Simplified Setup for Platform Single Sign-On (Platform SSO) streamlines device enrollment by enabling Platform SSO registration and account creation directly within Setup Assistant during Automated Device Enrollment. Two workflow configurations are available: attended, in which the Platform SSO profile installs before enrollment; and unattended, in which the Platform SSO profile installs during enrollment. The attended workflow requires a Platform SSO configuration profile selected in the PreStage enrollment and SAML-based SSO configured for end users in Jamf Pro.
When a computer attempts to enroll with Jamf Pro using the attended workflow, Jamf Pro returns a 403 response that rejects the enrollment until the computer completes Platform SSO registration. The 403 response includes secured download links for the Platform SSO configuration profile and the Platform SSO app package, which macOS downloads and installs automatically. After the profile and package are installed, the computer prompts the user to register with Platform SSO before the computer can attempt to enroll with Jamf Pro again. Once the user completes Platform SSO registration, the computer sends an authentication token to Jamf Pro, which verifies it against the server's SAML SSO integration and authorizes enrollment. After enrollment completes, account creation and Setup Assistant screens continue as configured in the PreStage enrollment settings.
When a computer enrolls with Jamf Pro using the unattended workflow, Jamf Pro keeps the computer in Setup Assistant until the Platform SSO app and its associated configuration profiles are installed. When installation is complete, macOS begins a required Platform SSO registration process on the next screen the user sees during setup. After the user registers with the IdP, the first user account is created in Setup Assistant based on the authenticated identity. After enrollment completes, account creation and Setup Assistant screens continue as configured in the PreStage enrollment settings.
Jamf recommends first validating your Platform SSO configuration profile using the unattended workflow, which enforces Platform SSO registration after enrollment. This allows you to use a device erase command to reset and retest if an error occurs.
See your IdP’s documentation for their Platform SSO feature capabilities and proper configuration settings with MDM, as well as compatibility with this workflow in macOS 26. If a computer enters Platform SSO registration mode during Setup Assistant and cannot complete, the computer remains in Setup Assistant and may require an erase and reset. If a computer cannot complete Setup Assistant when testing these workflows with macOS 26 and computers with Apple silicon, Jamf recommends using the Wipe Computer command to reset the computer. Because macOS 26 escrows a bootstrap token to Jamf Pro at the time the MDM profile installs, the computer will perform an Erase All Contents and Settings action when it requests the bootstrap token during the erase process.
Full functionality requires compatible implementation from supported identity providers (Okta and Microsoft Entra ID). Verify support status with your IdP to ensure full feature availability.
For technical details on how Simplified Setup for Platform SSO works, see Enrolling with Platform Single Sign-On from the Apple Developer documentation.
- You must have Platform SSO configured in your environment with a supported IdP. For more information, see the Platform Single Sign-on for macOS with Jamf Pro article.
- Computers with macOS 26 or later (macOS 26.4 if using the attended workflow with Okta as an IdP)
Simplified Setup for Platform SSO is configured and applies to subsequently enrolled computers in the chosen PreStage enrollment.