Skip to main content

Category filter

Platform SSO on macOS: Authentication, Features, and Hexnode UEM Configuration

TL;DR

Platform SSO enables macOS devices to use an organization’s identity provider (IdP) for supported Mac authentication and single sign-on workflows. Hexnode UEM helps administrators deploy and manage Platform SSO configurations, allowing users to access Mac sign-in workflows and supported enterprise applications through their organizational identity.

What is Platform SSO on macOS?

Platform Single Sign-On (Platform SSO) integrates an organization’s identity provider (IdP) directly into macOS authentication workflows. By linking a user’s cloud IdP account with their local Mac user profile, Platform SSO allows users to sign in to their Mac and access supported enterprise applications and resources with fewer repeated authentication prompts.

How Platform SSO extends Extensible SSO

Platform SSO is built on Apple’s Extensible Single Sign-On (SSO) framework. While standard SSO extensions deliver single sign-on access to supported applications and websites, Platform SSO expands this framework beyond the app layer to integrate identity providers into supported macOS login and system authentication workflows.

Requirements for Platform SSO

Platform SSO on managed Mac devices requires a supported macOS version, a compatible identity provider (IdP) with a Platform SSO-enabled application, and a device management solution to deploy and manage the required configuration.

Requirement Details
macOS Hexnode UEM supports macOS 14 or later for configuring Platform SSO.
Identity provider A supported identity provider (IdP) that supports Platform SSO through a compatible SSO extension.
IdP application with SSO extension An IdP-provided application containing a Platform SSO-compatible SSO extension installed on the Mac device.
Device management Service A UEM/MDM solution such as Hexnode UEM capable of deploying the required Extensible SSO/Platform SSO configuration to Mac devices. Devices must be enrolled with the UEM solution to receive and apply these configurations.
Bootstrap Token support For Platform SSO workflows involving Secure Token assignment, such as on-demand account creation and FileVault-related workflows, the UEM solution must support Bootstrap Token escrow. Hexnode permits escrowing of Bootstrap Token to the UEM console.

Platform SSO-compatible IdP applications

The required Platform SSO application and supported version vary depending on the configured identity provider. The following table lists examples of IdP applications and their supported versions.

Identity provider Required Application Version requirement
Microsoft Entra ID Microsoft Company Portal Version 5.2404.0 or later
Okta Okta Verify Version 9.52 or later

For other identity providers, administrators should verify the availability of a Platform SSO-compatible application, SSO extension, and required configuration details with the respective IdP documentation.

How does Platform SSO work on macOS?

Platform SSO works through three stages: configuration deployment, device and user registration, and authentication.

1. Deploy Platform SSO configuration

The organization first deploys the Platform SSO configuration through a device management solution such as Hexnode UEM. The configuration provides the Mac with the settings required for Platform SSO registration and communication with the organization’s identity provider.

2. Register the device and user with the IdP

After the Platform SSO configuration is deployed, the Mac communicates with the configured identity provider (IdP) through the IdP’s SSO extension to begin the Platform SSO registration process. Device registration establishes a trust relationship between the Mac and the IdP, allowing the IdP to recognize the device during Platform SSO authentication.

The user completes Platform SSO registration by authenticating with the configured IdP. This associates the user’s IdP account with the corresponding local macOS account.

3. Authenticate and access resources

During Mac sign-in, users authenticate their identity through the organization’s configured authentication method, which may include password-based or passwordless methods, including Secure Enclave-backed keys or smart cards. After authentication, Platform SSO uses authentication tokens to provide SSO access to supported native applications and websites.

Features of Platform SSO

Authentication and Single Sign-On

  • Single sign-on for applications and websites: Allows users to access supported native and web applications using their organizational identity without repeatedly entering their credentials.
  • IdP-based Mac authentication: Allows users to sign in to their Mac using their organizational credentials.
  • Multiple authentication methods: Supports password-based and passwordless authentication methods, including Password, Secure Enclave-Backed Key, Smart Card, and Access Key. Organizations can require Touch ID verification as a second authentication factor for supported Platform SSO authentication methods.
  • Password synchronization: Synchronizes the user’s IdP password with the corresponding local macOS account password.

User Account Management

  • User account mapping: Maps information from the user’s IdP account to attributes of the corresponding local macOS account.
  • On-demand account creation: Allows a local macOS user account to be created when a user signs into the Mac for the first time using their IdP account. For newly created accounts, Bootstrap Token escrow enables macOS to automatically assign Secure Token privileges required for supported workflows.

Authorization and Privilege Management

  • User authorization: Allows users to use their IdP credentials to satisfy macOS authorization prompts for actions that require administrator approval, such as installing applications or changing system settings.
  • Privilege management: Allows administrators to control the privileges assigned to users, including Standard, Admin, or group-based privileges.

Authentication Policy Management

  • Authentication policies: Allows organizations to control how Platform SSO authentication is applied during macOS login, FileVault unlock, and screensaver unlock by defining when IdP authentication is required.

Shared Device and Device Enrollment Support

  • Shared device access: Allows multiple users to access the same Mac by using shared device keys, which are cryptographic keys managed by macOS to maintain the device’s trusted relationship with the IdP independently of individual user accounts.
  • Authenticated Guest Mode: Extends shared device access by allowing users to temporarily sign in to a shared Mac using their IdP credentials without creating a persistent local macOS account.
  • Platform SSO during Automated Device Enrollment: Extends Platform SSO authentication to macOS Setup Assistant by allowing organizations to require IdP authentication during Automated Device Enrollment and create a local macOS user account using the authenticated identity.

Authentication methods in Platform SSO

Platform SSO supports both password-based and passwordless authentication methods.

Authentication Method Description
Password Uses the user’s IdP password as the authentication method for Platform SSO workflows. When password synchronization is enabled, the IdP password can be synchronized with the local macOS account password.
Secure Enclave-backed key Uses hardware-bound cryptographic keys stored in the Mac’s Secure Enclave to authenticate the user with the IdP without requiring the IdP password.
Smart card Uses a physical smart card containing an authentication certificate and associated PIN to authenticate the user with the IdP during supported Platform SSO workflows.
Access key Uses a pass stored in Apple Wallet to authenticate the user with the IdP during Platform SSO authentication workflows.

Platform SSO Capability Support by Authentication Method

Platform SSO capabilities are not supported uniformly across all authentication methods. The following table shows which capabilities are supported for each authentication method available through the Hexnode UEM configuration.

Platform SSO capability Password Smart card Secure Enclave–backed key Access key
Privilege management Supported Supported Supported Supported
Authenticated Guest Mode Supported Supported Not Supported Supported
Platform SSO during Automated Device Enrollment Supported Supported Supported Not Supported
On-demand account creation Supported Supported Not Supported Supported
Password synchronization Supported Not Supported Not Supported Not Supported
Authentication policies Supported Not Supported Not Supported Not Supported
Require Touch ID Supported Not Supported Supported Not Supported

How enterprises benefit from Platform SSO

Consistent identity experience

Without Platform SSO, users authenticate separately with their organizational account and their local Mac account. Platform SSO links the local Mac account with the user’s organizational identity, allowing the organization’s existing identity to participate in Mac authentication and supported application access.

Reduced password management

Platform SSO reduces credential management overhead by allowing organizations to align Mac authentication with existing identity systems. In supported configurations, password synchronization helps maintain consistency between the IdP password and the local macOS account password.

Streamlined device onboarding

By requiring IdP authentication during Automated Device Enrollment, organizations can establish the user’s identity association during the initial Mac setup process. This allows Macs to be configured for organizational access as part of the initial deployment workflow.

Flexible authentication and access control

Organizations can choose authentication methods and access policies based on their security requirements. Platform SSO supports password-based and passwordless authentication methods, while authorization and privilege management controls define what users are allowed to do on the Mac.

Platform SSO with Hexnode UEM

Hexnode UEM allows administrators to deploy and manage Platform SSO configurations on enrolled Mac devices. Administrators can configure Platform SSO settings and centrally manage authentication and access policies from the UEM console instead of configuring individual Mac devices.

Platform SSO management capabilities in Hexnode UEM

  • Authentication method configuration
    Supports configuring Platform SSO authentication methods including Password, User Secure Enclave Key, Smart Card, and Access Key.
  • User account configuration
    Allows administrators to configure how IdP identities are mapped to local macOS accounts and whether local user accounts are created when users sign in for the first time.
  • Shared device configuration
    Allows administrators to configure shared device settings for Macs used by multiple users and manage temporary access scenarios through the UEM console.
  • Authentication policy management
    Allows administrators to control Platform SSO authentication behavior during Login Window, FileVault unlock, and Screensaver Unlock by configuring whether IdP authentication is attempted or required.
  • Authentication grace period configuration
    Provides Offline Grace Period and Authentication Grace Period settings to control authentication behavior when devices are offline or users have not completed Platform SSO registration.
  • Platform SSO during device setup
    Allows administrators to configure Platform SSO authentication during macOS Setup Assistant so users can complete initial device setup using their organizational identity.

Administrators can configure Platform SSO under Policies > macOS > Security > Extensible SSO and enable Platform SSO to configure Platform SSO-specific settings in the Hexnode UEM portal. The configured policy can then be associated with the required Mac devices or device groups.

For detailed configuration steps and the available Platform SSO settings, refer to Configure settings for Extensible Single Sign-On for macOS devices.

Frequently Asked Questions

1. When should an organization use Platform SSO instead of Extensible SSO?

Organizations should use Extensible SSO when the requirement is limited to providing single sign-on access to supported applications and websites. Platform SSO should be used when organizations need their identity provider to participate in macOS authentication workflows, such as Mac sign-in, local account association, and supported authentication scenarios.

2. Does Platform SSO replace the local Mac account?

No. Platform SSO does not replace the local macOS account. Instead, it associates the local account with the user’s organizational identity, allowing the IdP to be used during supported Mac sign-in workflows.

3. Can Platform SSO create a local Mac user account?

Yes. Platform SSO can create a local macOS account when user account creation is configured. The local account can be associated with the user’s IdP identity using attributes provided by the identity provider, such as the username or display name.

4. Does Platform SSO require an internet connection to sign in to a Mac?

No, not always. Platform SSO supports offline authentication for supported configurations. When the Mac is offline, authentication behavior depends on the configured authentication method and Platform SSO settings. Administrators can configure an Offline Grace Period to control how long offline authentication remains available.

5. How does Platform SSO work during Mac enrollment?

Platform SSO can be integrated with macOS Setup Assistant during Automated Device Enrollment. Organizations can require users to authenticate with their IdP during setup, allowing identity registration and local account creation to be incorporated into the initial deployment process.

macOS Device Management