About Okta Desktop Password Sync and Platform SSO
Okta Desktop Password Sync with Platform Single Sign-On (SSO) in Iru Endpoint keeps local macOS passwords aligned with Okta and extends Okta sign-in to the macOS login window.How It Works
Requirements
Okta Requirements
- You use Okta Identity Engine.
- Your macOS computers must run macOS 14 Sonoma or later, which supports Platform SSO 2.0 and Desktop Password Sync from the login window.
- The Desktop Password Sync application is available for your organization in Okta. If you can’t locate the Desktop Password Sync app in the app catalog, contact your Okta account representative.
- The Okta Verify authenticator is set up in your org.
- An Okta Verify Auto App Library Item in your Library, assigned to the Blueprints where you deploy Desktop Password Sync.
Additional Requirements
- Two Custom Profile mobileconfig templates from this guide (see Edit the mobileconfig template files) and a Single Sign-on Extension Library Item for Okta Platform SSO (see Configure the Okta Platform SSO Single Sign-on Extension Library Item).
FileVault Support for macOS 15+
Okta authentication policies can require stronger checks on macOS 15 and later, including the FileVault interface during Desktop Password Sync. Configure that in Okta; see FileVault network requirements.Create Device Access SCEP Certificates
Configure a Desktop SCEP Certificate Authority in Okta
Access Okta Admin Portal
Navigate to Security
Select Device Integrations
Select Device Access
Add SCEP Configuration
Select Static SCEP URL
Generate Configuration
Copy SCEP URL
Copy Secret Key
Save Configuration
Reset Secret Key (Optional)
Add the SCEP Library Item
To add this Library Item to your Iru Endpoint Library, see the Library Overview article.Configure the SCEP Library Item
Name the Library Item
Assign to Blueprints
Configure SCEP URL
Enter Name (Optional)
Configure Challenge
Set Subject
Configure Subject Alternative Name
Set Key Size
Set Key Usage
Configure Retries
Configure Retry Delay
Enable Private Key Access
Prevent Key Extraction
Configure Automatic Redistribution
Save Configuration
Create and Configure the Desktop Password Sync App Integration in Okta
Access Applications Catalog
Search for Desktop Password Sync
Add Integration
Open Application Configuration
Configure General Settings
Record Client ID
Assign Users or Groups
Save Configuration
Edit the Mobileconfig Template Files
Download and edit these two mobileconfig templates with a plain text editor such as Visual Studio Code, Sublime Text, or BBEdit:Okta_Associated_Domains_Configuration_Template.mobileconfig— Associated Domains for Okta Verify and the auth-service extensionOkta_Verify_Configuration_Template.mobileconfig— Okta tenant URL and Desktop Password Sync client ID for Okta Verify and the auth-service extension
Download Associated Domains Template
Download Okta Verify Template
Okta Associated Domains template
The Okta_Associated_Domains_Configuration_Template.mobileconfig file deploys a com.apple.associated-domains payload. It connects Okta Verify and the Okta auth-service extension to your Okta tenant for Platform SSO and Desktop Password Sync.Open Configuration Template
Update auth-service-extension AssociatedDomains
-
Example: authsrv:accuhive.okta.com
Update Okta Verify AssociatedDomains
-
Example: authsrv:accuhive.okta.com
Save Configuration File
Okta Verify template
Open Okta Verify Template
Set OktaVerify.OrgUrl on com.okta.mobile
-
Example: https://accuhive.okta.com
Set OktaVerify.PasswordSyncClientID on com.okta.mobile
Set OktaVerify.OrgUrl on com.okta.mobile.auth-service-extension
Set OktaVerify.PasswordSyncClientID on com.okta.mobile.auth-service-extension
Save Okta Verify Configuration File
Configure the Okta Platform SSO Single Sign-on Extension Library Item
Use a Single Sign-on Extension Library Item to deploy the Okta Verify redirect extension and Platform SSO settings on enrolled Mac computers.Name the Library Item
Select Platform
Assign to Blueprints
Select Extension Type
Configure Extension Identifier
Set Team Identifier
Configure URLs
accuhive.okta.com with your Okta org hostname (the same hostname you used in the Associated Domains and Okta Verify templates):Leave Hosts empty
Enable Platform SSO
Select Authentication Method
Enter Registration token (optional)
Enable macOS 15 and later settings (optional)
Set Existing Users permissions
Set New Users permissions
Enable Shared Device Keys
Enable authorization with identity provider
Enable automatic local account creation (optional)
Enable device attestation (optional)
Enter Account display name
Set Require Full Login Timeout
Configure Token Mapping
Configure Groups (optional)
- Admin groups are groups from Okta that should receive administrator access on the device.
- Additional groups are custom groups to create in the device’s local directory.
- User groups map macOS system rights (for example
sudoor printer management) to local directory groups.
Save the Library Item
Enable Registration During Setup Assistant (macOS 26 and later)
On macOS 26 and later, Platform SSO can run during Setup Assistant so the Mac registers with Okta earlier in enrollment. Set registration during setup, first-user creation, profile picture sync, and Authenticated Guest Mode in the Mac macOS 26 and later section of your Okta Platform SSO Single Sign-on Extension Library Item.Open the Single Sign-on Extension Library Item
Set Enable registration during Setup Assistant
Set Create first user during Setup Assistant
Set Synchronize profile picture
Set Enable Authenticated Guest Mode
Set New user authentication methods
Save the Library Item
Install Platform SSO Library Items during Automated Device Enrollment
When you use registration during Setup Assistant, the SCEP Library Item, both Custom Profile Library Items, the Okta Platform SSO Single Sign-on Extension Library Item, and the Okta Verify Auto App must install before Setup Assistant finishes. Add and assign those Library Items in Add Library Items in Iru Endpoint, then configure Automated Device Enrollment:Open the Automated Device Enrollment Library Item
Turn on Install Library Items during Setup Assistant
Add required Library Items
- SCEP Library Item
- Okta Associated Domains (Custom Profile) —
Okta_Associated_Domains_Configuration_Template.mobileconfig - Okta Verify Configuration (Custom Profile) —
Okta_Verify_Configuration_Template.mobileconfig - Okta Platform SSO (Single Sign-on Extension Library Item)
- Okta Verify Auto App
Save the Automated Device Enrollment Library Item
Add Library Items in Iru Endpoint
Add your SCEP Library Item, Custom Profile Library Items, Okta Platform SSO Single Sign-on Extension Library Item, and Okta Verify Auto App to Iru Endpoint. See the Library Overview article if you need the basics.Create the Associated Domains Custom Profile Library Item
Confirm the Okta Platform SSO Single Sign-on Extension Library Item
Create the Okta Verify Custom Profile Library Item
Assign the Okta Verify Auto App
Deploy to devices
Assignment Maps
Assign the SCEP Library Item, both Custom Profile Library Items, the Okta Platform SSO Single Sign-on Extension Library Item, and the Okta Verify Auto App on the Blueprint Assignment Map. Use conditional logic when you need to scope Library Items to specific device groups. See Configuring Blueprints for Blueprint basics.Switch to the Okta Verify Auto App
If Okta Verify is already on the Blueprint through another Library Item, switch to the Okta Verify Auto App without redoing Desktop Password Sync setup. Your Custom Profile Library Items, Okta Platform SSO Single Sign-on Extension Library Item, and Okta configuration stay on the device.Edit the Assignment Map
Remove the previous Okta Verify assignment
Assign the Okta Verify Auto App
Save the Assignment Map