Microsoft Enterprise Platform Single Sign-on for macOS

What

Platform Single Sign-on (Platform SSO or PSSO) extends Apple's Extensible SSO framework to the macOS login and account experience. For Microsoft Entra ID deployments, this workflow builds on FileWave's Microsoft Enterprise SSO plug-in for Apple devices guidance and Apple's Platform Single Sign-on for macOS framework.

With password authentication, Platform SSO can synchronize the user's local macOS account password with their Microsoft Entra ID password. Depending on the operating system version, identity provider support, and payload settings, Platform SSO can also support other authentication methods such as Secure Enclave-backed platform credentials or smart cards.

After registration, Platform Single Sign-on status appears under the user's account in System Settings > Users & Groups:

Configured Platform Single Sign-on status in macOS Users & Groups

When/Why

Use Platform SSO when you manage Mac computers with FileWave and want users to sign in with their Microsoft Entra ID identity while reducing local password drift. This builds on the Microsoft Enterprise SSO plug-in by extending the SSO experience closer to the local Mac account and login workflow.

How

Below are the main requirements and deployment steps to review before using the example profile.

Platform SSO requirements

Note: If the Mac is unenrolled from MDM, Apple notes that the Mac is also unregistered from the identity provider.

WS-Trust federation

WS-Trust federation is supported in macOS 13.3 or later. This allows Platform SSO to authenticate users when their account is managed by an identity provider federated with Microsoft Entra ID.

Deployment

The example below uses a Profile Fileset with a default password-authentication Platform SSO configuration:

FileWave Platform SSO deployment showing the profile and Company Portal installer

Please note: Company Portal is required for Microsoft's Platform SSO implementation because it contains the Microsoft SSO extension. Users generally do not need to configure Company Portal directly, but the app must be present and current enough before Platform SSO registration is expected to work.

End-user interaction required

After successful deployment, the user should see a Registration Required notification in macOS:

macOS Platform SSO registration required notification

When the user starts registration, macOS and Microsoft Entra ID will prompt the user to authenticate. Depending on the configuration, this can include entering the local or Platform SSO password and completing Microsoft Entra device registration:

Platform SSO password prompt for synchronizing the Mac password

Microsoft Entra device registration sign-in prompt

After registration, the user can confirm status in System Settings > Users & Groups by clicking the information button next to their account. The Platform Single Sign-on section should show the configured method, registration state, and token state.

Notes and Observations


Revision #10
Created 2024-03-20 16:16:01 UTC by Zachary Butterfield
Updated 2026-05-01 13:28:58 UTC by Josh Levitsky