Configuring Simplified Setup for Platform Single Sign-On

Jamf Pro Documentation 11.23.0

Solution
Application
Content Type
Technical Documentation
Utilities & Services
version
11.23.0
ft:locale
en-US
vrm_version
11.23.0

The Simplified Setup for Platform Single Sign-on (Platform SSO) feature streamlines the device enrollment process by enabling authentication and account creation directly within Setup Assistant. This workflow allows for Platform SSO to be enforced through Setup Assistant during Automated Device Enrollment, requiring registration with an identity provider (IdP) and the ability for macOS to create a user account based on the user’s information from the IdP.

After a computer has enrolled with Jamf Pro, it will be kept in Setup Assistant until a specified Platform SSO app and its associated configuration profiles are installed. When the configuration is complete, macOS will begin a required Platform SSO registration process on the next screen a user sees during setup. After registration, the first user is created during Setup Assistant, based on the identity of the user that authenticated with the IdP. After a user registers with the IdP, Platform SSO applications can be configured to simplify user authentication to enterprise applications.

Important:

See your IdP’s documentation for their Platform SSO feature capabilities and proper configuration settings with MDM, as well as compatibility with this workflow in macOS 26. If a computer enters Platform SSO registration mode during Setup Assistant and cannot complete, the computer will remain in Setup Assistant and may need to be erased and reset. If a computer cannot complete Setup Assistant when testing these workflows with macOS 26 and computers with Apple silicon, Jamf recommends using the Wipe Computer command to reset the computer. Because macOS 26 escrows a bootstrap token to Jamf Pro at the time the MDM profile installs, the computer will perform an Erase All Contents and Settings action when it requests the bootstrap token during the erase process.

Full functionality requires compatible implementation from supported identity providers (Okta and Microsoft Entra ID). Verify support status with your IdP to ensure full feature availability.

Requirements
  1. On the PreStage Enrollments page, do one of the following:
    • Click New to create a new PreStage enrollment.

    • Select an existing PreStage enrollment and click Edit .

  2. In the General pane, select the Enable Simplified Setup for Platform Single Sign-on checkbox.
  3. In the Platform Single Sign-on App Bundle ID field, enter the bundle ID for one of the supported authentication apps that corresponds to your chosen IdP:
    • Microsoft Entra IDcom.microsoft.CompanyPortalMac
    • Oktacom.okta.mobile
  4. In the Configuration Profiles pane, select the configuration profiles that you configured during your initial Platform SSO setup.
    Important:

    There are specific settings that must be enabled in the Single Sign-on Extensions profile for this workflow to function properly. For more information, see the Platform Single Sign-on for macOS with Jamf Pro article.

  5. In the Enrollment Packages pane, click Add and add a PKG that includes the authentication app that corresponds to your IdP.
  6. Click the Scope tab and do one of the following:
    • Select each device that you want to enroll via Automated Device Enrollment using settings in the PreStage enrollment.

    • Click Select All to add all devices associated with the Automated Device Enrollment instance, regardless of any results that have been filtered using the Filter Results, to the PreStage enrollment.

  7. Click Save .

Simplified Setup for Platform SSO is configured and applies to subsequently enrolled computers in the chosen PreStage enrollment.