Deploying a Platform Single Sign-on Extensions Configuration Profile

Technical Articles

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

You must deploy a configuration profile containing a Platform SSO configuration to enable Platform SSO on target computers. If you have computers in your environment with macOS 13 and macOS 14 or later, you must create separate profiles for each OS.

Important:

If you intend to use Simplified Setup with Platform SSO, keep the following in mind:

  • You must enable the Enable registration during setup and Create first user during setup settings in this profile to activate Platform SSO during Setup Assistant.

  • You can also include the New user creation authentication method setting to determine the authentication method for new user creation. If this setting is not enabled, the system will use Password and Smart Card authentication by default.

Requirements

To enable Platform SSO, you must first configure the Platform Single Sign-on app in your Okta Admin Console. For more information, see the "Create and configure the Platform Single Sign-on app" section in the Desktop Password Sync for macOS article from Okta.

  1. In Jamf Pro, click Computers in the sidebar.
  2. Click Configuration profiles in the sidebar.
  3. Click New.
  4. Click the Associated Domains payload.
    1. (macOS 14 or later only) Click Add.
    2. (macOS 14 or later only) In the App Identifier field, enter the following value: B7F62B65BN.com.okta.mobile.
    3. (macOS 14 or later only) In the Associated Domain field, enter the Okta domain for your organization.
      Example:

      authsrv:DOMAIN.okta.com

    4. (macOS 14 or later only) Ensure the Enable Direct Downloads checkbox is deselected.
    5. (macOS 14 or later only) Click Save.
    6. Click Add.
    7. In the App Identifier field, enter the following value: B7F62B65BN.com.okta.mobile.auth-service-extension
    8. In the Associated Domain field, enter the Okta domain for your organization.
      Example:

      authsrv:DOMAIN.okta.com

    9. Ensure the Allow Direct Downloads checkbox is deselected.
    10. Click Save.
    11. Click Save .
  5. Click the General payload, and then click Edit.
  6. Click the Single Sign-on Extensions payload.
    1. Click Add.
    2. Under Payload Type, ensure SSO is selected in the toggle button.
    3. In the Extension Identifier field, enter the following value: com.okta.mobile.auth-service-extension
    4. In the Team Identifier field, enter the following value: B7F62B65BN
    5. Under Sign-on Type, select Redirect in the toggle button.
    6. In the URLs field, enter the following value: OKTA_URL/device-access/api/v1/nonce
      Note:

      Replace OKTA_URL with the Okta URL for your organization, including http:// or https://

    7. Click Add.
    8. In the URLs field, enter the following value: OKTA_URL/oauth2/v1/token
      Note:

      Replace OKTA_URL with the Okta URL for your organization, including http:// or https://

    9. Under Setting, select the toggle for Use Platform SSO, and ensure Password is selected in the toggle button.
    10. (macOS 14 or later only) Select the toggle for Use Shared Device Keys and ensure Enabled is selected in the toggle button.
    11. Select the toggle for Account Display Name and enter a display name for your configuration.

      This value will be used in notifications that macOS uses as part of the registration process. Use a value that will be clear to end users what credentials are required (example: ACME Okta Credentials).

    12. Click Save .
  7. (Optional) (macOS 14 or later) To enable Just-In-Time local account creation for additional user accounts, do the following:
    1. Select the toggle for Registration Token and enter any value.

      This value must be present, but any value can be used because the SCEP profile created in Deploying a SCEP Profile will override this value.

    2. Select the toggle for Create New User at Login and ensure Enabled is selected in the toggle button.
    3. Select the toggle for User Mapping and enter macOSAccountFullName in the Full Name field, and macOSAccountUsername in the Account Name field.
    4. Select the toggle for Account Authorization Type, and use the pop-up menu to set the authorization type as either Standard or Admin.
    5. Select the toggle for New User Account Type, and use the pop-up menu to set account permissions to either Standard or Admin.

    For more information on Just-In-Time account creation, see Just-In-Time (JIT) Local Account Creation for macOS from Okta.

  8. Click the Scope tab, and then configure the target devices or device groups.
  9. Click Save in the bottom-right corner of the pane.

The configuration profile is deployed immediately to computers in the scope. After the command processes, macOS displays a notification to end users prompting them to register with Okta to enable Platform SSO.