The Simplified Setup for Platform Single Sign-on (Platform SSO) feature streamlines the device enrollment process by enabling authentication and account creation directly within Setup Assistant. This workflow allows for Platform SSO to be enforced through Setup Assistant during Automated Device Enrollment, requiring registration with an identity provider (IdP) and the ability for macOS to create a user account based on the user's information from the IdP.
After a computer has enrolled with Jamf School, it will be kept in Setup Assistant until a specified Platform SSO app and its associated profiles are installed. When the configuration is complete, macOS will begin a required Platform SSO registration process on the next screen a user sees during setup. After registration, the first user is created during Setup Assistant, based on the identity of the user that authenticated with the IdP. After a user registers with the IdP, Platform SSO applications can be configured to simplify user authentication to enterprise applications.
-
Platform SSO configured in your environment with a supported IdP (Okta and Microsoft Entra ID) and application. For more information, see Platform Single Sign-on for macOS with Jamf School.
-
Computers with macOS 26 or later enrolled via Automated Device Enrollment in Jamf School. For more information, see Automated Device Enrollment.
- In Jamf School, navigate to in the sidebar.
- Click the name of the profile that you configured during your initial Platform SSO setup.
- In the list of payloads on the left side of the pane, locate the macOS payload category and click the App Extension SSO payload.
- Select the Enable Registration During Setup checkbox.
- (Optional) To use Platform SSO to create the first user account on a computer during Setup Assistant, do the following:
- Click Save.
- Add the profile that you configured during your initial Platform SSO setup to an Automated Device Enrollment profile by doing the following:
- Navigate to in the sidebar.
- Click the name of the Automated Device Enrollment profile that you want to add the Platform SSO profile to.
- Click the Profiles and packages tab.
- In the Profiles section, click + Add.
- Choose the Platform SSO profile from the pop-up menu.
- Click Save.
Simplified Setup for Platform SSO is configured and applies to subsequently enrolled computers that the Automated Device Enrollment profile is assigned to.