Configuring a Platform SSO Profile for Computers

Jamf School Documentation

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

After you have determined the authentication method you want users to use and prepared the Company Portal app for distribution, you must deploy a profile to your target computers to enable Platform SSO with Microsoft Entra ID.

Important:

If you intend to use Simplified Setup for Platform SSO, keep the following in mind:

  • You must also add an Associated Domains payload to this profile and configure the payload. When configuring the payload, click + Add Associated Domain to add an associated domain, but do not enter any values in the App Identifier and Associated Domain fields.
  • You must enable the Enable Registration During Setup setting in this profile to activate Platform SSO during Setup Assistant.

  • You can use the Enable Create First User During Setup setting in this profile to use Platform SSO to create the first user account on a computer during Setup Assistant.

  • You can use the New User Authentication Methods setting to determine the authentication methods for new user creation. If this setting is not configured, the system will use Password and Smart Card authentication by default.

For more information about Simplified Setup for Platform SSO, see Configuring Simplified Setup for Platform SSO in Jamf School.

  1. In Jamf School, navigate to Profiles > Overview in the sidebar.
  2. Click + Create Profile.
  3. Select the macOS operating system.
  4. Select the type of enrollment you want to make the profile for.
  5. Enter a name in the Profile name field and configure the additional settings as needed, including the time filter.
  6. Click Finish.
  7. In the list of payloads on the left side of the pane, locate the macOS payload category and click the App Extension SSO payload.
  8. Click Configure.
  9. From the Sign-on type pop-up menu, choose "Redirect".
  10. In the Extension Identifier field, enter the following value: com.microsoft.CompanyPortalMac.ssoextension
  11. In the Team identifier field, enter the following value: UBF8T346G9
  12. In the URLs field, enter the URLs that macOS should trigger a redirect to the Company Portal app for authentication. These should include the following:
    Note:

    These URLs are subject to change. For up-to-date information, see the Manual configuration for other MDM services section of Microsoft's documentation.

    • https://login.microsoftonline.com

    • https://login.microsoft.com

    • https://sts.windows.net

    • https://login.partner.microsoftonline.cn

    • https://login.chinacloudapi.cn

    • https://login.microsoftonline.us

    • https://login-us.microsoftonline.com

    Note:

    Country-specific URLs (i.e., those ending in .cn and .us) are used to authenticate to national cloud instances and may be omitted if desired. For more information on national cloud instances, see the National clouds section of Microsoft's documentation.

  13. (Optional) To add a custom configuration setting for Microsoft Entra ID, click + Add a custom configuration, and then configure the key, type, and value for the setting. Repeat this step for each custom configuration setting you want to add.

    Microsoft Entra ID supports several additional configuration settings that can be configured for Platform SSO. The following settings enable the use of Platform SSO for all apps created by Microsoft, all apps created by Apple, and the Jamf Trust app. These settings are recommended but can be adjusted to meet your specific needs:

    KeyTypeValue
    AppPrefixAllowListStringcom.microsoft.,com.apple.,com.jamf.trust.
    browser_sso_interaction_enabledNumber1
    disable_explicit_app_promptNumber1

    For a full list of available settings, see the Manual configuration for other MDM services section of Microsoft's documentation.

  14. (Optional) In the Denied bundle identifiers field, enter the bundle identifiers of the applications that you do not want to use SSO provided by Microsoft Entra ID.
  15. From the Authentication when screen is locked pop-up menu, choose "Do not handle".
  16. (macOS 13 only) From the SSO Authentication Method pop-up menu, choose the option that you decided on earlier in the Determining the Authentication Method section.
    Note:

    This setting does not apply to computers with macOS 14 or later. To configure the authentication method to use on computers with macOS 14 or later, see step 20. If your environment has a mix of computers with macOS 13 and macOS 14 or later, configure both the SSO Authentication Method and Authentication method settings.

  17. Select the Use Platform SSO checkbox.
  18. In the Account display name field, enter the account display name to use in notifications and authorization requests. This value will be used in the notification that macOS uses as part of the registration process. Jamf recommends using the name of your school or organization.
    Example:
    If you enter Central District in the Account display name field, Platform SSO notifications and authorization requests will look like the following:
    • Use your Central District password to log in to your Mac.

    • Register your Mac computer with Central District.

    • Synchronize your macOS password with your "Central District" password.

  19. (macOS 14 or later only) From the Authentication method pop-up menu, choose the option that you decided on earlier in the Determining the Authentication Method section.
    Note:

    This setting does not apply to computers with macOS 13. To configure the authentication method to use on computers with macOS 13, see step 16. If your environment has a mix of computers with macOS 13 and macOS 14 or later, configure both the SSO Authentication Method and Authentication method settings.

  20. (Optional) To enable the use of the same signing and encryption keys for all users on the same device, select the Use shared device keys checkbox.
  21. (Optional) To allow the use of Microsoft Entra ID credentials for events that require authorization prompts (e.g., use of the sudo command, unlocking certain preferences in System Settings, and installation of software), select the Enable authorization checkbox. The user must also have administrator rights to complete authorization.
    Note:

    To use this setting, you must select the Use shared device keys checkbox.

  22. (Optional) To allow any user with valid credentials on your Microsoft Entra ID domain to create a new user account on their computer, select the Create new user at login checkbox. A local macOS UNIX user account will be created with the user's Microsoft Entra ID password. Users restricted to "passwordless" authentication in Microsoft Entra ID cannot use this method.
    Note:

    To use this setting, you must select the Use shared device keys checkbox and choose either "Password" or "Smart Card" from the Authentication method pop-up menu.

  23. From the Account authorization type pop-up menu, choose either "Standard" or "Admin".

    This setting determines what privilege set is granted upon a successful authentication to Microsoft Entra ID. For example, if you want users to be able to use their Microsoft Entra ID credentials to install printers, choose "Admin".

    Note:

    When configured, this setting will grant the specified privilege set to users each time the Platform SSO profile is deployed or updated. If your organization is also using other privilege management solutions (e.g., privilege elevation with Jamf Connect), Jamf recommends leaving these settings unconfigured to avoid unexpected behaviors or conflicts between deployed settings.

  24. From the New user account type pop-up menu, choose either "Standard" or "Admin".

    This setting determines the permissions to grant to user accounts created at login. This setting is used only when the account is created.

  25. In the Token-to-user mapping section, configure the following claims:
    1. In the Account name field, enter the following value: preferred_username
    2. In the Full name field, enter the following value: name

    For a complete list of additional claims, see the Payload claims section in Microsoft's documentation.

  26. (Optional) (macOS 15.4 or later only) To allow device UDIDs and serial numbers to be included in Platform SSO attestations, select the Allow device identifiers in attestation checkbox.
  27. In the Login Frequency field, configure the amount of time, in seconds, until the system requires a complete login instead of a refresh.
  28. (macOS 15 or later only) In the Non-Platform SSO Accounts field, enter the short name of each macOS local account on the computer that you do not want to require to authenticate with Platform SSO (e.g., a local administrator account added during Automated Device Enrollment).
  29. In the list of payloads on the left side of the pane, locate the General category and click the Scope payload.
  30. Configure the scope of the profile by clicking the + icon and adding device groups to the profile scope using the pop-up menu.
  31. Click the Settings icon on the right side of the page, and do one of the following:
    • To install the profile on devices automatically, click Change to automatic installation for all groups.

    • To allow users to install the profile themselves, click Change to on-demand installation for all groups. The profile will be available for users to install in the Jamf Teacher or Jamf School Student apps.

  32. Click Save.

The profile is distributed immediately to computers in the scope. After the command processes, macOS displays a notification to end users prompting them to register with Microsoft Entra ID to enable Platform SSO, which then creates a shell record in Microsoft Entra ID.