For computers with macOS 14 or later, you must deploy a SCEP profile alongside the Single Sign-on Extension profile for Platform SSO to function properly.
Requirements
You must generate a SCEP URL and secret key in your Okta Admin Console before proceeding in Jamf Pro. For more information, see Configure Okta as a CA with Static SCEP challenge for macOS with Jamf Pro from Okta.
- In Jamf Pro, click Computers in the sidebar.
- Click Configuration profiles in the sidebar.
- Click New.
- Click the SCEP payload.
- Click Configure.
- In the URL field, enter the static SCEP URL generated in your Okta Admin Console.
- In the Name field, enter a display name for the SCEP instance.
- Choose 7 days from the pop-up menu under Redistribute Profile.
- In the Subject field, enter the following value: CN=$COMPUTERNAME $PROFILE_IDENTIFIER
- Under Subject Alternative Names, ensure Challenge Type is set to Static.
- In the Challenge and Verify Challenge fields, enter the challenge secret from your Okta portal.
- In the Retries field, ensure the value is set to 0.
- In the Retry Delay field, ensure the value is set to 0.
- Choose 2048 from the Key Size pop-up menu.
- Deselect the Allow export from keychain checkbox.
- Select the Allow all apps access checkbox.
- Click the Scope tab, and then configure the target devices or device groups.
- Click Save in the bottom-right corner of the pane.
The configuration profile is deployed to computers in scope.