Configuring Simplified Setup for Platform SSO in Jamf School

Jamf School Documentation

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

The Simplified Setup for Platform Single Sign-on (Platform SSO) feature streamlines the device enrollment process by enabling authentication and account creation directly within Setup Assistant. This workflow allows for Platform SSO to be enforced through Setup Assistant during Automated Device Enrollment, requiring registration with an identity provider (IdP) and the ability for macOS to create a user account based on the user's information from the IdP.

After a computer has enrolled with Jamf School, it will be kept in Setup Assistant until a specified Platform SSO app and its associated profiles are installed. When the configuration is complete, macOS will begin a required Platform SSO registration process on the next screen a user sees during setup. After registration, the first user is created during Setup Assistant, based on the identity of the user that authenticated with the IdP. After a user registers with the IdP, Platform SSO applications can be configured to simplify user authentication to enterprise applications.

Important:See your IdP's documentation for their Platform SSO feature capabilities and proper configuration settings with MDM, as well as compatibility with this workflow in macOS 26. If a computer enters Platform SSO registration mode during Setup Assistant and cannot complete, the computer will remain in Setup Assistant and may need to be erased and reset. If a computer cannot complete Setup Assistant when testing these workflows with macOS 26 and computers with Apple silicon, Jamf recommends using the Erase Device command to reset the computer. Because macOS 26 escrows a bootstrap token to Jamf School at the time the MDM profile installs, the computer will perform an Erase All Contents and Settings action when it requests the bootstrap token during the erase process.
Requirements
  1. In Jamf School, navigate to Profiles > Overview in the sidebar.
  2. Click the name of the profile that you configured during your initial Platform SSO setup.
  3. In the list of payloads on the left side of the pane, locate the macOS payload category and click the App Extension SSO payload.
  4. Select the Enable Registration During Setup checkbox.
  5. (Optional) To use Platform SSO to create the first user account on a computer during Setup Assistant, do the following:
    1. Select the Enable Create First User During Setup checkbox.
    2. (Optional) In the New User Authentication Methods section, select the checkbox for each authentication method to use for accounts created with Platform SSO at login or during Setup Assistant.
      Note:

      If no authentication methods are selected, the system will use the Password and Smart Card authentication methods.

  6. Click Save.
  7. Add the profile that you configured during your initial Platform SSO setup to an Automated Device Enrollment profile by doing the following:
    1. Navigate to Profiles > Automated Device Enrollment Profiles in the sidebar.
    2. Click the name of the Automated Device Enrollment profile that you want to add the Platform SSO profile to.
    3. Click the Profiles and packages tab.
    4. In the Profiles section, click + Add.
    5. Choose the Platform SSO profile from the pop-up menu.
    6. Click Save.

Simplified Setup for Platform SSO is configured and applies to subsequently enrolled computers that the Automated Device Enrollment profile is assigned to.