require IdP authentication at login, confirm that the Mac can reach the IdP before the user signs in. VPN, Jamf network relay, and 802.1X connections are not available at the login window.

Known Issues in macOS 27

Issue Workaround
macOS 27 rejects duplicate Single Sign-On Extensions payloads for the same extension, and Platform SSO stops working Make sure only one configuration profile in scope contains the Platform SSO payload for each extension. Remove duplicate payloads, and then repair registration.
Okta password method fails to authenticate again with "Failed to update keybag password" Restart the Mac and sign in again. Apple reportedly fixes this in a later macOS 27 update. Test each update before you deploy it.
Users are locked out at the Lock Screen after sleep Review the Platform SSO known issues in the macOS 27 release notes, and use Attempt Authentication for the unlock policy until Apple releases a fix.
Okta SCEP certificates fail with the identity first workflow method Use device first with dynamic SCEP until Jamf and Okta resolve the issue.
The macOS 27 Touch ID policy keys are not available in the Jamf Pro payload Confirm that your Jamf Pro version supports them. If it does not, deploy the keys with a custom configuration profile after you test it.

Known issues change with each release. Check the Jamf Pro release notes and Apple's macOS release notes before you upgrade.

Known Limitations

  • Each domain can use only one SSO extension. If you also deploy the Kerberos SSO extension, set syncLocalPassword to false.
  • Login policies require the password method. The Secure Enclave key method supports only the Touch ID policies.
  • Authenticated Guest Mode and account creation at login do not support the Secure Enclave key method.
  • Passkeys are not available at FileVault unlock.
  • The macOS 27 web sign-in allow list does not accept wildcards.
  • Removing the MDM profile unregisters the Mac from the IdP.

Resources

Cela vous a-t-il été utile ?