Configuring Simplified Setup for Platform Single Sign-On

Jamf Pro Documentation 11.30.0

Solution
Application
Content Type
Technical Documentation
Utilities & Services
version
11.30.0
ft:locale
en-US
vrm_version
11.30.0

Simplified Setup for Platform Single Sign-On (Platform SSO) streamlines device enrollment by enabling Platform SSO registration and account creation directly within Setup Assistant during Automated Device Enrollment. Two workflow configurations are available: attended, in which the Platform SSO profile installs before enrollment; and unattended, in which the Platform SSO profile installs during enrollment. The attended workflow requires a Platform SSO configuration profile selected in the PreStage enrollment and SAML-based SSO configured for end users in Jamf Pro.

When a computer attempts to enroll with Jamf Pro using the attended workflow, Jamf Pro returns a 403 response that rejects the enrollment until the computer completes Platform SSO registration. The 403 response includes secured download links for the Platform SSO configuration profile and the Platform SSO app package, which macOS downloads and installs automatically. After the profile and package are installed, the computer prompts the user to register with Platform SSO before the computer can attempt to enroll with Jamf Pro again. Once the user completes Platform SSO registration, the computer sends an authentication token to Jamf Pro, which verifies it against the server's SAML SSO integration and authorizes enrollment. After enrollment completes, account creation and Setup Assistant screens continue as configured in the PreStage enrollment settings.

When a computer enrolls with Jamf Pro using the unattended workflow, Jamf Pro keeps the computer in Setup Assistant until the Platform SSO app and its associated configuration profiles are installed. When installation is complete, macOS begins a required Platform SSO registration process on the next screen the user sees during setup. After the user registers with the IdP, the first user account is created in Setup Assistant based on the authenticated identity. After enrollment completes, account creation and Setup Assistant screens continue as configured in the PreStage enrollment settings.

Jamf recommends first validating your Platform SSO configuration profile using the unattended workflow, which enforces Platform SSO registration after enrollment. This allows you to use a device erase command to reset and retest if an error occurs.

Important:

See your IdP’s documentation for their Platform SSO feature capabilities and proper configuration settings with MDM, as well as compatibility with this workflow in macOS 26. If a computer enters Platform SSO registration mode during Setup Assistant and cannot complete, the computer remains in Setup Assistant and may require an erase and reset. If a computer cannot complete Setup Assistant when testing these workflows with macOS 26 and computers with Apple silicon, Jamf recommends using the Wipe Computer command to reset the computer. Because macOS 26 escrows a bootstrap token to Jamf Pro at the time the MDM profile installs, the computer will perform an Erase All Contents and Settings action when it requests the bootstrap token during the erase process.

Full functionality requires compatible implementation from supported identity providers (Okta and Microsoft Entra ID). Verify support status with your IdP to ensure full feature availability.

Note:

For technical details on how Simplified Setup for Platform SSO works, see Enrolling with Platform Single Sign-On from the Apple Developer documentation.

Requirements
  • You must have Platform SSO configured in your environment with a supported IdP. For more information, see the Platform Single Sign-on for macOS with Jamf Pro article.
  • Computers with macOS 26 or later (macOS 26.4 if using the attended workflow with Okta as an IdP)
  1. Create or edit a PreStage enrollment. For instructions, see Creating or Editing a Computer PreStage Enrollment.
  2. In the General payload, select the Enable Simplified Setup for Platform Single Sign-on checkbox.
  3. Use the Set workflow method pop-up menu to select the method used for the Platform SSO workflow:
    • Attended (SSOe profile installs before enrollment)The Platform SSO application and profile are installed prior to enrollment, and successful user registration is required to enroll with Jamf Pro.
      Note:

      Enrollment customizations cannot be used with the attended workflow method.

    • Unattended (SSOe profile installs during enrollment)Enrollment with Jamf Pro completes, then the computer is held in Setup Assistant to register with Platform SSO before setup completes.
  4. Depending on the workflow method you selected, complete the applicable configuration:
    • If you selected Attended:
      1. From the Select configuration profile pop-up menu, choose a macOS configuration profile with an SSOe payload.
      2. In the Package manifest URL field, enter the URL for the manifest document that defines the installation package.
    • If you selected Unattended, enter the bundle ID for one of the supported authentication apps in the Platform Single Sign-on App Bundle ID field.
    Note:

    Okta Verify and the Microsoft Company Portal app are currently supported.

  5. In the Configuration profiles payload, select the configuration profiles that you configured during your initial Platform SSO setup.
    Important:

    There are specific settings that must be enabled in the Single Sign-on Extensions profile for this workflow to function properly. For more information, see the Platform Single Sign-on for macOS with Jamf Pro article.

  6. In the Enrollment packages payload, click Add and add a PKG that includes the authentication app that corresponds to your IdP.
  7. Click the Scope tab and do one of the following:
    • Select each device that you want to enroll via Automated Device Enrollment using settings in the PreStage enrollment.

    • Click Select All to add all devices associated with the Automated Device Enrollment instance, regardless of any results that have been filtered using the Filter Results, to the PreStage enrollment.

  8. Click Save .

Simplified Setup for Platform SSO is configured and applies to subsequently enrolled computers in the chosen PreStage enrollment.