# Platform SSO on macOS: Authentication, Features, and Hexnode UEM Configuration

What is Platform SSO on macOS?
------------------------------

Platform Single Sign-On (Platform SSO) integrates an organization’s identity provider (IdP) directly into macOS authentication workflows. By linking a user’s cloud IdP account with their local Mac user profile, Platform SSO allows users to sign in to their Mac and access supported enterprise applications and resources with fewer repeated authentication prompts.

How Platform SSO extends Extensible SSO
---------------------------------------

Platform SSO is built on Apple’s Extensible Single Sign-On (SSO) framework. While standard SSO extensions deliver single sign-on access to supported applications and websites, Platform SSO expands this framework beyond the app layer to integrate identity providers into supported macOS login and system authentication workflows.

Requirements for Platform SSO
-----------------------------

Platform SSO on managed Mac devices requires a supported macOS version, a compatible identity provider (IdP) with a Platform SSO-enabled application, and a device management solution to deploy and manage the required configuration.

RequirementDetailsmacOSHexnode UEM supports macOS 14 or later for configuring Platform SSO.Identity providerA supported identity provider (IdP) that supports Platform SSO through a compatible SSO extension.IdP application with SSO extensionAn IdP-provided application containing a Platform SSO-compatible SSO extension installed on the Mac device.Device management ServiceA UEM/MDM solution such as Hexnode UEM capable of deploying the required Extensible SSO/Platform SSO configuration to Mac devices. Devices must be enrolled with the UEM solution to receive and apply these configurations.Bootstrap Token supportFor Platform SSO workflows involving Secure Token assignment, such as on-demand account creation and FileVault-related workflows, the UEM solution must support Bootstrap Token escrow. Hexnode permits escrowing of Bootstrap Token to the UEM console.Platform SSO-compatible IdP applications
----------------------------------------

The required Platform SSO application and supported version vary depending on the configured identity provider. The following table lists examples of IdP applications and their supported versions.

Identity providerRequired ApplicationVersion requirementMicrosoft Entra IDMicrosoft Company PortalVersion 5.2404.0 or laterOktaOkta VerifyVersion 9.52 or laterFor other identity providers, administrators should verify the availability of a Platform SSO-compatible application, SSO extension, and required configuration details with the respective IdP documentation.

How does Platform SSO work on macOS?
------------------------------------

Platform SSO works through three stages: configuration deployment, device and user registration, and authentication.

### 1. Deploy Platform SSO configuration

The organization first deploys the Platform SSO configuration through a device management solution such as Hexnode UEM. The configuration provides the Mac with the settings required for Platform SSO registration and communication with the organization’s identity provider.

### 2. Register the device and user with the IdP

After the Platform SSO configuration is deployed, the Mac communicates with the configured identity provider (IdP) through the IdP’s SSO extension to begin the Platform SSO registration process. Device registration establishes a trust relationship between the Mac and the IdP, allowing the IdP to recognize the device during Platform SSO authentication.

The user completes Platform SSO registration by authenticating with the configured IdP. This associates the user’s IdP account with the corresponding local macOS account.

### 3. Authenticate and access resources

During Mac sign-in, users authenticate their identity through the organization’s configured authentication method, which may include password-based or passwordless methods, including Secure Enclave-backed keys or smart cards. After authentication, Platform SSO uses authentication tokens to provide SSO access to supported native applications and websites.

Features of Platform SSO
------------------------

### Authentication and Single Sign-On

- **Single sign-on for applications and websites**: Allows users to access supported native and web applications using their organizational identity without repeatedly entering their credentials.
- **IdP-based Mac authentication**: Allows users to sign in to their Mac using their organizational credentials.
- **Multiple authentication methods**: Supports password-based and passwordless authentication methods, including Password, Secure Enclave-Backed Key, Smart Card, and Access Key. Organizations can require Touch ID verification as a second authentication factor for supported Platform SSO authentication methods.
- **Password synchronization**: Synchronizes the user’s IdP password with the corresponding local macOS account password.

### User Account Management

- **User account mapping**: Maps information from the user’s IdP account to attributes of the corresponding local macOS account.
- **On-demand account creation**: Allows a local macOS user account to be created when a user signs into the Mac for the first time using their IdP account. For newly created accounts, Bootstrap Token escrow enables macOS to automatically assign Secure Token privileges required for supported workflows.

### Authorization and Privilege Management

- **User authorization**: Allows users to use their IdP credentials to satisfy macOS authorization prompts for actions that require administrator approval, such as installing applications or changing system settings.
- **Privilege management**: Allows administrators to control the privileges assigned to users, including Standard, Admin, or group-based privileges.

### Authentication Policy Management

- **Authentication policies**: Allows organizations to control how Platform SSO authentication is applied during macOS login, FileVault unlock, and screensaver unlock by defining when IdP authentication is required.

### Shared Device and Device Enrollment Support

- **Shared device access**: Allows multiple users to access the same Mac by using shared device keys, which are cryptographic keys managed by macOS to maintain the device’s trusted relationship with the IdP independently of individual user accounts.
- **Authenticated Guest Mode**: Extends shared device access by allowing users to temporarily sign in to a shared Mac using their IdP credentials without creating a persistent local macOS account.
- **Platform SSO during Automated Device Enrollment**: Extends Platform SSO authentication to macOS Setup Assistant by allowing organizations to require IdP authentication during Automated Device Enrollment and create a local macOS user account using the authenticated identity.

Authentication methods in Platform SSO
--------------------------------------

Platform SSO supports both password-based and passwordless authentication methods.

Authentication MethodDescriptionPasswordUses the user’s IdP password as the authentication method for Platform SSO workflows. When password synchronization is enabled, the IdP password can be synchronized with the local macOS account password.Secure Enclave-backed keyUses hardware-bound cryptographic keys stored in the Mac’s Secure Enclave to authenticate the user with the IdP without requiring the IdP password.Smart cardUses a physical smart card containing an authentication certificate and associated PIN to authenticate the user with the IdP during supported Platform SSO workflows.Access keyUses a pass stored in Apple Wallet to authenticate the user with the IdP during Platform SSO authentication workflows.Platform SSO Capability Support by Authentication Method
--------------------------------------------------------

Platform SSO capabilities are not supported uniformly across all authentication methods. The following table shows which capabilities are supported for each authentication method available through the Hexnode UEM configuration.

Platform SSO capabilityPasswordSmart cardSecure Enclave–backed keyAccess keyPrivilege managementSupportedSupportedSupportedSupportedAuthenticated Guest ModeSupportedSupportedNot SupportedSupportedPlatform SSO during Automated Device EnrollmentSupportedSupportedSupportedNot SupportedOn-demand account creationSupportedSupportedNot SupportedSupportedPassword synchronizationSupportedNot SupportedNot SupportedNot SupportedAuthentication policiesSupportedNot SupportedNot SupportedNot SupportedRequire Touch IDSupportedNot SupportedSupportedNot SupportedHow enterprises benefit from Platform SSO
-----------------------------------------

### Consistent identity experience

Without Platform SSO, users authenticate separately with their organizational account and their local Mac account. Platform SSO links the local Mac account with the user’s organizational identity, allowing the organization’s existing identity to participate in Mac authentication and supported application access.

### Reduced password management

Platform SSO reduces credential management overhead by allowing organizations to align Mac authentication with existing identity systems. In supported configurations, password synchronization helps maintain consistency between the IdP password and the local macOS account password.

### Streamlined device onboarding

By requiring IdP authentication during Automated Device Enrollment, organizations can establish the user’s identity association during the initial Mac setup process. This allows Macs to be configured for organizational access as part of the initial deployment workflow.

### Flexible authentication and access control

Organizations can choose authentication methods and access policies based on their security requirements. Platform SSO supports password-based and passwordless authentication methods, while authorization and privilege management controls define what users are allowed to do on the Mac.

Platform SSO with Hexnode UEM
-----------------------------

Hexnode UEM allows administrators to deploy and manage Platform SSO configurations on enrolled Mac devices. Administrators can configure Platform SSO settings and centrally manage authentication and access policies from the UEM console instead of configuring individual Mac devices.

### Platform SSO management capabilities in Hexnode UEM

- **Authentication method configuration**
    Supports configuring Platform SSO authentication methods including Password, User Secure Enclave Key, Smart Card, and Access Key.
- **User account configuration**
    Allows administrators to configure how IdP identities are mapped to local macOS accounts and whether local user accounts are created when users sign in for the first time.
- **Shared device configuration**
    Allows administrators to configure shared device settings for Macs used by multiple users and manage temporary access scenarios through the UEM console.
- **Authentication policy management**
    Allows administrators to control Platform SSO authentication behavior during Login Window, FileVault unlock, and Screensaver Unlock by configuring whether IdP authentication is attempted or required.
- **Authentication grace period configuration**
    Provides Offline Grace Period and Authentication Grace Period settings to control authentication behavior when devices are offline or users have not completed Platform SSO registration.
- **Platform SSO during device setup**
    Allows administrators to configure Platform SSO authentication during macOS Setup Assistant so users can complete initial device setup using their organizational identity.

Administrators can configure Platform SSO under **Policies > macOS > Security > Extensible SSO** and enable **Platform SSO** to configure Platform SSO-specific settings in the Hexnode UEM portal. The configured policy can then be associated with the required Mac devices or device groups.

For detailed configuration steps and the available Platform SSO settings, refer to [Configure settings for Extensible Single Sign-On for macOS devices](https://www.hexnode.com/mobile-device-management/help/configure-settings-for-extensible-single-sign-on-for-macos-devices/).