Jamf Concepts
Handleidingen

Handleidingen

Configure Platform SSO with Jamf Pro and Microsoft Entra ID

~7 min read
Was dit nuttig?

This guide configures Microsoft Entra ID Platform SSO for macOS with the Secure Enclave key method, which Microsoft recommends. The Secure Enclave key method is phishing resistant and lets the Platform SSO credential act as a passkey for Entra ID sign-in.

Choose an Authentication Method

Method Use when Notes
Secure Enclave key 1:1 Macs, phishing-resistant and passwordless goals Microsoft recommends. Does not sync the Entra ID password to the local account.
Password You need the local password to match Entra ID, or you need login and FileVault policies Not phishing resistant. A local password policy stricter than Entra ID breaks sync.
Smart card You use PIV or CAC credentials macOS 14 or later. Users cannot register in Setup Assistant.

Changing the authentication method or the Use Shared Device Keys setting after deployment forces every Mac to register again. Decide before you deploy.

Requirements

  • Microsoft Entra ID tenant
  • Mac with Apple silicon and macOS 14 or later (macOS 26 or later for Simplified Setup)
  • Jamf Pro 11.20 or later for Simplified Setup, and 11.26 or later for automatic Entra ID registration with Simplified Setup
  • Microsoft Company Portal 5.2404.0 or later (5.2604.0 or later for Simplified Setup), deployed before you scope the Platform SSO profile
  • Jamf Pro and Microsoft Entra ID device compliance integration, if you use conditional access

Step 1: Deploy Company Portal

  1. In Jamf Pro, go to Computers > Mac Apps, and click New.
  2. Select Jamf App Catalog, search for Company Portal, and add it.
  3. Scope the app to your target computers, enable deployment, and click Save.

Company Portal contains the Microsoft Enterprise SSO extension. Install it before the Platform SSO profile arrives so that registration starts without errors.

Step 2: Create the Platform SSO Configuration Profile

  1. Go to Computers > Configuration Profiles, and click New.
  2. Enter a name, description, and category. Set Level to Computer Level and Distribution Method to Install Automatically.
  3. Select the Single Sign-On Extensions payload, and click Add.
  4. Configure the following settings:
Setting Value
Payload Type SSO
Extension Identifier com.microsoft.CompanyPortalMac.ssoextension
Team Identifier UBF8T346G9
Sign-on Type Redirect
URLs https://login.microsoftonline.com
https://login.microsoft.com
https://sts.windows.net
Screen Locked Behavior Do Not Handle
Use Platform SSO Included
Authentication Method User Secure Enclave Key
Use Shared Device Keys Enabled
Account Display Name Your organization name, such as Contoso Entra ID
Token To User Mapping: Account Name com.apple.PlatformSSO.AccountShortName or preferred_username
Token To User Mapping: Full Name name

Add the sovereign cloud URLs only if your tenant uses them: https://login.partner.microsoftonline.cn, https://login.chinacloudapi.cn, https://login.microsoftonline.us, and https://login-us.microsoftonline.com.

  1. Scope the profile, and click Save.

The Associated Domains payload is not required for Microsoft Entra ID.

Optional Settings

  • Enable Create User At Login: Creates local accounts at the login window for Entra ID users on shared Macs. Requires shared device keys.
  • Kerberos TGT: Company Portal 2508 or later can retrieve on-premises and cloud Kerberos ticket-granting tickets. Pair it with a Kerberos SSO extension profile that sets usePlatformSSOTGT to true.
  • Touch ID for the Secure Enclave key: Set enable_se_key_biometric_policy to true in the extension data (Company Portal 2504 or later, macOS 14.6 or later). Enabling this after users register forces every user to register again.

Microsoft Entra ID does not send group claims to the Platform SSO extension, so the Administrator Groups and Authorization Groups settings do not grant rights from Entra ID groups. Use Self Service+ privilege elevation instead.

Step 3: Configure Simplified Setup (macOS 26 or Later)

  1. Edit the Platform SSO profile, and enable Enable Registration During Setup.
  2. If you use the password method, also enable Create First User During Setup.
  3. Go to Computers > PreStage Enrollments, and create or edit a PreStage enrollment.
  4. Under Enrollment Requirements, select Enable Simplified Setup for Platform Single Sign-on (macOS 26 or later).
  5. Set Set workflow method to Identity first or Device first. See Simplified Setup: Identity First and Device First.
  6. Set Minimum required macOS version to 26.0 or later.
  7. Include the Platform SSO profile in Configuration Profiles.
  8. For device first, set Platform Single Sign-on App Bundle ID to com.microsoft.CompanyPortalMac, and include a Company Portal package (5.2604.0 or later) in Enrollment Packages. For identity first, Jamf Pro delivers Company Portal before enrollment.
  9. Click Save.

For first account creation, use the Password new user authentication method. Do not enforce per-user MFA in Entra ID. Require MFA with Conditional Access instead.

With Jamf Pro 11.26 or later and the Entra ID device compliance integration, Jamf Pro registers the Mac with Entra ID automatically, so users do not act on a separate registration notification.

Step 4: Register an Existing Mac

On Macs that enrolled before you deployed Platform SSO, users register from the notification. Do not ask users to open Company Portal and sign in, because Company Portal can start a Microsoft Intune enrollment instead of Platform SSO registration.

  1. The user clicks Registration Required in Notification Center.
  2. The user enters the local account password.
  3. The user signs in to Entra ID and completes MFA.
  4. The user confirms registration. With the password method, macOS prompts for the Entra ID password if it differs from the local password.

Step 5: Enable the Passkey (Optional)

With the Secure Enclave key method, users can use the Platform SSO credential as a passkey in browsers.

  1. On the Mac, open the password options in System Settings. Microsoft documents the path as Passwords > Password Options. On recent macOS versions, the setting is under General > AutoFill & Passwords.
  2. Under Use passwords and passkeys from, turn on Company Portal.

If your Entra ID passkey policy restricts authenticators by AAGUID, add 7FD635B3-2EF9-4542-8D9D-164F2C771EFC.

Verify the Deployment

  1. Run app-sso platform -s in Terminal. Confirm that the device and user registration states show as registered.
  2. Open System Settings > Users & Groups, and confirm that Network Account Server shows Entra ID.
  3. In the Microsoft Entra admin center, confirm that the device appears under Devices > All devices.

Troubleshooting

The extension does not start after a macOS update

Run sudo killall swcd and then sudo swcutil reset, and restart the Mac.

Registration fails behind a proxy

Exclude app-site-association.cdn-apple.com, app-site-association.networking.apple, and the Entra ID sign-in URLs from TLS inspection. Platform SSO does not work with tenant restrictions v2 enforced through a proxy.

Users register again unexpectedly

Update to macOS 15.3 or later. macOS 15.0 through 15.2 contained a defect that corrupted the device configuration. Also confirm that the authentication method and shared device keys settings did not change.

Users must register again after a password reset

A password reset through FileVault recovery or MDM resets the Secure Enclave keys. Ask the user to register again from Notification Center.

For more help, see Troubleshooting Platform SSO and Troubleshoot the macOS Platform SSO extension (Microsoft).

Resources

Demo Video

Platform SSO Registration with Secure Enclave and Microsoft Entra ID

Was dit nuttig?