175: Deploy macOS SSO extension
Overview
Deploying the macOS Single Sign-On (SSO) extension using Microsoft Intune can streamline authentication processes for users and enhance security. Here's a detailed overview:
Steps to Deploy macOS SSO Extension
-
Prerequisites:
- Ensure devices are running macOS 13.0 or newer.
- Install the Microsoft Intune Company Portal app version 5.2404.0 or newer.
-
Decide Authentication Method:
- Choose between passwordless authentication, Microsoft Entra ID user accounts, or smart cards.
-
Create Platform SSO Policy in Intune:
- Navigate to the Intune admin center.
- Go to Devices > Configuration profiles > Create profile.
- Select macOS for the platform and Device features for the profile type.
- Configure the SSO app extension settings¹.
-
Deploy the Company Portal App:
- Ensure the Company Portal app is deployed to all macOS devices.
-
Enroll Devices and Apply Policies:
- Enroll the macOS devices in Intune.
- Assign the SSO policy to the relevant user groups.
-
Confirm Settings on Devices:
- Verify that the SSO settings are correctly applied on the devices.
Benefits
- Reduced Authentication Prompts: Users experience fewer sign-in prompts, enhancing productivity.
- Enhanced Security: Supports passwordless authentication and integrates with Microsoft Entra ID for secure access.
- Seamless User Experience: Users can sign in using their Microsoft Entra ID credentials and Touch ID.
- Conditional Access: Ensures that only compliant devices can access corporate resources.
Drawbacks
- Compatibility Issues: Some older macOS versions may not support the latest SSO features.
- Initial Setup Complexity: Requires careful configuration and testing to ensure seamless deployment.
- Dependency on Microsoft Entra ID: Organizations must be using Microsoft Entra ID for full functionality.
Possible Impact on End Users
- Improved User Experience: Fewer sign-in prompts and easier access to resources.
- Learning Curve: Users may need initial guidance on using new authentication methods like Touch ID.
- Increased Security: Users benefit from enhanced security measures, reducing the risk of unauthorized access.