> ## Documentation Index
> Fetch the complete documentation index at: https://docs.iru.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Deploy Okta Desktop Password Sync and Platform SSO

> Deploy Okta Desktop Password Sync with Platform SSO on Mac using Iru Endpoint. Configure SCEP, Custom Profile Library Items, and the Okta Verify Auto App.

<Callout icon="apple" color="#B84A7A" iconType="regular">This guide applies to Mac computers</Callout>

### About Okta Desktop Password Sync and Platform SSO

Okta Desktop Password Sync with Platform Single Sign-On (SSO) in Iru Endpoint keeps local macOS passwords aligned with Okta and extends Okta sign-in to the macOS login window.

### How It Works

<Warning>
  Okta Desktop Password Sync is currently in Okta "Early Access" release. See Okta's resource: [Manage Early Access and Beta](https://help.okta.com/oie/en-us/content/topics/security/manage-ea-and-beta-features.htm).
</Warning>

<Note>
  Deploy Desktop Password Sync with the **Okta Verify Auto App** Library Item. If the App Store version of Okta Verify is already on your Blueprint, see [Switch to the Okta Verify Auto App](#switch-to-the-okta-verify-auto-app) later in this guide.
</Note>

### Requirements

#### Okta Requirements

* You use Okta Identity Engine.
* Your macOS computers must run **macOS 14 Sonoma or later**, which supports **Platform SSO 2.0** and Desktop Password Sync from the login window.
* The Desktop Password Sync application is available for your organization in Okta. If you can't locate the Desktop Password Sync app in the app catalog, contact your Okta account representative.
* The Okta Verify authenticator is set up in your org.
* An **Okta Verify** Auto App Library Item in your Library, assigned to the Blueprints where you deploy Desktop Password Sync.

#### Additional Requirements

* Two Custom Profile mobileconfig templates from this guide (see **Edit the mobileconfig template files**) and a **Single Sign-on Extension** Library Item for Okta Platform SSO (see **Configure the Okta Platform SSO Single Sign-on Extension Library Item**).

### FileVault Support for macOS 15+

Okta authentication policies can require stronger checks on macOS 15 and later, including the FileVault interface during Desktop Password Sync. Configure that in Okta; see [FileVault network requirements](https://help.okta.com/oie/en-us/content/topics/oda/macos-pw-sync/about-psso-version-history.htm#fvnetwork).

### Create Device Access SCEP Certificates

#### Configure a Desktop SCEP Certificate Authority in Okta

<Steps>
  <Step title="Access Okta Admin Portal">
    Log in to your Okta admin portal.
  </Step>

  <Step title="Navigate to Security">
    In the left-hand navigation, select **Security**.
  </Step>

  <Step title="Select Device Integrations">
    In the expanded menu, select **Device Integrations**.
  </Step>

  <Step title="Select Device Access">
    In the Device Integration pane, select **Device Access**.
  </Step>

  <Step title="Add SCEP Configuration">
    Click **Add SCEP configuration**.
  </Step>

  <Step title="Select Static SCEP URL">
    Select **Static SCEP URL**.
  </Step>

  <Step title="Generate Configuration">
    Click **Generate**.
  </Step>

  <Step title="Copy SCEP URL">
    Copy the **SCEP URL**.
  </Step>

  <Step title="Copy Secret Key">
    Copy the **Secret key**.

    Record the secret key now. This is the only time you can view it. Okta stores a hash afterward.
  </Step>

  <Step title="Save Configuration">
    Click **Save**.
  </Step>

  <Step title="Reset Secret Key (Optional)">
    If you need to **Reset the secret key**, you can do so from the **Actions** menu to the right of the integration.
  </Step>
</Steps>

#### Add the SCEP Library Item

To add this Library Item to your Iru Endpoint Library, see the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article.

#### Configure the SCEP Library Item

<Steps>
  <Step title="Name the Library Item">
    Name the Library Item.
  </Step>

  <Step title="Assign to Blueprints">
    Assign it to your desired [Blueprints](/en/endpoint/getting-started/blueprints-and-library/configuring-blueprints).
  </Step>

  <Step title="Configure SCEP URL">
    In the **URL** field, paste the SCEP server URL you copied earlier.
  </Step>

  <Step title="Enter Name (Optional)">
    Enter a **Name** (optional).
  </Step>

  <Step title="Configure Challenge">
    In the **Challenge** field, paste the secret key you copied earlier.
  </Step>

  <Step title="Set Subject">
    In the **Subject** field, enter CN=\$SERIAL\_NUMBER.

    When you save the SCEP Library Item, Iru Endpoint appends the PROFILE\_UUID to the CN.
  </Step>

  <Step title="Configure Subject Alternative Name">
    Set **Subject Alternative Name** type to **None**.
  </Step>

  <Step title="Set Key Size">
    For **Key Size**, select 2048.
  </Step>

  <Step title="Set Key Usage">
    For **Key Usage**, select Signing.
  </Step>

  <Step title="Configure Retries">
    Select **Retries** and enter **5**. Change this if your environment needs a different retry count.
  </Step>

  <Step title="Configure Retry Delay">
    Select **Retry delay** and enter **30** seconds. Change this if your environment needs a different delay.
  </Step>

  <Step title="Enable Private Key Access">
    Select **Allow apps to access the private key**.
  </Step>

  <Step title="Prevent Key Extraction">
    Select **Prevent the private key data from being extracted in the keychain**.
  </Step>

  <Step title="Configure Automatic Redistribution">
    Select **Automatic profile redistribution** and enter **30** days before the certificate expires. Change this if your environment needs a different interval.
  </Step>

  <Step title="Save Configuration">
    Click Save.
  </Step>
</Steps>

For more information about the Iru Endpoint SCEP Library Item, see [Configure the SCEP Library Item](/en/endpoint/library/library-items-profiles/configure-the-scep-library-item).

### Create and Configure the Desktop Password Sync App Integration in Okta

<Steps>
  <Step title="Access Applications Catalog">
    In the Okta Admin Console, go to **Applications** > **Applications Catalog**.
  </Step>

  <Step title="Search for Desktop Password Sync">
    Search for **Desktop Password Sync** and select the app.
  </Step>

  <Step title="Add Integration">
    Click **Add Integration**. If you see **This feature isn't enabled**, contact your Okta account representative.
  </Step>

  <Step title="Open Application Configuration">
    Open Desktop Password Sync from your **Applications** list to configure it.
  </Step>

  <Step title="Configure General Settings">
    On the **General** tab, you can edit the application label or use the default label.
  </Step>

  <Step title="Record Client ID">
    On the **Sign on** tab, record the **Client ID**. You need it when you edit the Okta Verify mobileconfig template.
  </Step>

  <Step title="Assign Users or Groups">
    Assign the app to individual users or groups on the **Assignments** tab. Users must be assigned the app to use Desktop Password Sync.
  </Step>

  <Step title="Save Configuration">
    Click **Save**.
  </Step>
</Steps>

### Edit the Mobileconfig Template Files

Download and edit these two mobileconfig templates with a plain text editor such as Visual Studio Code, Sublime Text, or BBEdit:

* `Okta_Associated_Domains_Configuration_Template.mobileconfig` — Associated Domains for Okta Verify and the auth-service extension
* `Okta_Verify_Configuration_Template.mobileconfig` — Okta tenant URL and Desktop Password Sync client ID for Okta Verify and the auth-service extension

Upload each finished file as a Custom Profile Library Item in [Add Library Items in Iru Endpoint](#add-library-items-in-iru-endpoint).

<Steps>
  <Step title="Download Associated Domains Template">
    Download **Okta\_Associated\_Domains\_Configuration\_Template.mobileconfig** from the support GitHub repository ([GitHub](https://github.com/kandji-inc/support/blob/main/Configuration%20Profiles/Okta_Associated_Domains_Configuration_Template.mobileconfig)).
  </Step>

  <Step title="Download Okta Verify Template">
    Download **Okta\_Verify\_Configuration\_Template.mobileconfig** from the support GitHub repository ([GitHub](https://github.com/kandji-inc/support/blob/main/Configuration%20Profiles/Okta_Verify_Configuration_Template.mobileconfig)).
  </Step>
</Steps>

#### Okta Associated Domains template

The **Okta\_Associated\_Domains\_Configuration\_Template.mobileconfig** file deploys a **com.apple.associated-domains** payload. It connects Okta Verify and the Okta auth-service extension to your Okta tenant for Platform SSO and Desktop Password Sync.

<Steps>
  <Step title="Open Configuration Template">
    Open the **Okta\_Associated\_Domains\_Configuration\_Template.mobileconfig** file in your text editor.
  </Step>

  <Step title="Update auth-service-extension AssociatedDomains">
    In the first **Configuration** entry, update **AssociatedDomains** and replace the example domain with your Okta tenant address.

    * Example: authsrv:accuhive.okta.com

      ```xml theme={null}
      <key>ApplicationIdentifier</key>
      <string>B7F62B65BN.com.okta.mobile.auth-service-extension</string>
      <key>AssociatedDomains</key>
      <array>
           <!-- replace accuhive.okta.com with your tenant address -->
           <string>authsrv:accuhive.okta.com</string>
      ```
  </Step>

  <Step title="Update Okta Verify AssociatedDomains">
    In the second **Configuration** entry, update **AssociatedDomains** for **com.okta.mobile** and replace the example domain with your Okta tenant address.

    * Example: authsrv:accuhive.okta.com

      ```xml theme={null}
      <key>ApplicationIdentifier</key>
      <string>B7F62B65BN.com.okta.mobile</string>
      <key>AssociatedDomains</key>
      <array>
           <!-- replace accuhive.okta.com with your tenant address -->
           <string>authsrv:accuhive.okta.com</string>
      ```
  </Step>

  <Step title="Save Configuration File">
    Save the mobileconfig file. You will upload it as a Custom Profile Library Item in [Add Library Items in Iru Endpoint](#add-library-items-in-iru-endpoint).
  </Step>
</Steps>

#### Okta Verify template

<Steps>
  <Step title="Open Okta Verify Template">
    Open the **Okta\_Verify\_Configuration\_Template.mobileconfig** file in your text editor.
  </Step>

  <Step title="Set OktaVerify.OrgUrl on com.okta.mobile">
    In the **com.okta.mobile** payload, set **OktaVerify.OrgUrl** to your Okta tenant URL.

    * Example: [https://accuhive.okta.com](https://accuhive.okta.com)

      ```xml theme={null}
      <dict>
           <!-- replace accuhive.okta.com with your tenant -->
           <key>OktaVerify.OrgUrl</key>
           <string>https://accuhive.okta.com</string>
      ```
  </Step>

  <Step title="Set OktaVerify.PasswordSyncClientID on com.okta.mobile">
    In the **com.okta.mobile** payload, set **OktaVerify.PasswordSyncClientID** to the Desktop Password Sync app **Client ID** you recorded earlier.

    ```xml theme={null}
    <!-- replace YOUR_CLIENT_ID with your Desktop Password Sync app Client ID -->
    <key>OktaVerify.PasswordSyncClientID</key>
    <string>YOUR_CLIENT_ID</string>
    ```
  </Step>

  <Step title="Set OktaVerify.OrgUrl on com.okta.mobile.auth-service-extension">
    In the **com.okta.mobile.auth-service-extension** payload, set **OktaVerify.OrgUrl** to your Okta tenant URL.

    ```xml theme={null}
    <dict>
         <!-- replace accuhive.okta.com with your tenant -->
         <key>OktaVerify.OrgUrl</key>
         <string>https://accuhive.okta.com</string>
    ```
  </Step>

  <Step title="Set OktaVerify.PasswordSyncClientID on com.okta.mobile.auth-service-extension">
    In the **com.okta.mobile.auth-service-extension** payload, set **OktaVerify.PasswordSyncClientID** to the Desktop Password Sync app **Client ID** you recorded earlier.

    ```xml theme={null}
    <!-- replace YOUR_CLIENT_ID with your Desktop Password Sync app Client ID -->
    <key>OktaVerify.PasswordSyncClientID</key>
    <string>YOUR_CLIENT_ID</string>
    ```
  </Step>

  <Step title="Save Okta Verify Configuration File">
    Save **Okta\_Verify\_Configuration\_Template.mobileconfig**.
  </Step>
</Steps>

### Configure the Okta Platform SSO Single Sign-on Extension Library Item

Use a **Single Sign-on Extension** Library Item to deploy the Okta Verify redirect extension and Platform SSO settings on enrolled Mac computers.

<Note>
  Finish the **Okta Associated Domains** and **Okta Verify Configuration** Custom Profiles before you assign this Library Item.
</Note>

See the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article to add Library Items in Iru Endpoint. For field descriptions, see [Configure the Single Sign-On Extension Library Item](/en/endpoint/library/library-items-profiles/configure-the-single-sign-on-extension-library-item).

<Steps>
  <Step title="Name the Library Item">
    Enter a **Name** for the new Library Item (for example **Okta Platform SSO**).
  </Step>

  <Step title="Select Platform">
    Select **Mac** as the **Install on** platform.
  </Step>

  <Step title="Assign to Blueprints">
    Assign the Library Item to the same [Blueprints](/en/endpoint/getting-started/blueprints-and-library/configuring-blueprints) as your SCEP Library Item and Custom Profile Library Items for this deployment.
  </Step>

  <Step title="Select Extension Type">
    Under **Extension type**, select **Redirect**.
  </Step>

  <Step title="Configure Extension Identifier">
    For **Extension identifier**, enter:

    ```text theme={null}
    com.okta.mobile.auth-service-extension
    ```
  </Step>

  <Step title="Set Team Identifier">
    For **Team identifier**, enter:

    ```text theme={null}
    B7F62B65BN
    ```
  </Step>

  <Step title="Configure URLs">
    Add these **URLs**, replacing `accuhive.okta.com` with your Okta org hostname (the same hostname you used in the Associated Domains and Okta Verify templates):

    ```text theme={null}
    https://accuhive.okta.com/device-access/api/v1/nonce
    ```

    ```text theme={null}
    https://accuhive.okta.com/oauth2/v1/token
    ```

    ```text theme={null}
    https://accuhive.okta.com/v1/auth/device-sign
    ```
  </Step>

  <Step title="Leave Hosts empty">
    Leave **Hosts** empty.
  </Step>

  <Step title="Enable Platform SSO">
    Toggle **Platform SSO** on.
  </Step>

  <Step title="Select Authentication Method">
    Under **Authentication method**, select **Password**.

    Desktop Password Sync requires password authentication at the macOS login window.
  </Step>

  <Step title="Enter Registration token (optional)">
    Enter a **Registration token** only if Okta or your org requires one for Platform SSO registration.
  </Step>

  <Step title="Enable macOS 15 and later settings (optional)">
    Under **Platform SSO**, turn on any **macOS 15 and later** options your org needs for Desktop Password Sync or FileVault. See [FileVault Support for macOS 15+](#filevault-support-for-macos-15) and [Okta's macOS PSSO version history](https://help.okta.com/oie/en-us/content/topics/oda/macos-pw-sync/about-psso-version-history.htm).
  </Step>

  <Step title="Set Existing Users permissions">
    Set default permissions for **Existing Users** (Standard or administrator, or a group you configure in a later step).
  </Step>

  <Step title="Set New Users permissions">
    Set default permissions for **New Users**.
  </Step>

  <Step title="Enable Shared Device Keys">
    Select **Use shared device keys**.

    This setting is required for Desktop Password Sync.
  </Step>

  <Step title="Enable authorization with identity provider">
    Turn on **Allow authorization (with identity provider account)** so users can approve system prompts with their Okta credentials.
  </Step>

  <Step title="Enable automatic local account creation (optional)">
    If you want local accounts created automatically at the login window, enable **Allow creation of new users at login window**.

    <Warning>
      Local account creation requires the device to be online at the login window with FileVault unlocked, and Iru Endpoint must have a valid bootstrap token for the device.
    </Warning>
  </Step>

  <Step title="Enable device attestation (optional)">
    If your org uses device attestation, turn on the option to send the device UDID and serial number in Platform SSO attestations (macOS 15.4 and later).
  </Step>

  <Step title="Enter Account display name">
    Enter an **Account display name** users will recognize in notifications and sign-in prompts (often your company name). This value is system-wide and visible to every user on the Mac.
  </Step>

  <Step title="Set Require Full Login Timeout">
    Specify **Require full login** in seconds. The default in Iru Endpoint is 18 hours (64800 seconds). The minimum is 1 hour (3600 seconds).
  </Step>

  <Step title="Configure Token Mapping">
    Under **Token mapping**, configure **AccountName** and **FullName**, plus any other attributes you need for new user creation and authorization. Use attribute names from your Okta tenant for Platform SSO or Desktop Password Sync.

    If you aren't sure which values to use, ask your Okta administrator or see **Configure login options** in [Configure the Single Sign-On Extension Library Item](/en/endpoint/library/library-items-profiles/configure-the-single-sign-on-extension-library-item#login-options--groups).
  </Step>

  <Step title="Configure Groups (optional)">
    Optional: configure **Admin groups**, **Additional groups**, and **User groups**:

    * **Admin groups** are groups from Okta that should receive administrator access on the device.
    * **Additional groups** are custom groups to create in the device's local directory.
    * **User groups** map macOS system rights (for example `sudo` or printer management) to local directory groups.
  </Step>

  <Step title="Save the Library Item">
    Click **Save**.
  </Step>
</Steps>

If you deploy Platform SSO during Setup Assistant on **macOS 26** or later, configure the **Mac macOS 26 and later** section of this Library Item. See [Enable Registration During Setup Assistant (macOS 26 and later)](#enable-registration-during-setup-assistant-macos-26-and-later).

### Enable Registration During Setup Assistant (macOS 26 and later)

On **macOS 26** and later, Platform SSO can run during Setup Assistant so the Mac registers with Okta earlier in enrollment. Set registration during setup, first-user creation, profile picture sync, and Authenticated Guest Mode in the **Mac macOS 26 and later** section of your **Okta Platform SSO** Single Sign-on Extension Library Item.

<Warning>
  When you deploy Platform SSO with Automated Device Enrollment, do not set **Primary account type** to **Skip primary account creation** in the **Mac** section of your [Automated Device Enrollment Library Item](/en/endpoint/enrollment/apple/configuring-apple-enrollment). Setup Assistant is where the user sets the local account password. Skipping that step leaves the password unset and can stall enrollment.

  On Mac computers with Apple silicon and some other models, credentials are stored in the [Secure Enclave](https://support.apple.com/guide/security/the-secure-enclave-sec59b0b31ff/web). See Apple's documentation for which devices include a Secure Enclave. **Skip primary account creation** is for [Passport](/en/endpoint/library/passport/passport-compatibility-with-macos-and-iru-endpoint-features#primary-account-creation) workflows, not Platform SSO.
</Warning>

<Steps>
  <Step title="Open the Single Sign-on Extension Library Item">
    In the **Library**, open your **Okta Platform SSO** Single Sign-on Extension Library Item, click **Edit**, then go to **Mac macOS 26 and later** in the **Platform SSO** section.
  </Step>

  <Step title="Set Enable registration during Setup Assistant">
    For **Enable registration during Setup Assistant**, select **Yes** to register with Okta during Setup Assistant.
  </Step>

  <Step title="Set Create first user during Setup Assistant">
    For **Create first user during Setup Assistant**, select **Yes** when the Mac should create its first local account during Setup Assistant from the Okta identity. Select **No** if you provision the first account another way.
  </Step>

  <Step title="Set Synchronize profile picture">
    For **Synchronize profile picture**, select **Yes** to copy the user's Okta profile picture to the local macOS account during setup, or **No** to skip it.
  </Step>

  <Step title="Set Enable Authenticated Guest Mode">
    Turn on **Enable Authenticated Guest Mode** for shared Macs where users sign in temporarily with Okta. Leave it off for standard single-user Macs.
  </Step>

  <Step title="Set New user authentication methods">
    Under **New user authentication methods**, select the methods for newly created accounts. Include **Password** and **SmartCard** as your org requires.
  </Step>

  <Step title="Save the Library Item">
    Click **Save**.
  </Step>
</Steps>

#### Install Platform SSO Library Items during Automated Device Enrollment

When you use registration during Setup Assistant, the SCEP Library Item, both Custom Profile Library Items, the **Okta Platform SSO** Single Sign-on Extension Library Item, and the **Okta Verify Auto App** must install before Setup Assistant finishes. Add and assign those Library Items in [Add Library Items in Iru Endpoint](#add-library-items-in-iru-endpoint), then configure Automated Device Enrollment:

<Steps>
  <Step title="Open the Automated Device Enrollment Library Item">
    In the **Library**, open your **Automated Device Enrollment** Library Item and go to the **Mac** section.
  </Step>

  <Step title="Turn on Install Library Items during Setup Assistant">
    Turn on **Install Library Items during Setup Assistant** for **Mac** so selected Library Items install during enrollment setup instead of after Setup Assistant completes.
  </Step>

  <Step title="Add required Library Items">
    Select **Add Library Items** and add each item from this guide:

    * SCEP Library Item
    * Okta Associated Domains (Custom Profile) — `Okta_Associated_Domains_Configuration_Template.mobileconfig`
    * Okta Verify Configuration (Custom Profile) — `Okta_Verify_Configuration_Template.mobileconfig`
    * Okta Platform SSO (Single Sign-on Extension Library Item)
    * Okta Verify Auto App

    A Library Item in this list installs during Setup Assistant only when it is also on the device's Blueprint **Assignment Map**. Add every item you need during setup to that map.
  </Step>

  <Step title="Save the Automated Device Enrollment Library Item">
    Click **Save** on the Automated Device Enrollment Library Item.
  </Step>
</Steps>

See [Install Library Items during Setup Assistant](/en/endpoint/enrollment/apple/configuring-apple-enrollment#install-library-items-during-setup-assistant) for the install experience, timeouts, and other considerations.

### Add Library Items in Iru Endpoint

Add your SCEP Library Item, Custom Profile Library Items, **Okta Platform SSO** Single Sign-on Extension Library Item, and **Okta Verify Auto App** to Iru Endpoint. See the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article if you need the basics.

<Steps>
  <Step title="Create the Associated Domains Custom Profile Library Item">
    Name the Library Item (for example **Okta Associated Domains**). Assign it to your [Blueprints](/en/endpoint/getting-started/blueprints-and-library/configuring-blueprints). Upload your edited **Okta\_Associated\_Domains\_Configuration\_Template.mobileconfig** file, then click **Save**.
  </Step>

  <Step title="Confirm the Okta Platform SSO Single Sign-on Extension Library Item">
    If you haven't already, complete [Configure the Okta Platform SSO Single Sign-on Extension Library Item](#configure-the-okta-platform-sso-single-sign-on-extension-library-item) and assign it to the same Blueprint(s).
  </Step>

  <Step title="Create the Okta Verify Custom Profile Library Item">
    Create a Custom Profile Library Item for **Okta\_Verify\_Configuration\_Template.mobileconfig** (for example **Okta Verify Configuration**). Assign it to the same Blueprint(s), upload the file, and click **Save**.
  </Step>

  <Step title="Assign the Okta Verify Auto App">
    In the Library, go to **Auto Apps** and open **Okta Verify**. Assign the Library Item to the same Blueprint(s) as the SCEP Library Item, Custom Profile Library Items, and **Okta Platform SSO** Single Sign-on Extension Library Item.
  </Step>

  <Step title="Deploy to devices">
    After devices receive the Library Items and **Okta Verify Auto App**, users are prompted to register and sync their Okta password.
  </Step>
</Steps>

### Assignment Maps

Assign the SCEP Library Item, both Custom Profile Library Items, the **Okta Platform SSO** Single Sign-on Extension Library Item, and the **Okta Verify Auto App** on the Blueprint **Assignment Map**.

Use [conditional logic](/en/endpoint/blueprints/assignment-maps/using-conditional-logic-in-blueprints) when you need to scope Library Items to specific device groups. See [Configuring Blueprints](/en/endpoint/getting-started/blueprints-and-library/configuring-blueprints) for Blueprint basics.

### Switch to the Okta Verify Auto App

If Okta Verify is already on the Blueprint through another Library Item, switch to the **Okta Verify Auto App** without redoing Desktop Password Sync setup. Your Custom Profile Library Items, **Okta Platform SSO** Single Sign-on Extension Library Item, and Okta configuration stay on the device.

<Warning>
  Make assignment changes in one Assignment Map edit session. Assign the **Okta Verify Auto App** before you select **Save**. Do not leave computers without an assigned Okta Verify app after you save.
</Warning>

<Steps>
  <Step title="Edit the Assignment Map">
    Open the Blueprint **Assignment Map**, then select **Edit assignments**.
  </Step>

  <Step title="Remove the previous Okta Verify assignment">
    Remove the existing **Okta Verify** Library Item from the Assignment Map.
  </Step>

  <Step title="Assign the Okta Verify Auto App">
    Add the **Okta Verify Auto App** Library Item to the same Assignment Map scope as your SCEP, Custom Profile, and **Okta Platform SSO** Library Items.
  </Step>

  <Step title="Save the Assignment Map">
    Select **Save** to apply the Assignment Map changes.
  </Step>
</Steps>

<Note>
  The previous Okta Verify app is removed from devices. The Associated Domains profile, **Okta Platform SSO** Single Sign-on Extension configuration, and Okta Verify Custom Profile remain. On the next Iru Agent check-in (within about 15 minutes), Iru Endpoint installs the **Okta Verify Auto App**.

  If you also use [Okta Device Trust](/en/endpoint/integrations/okta-device-trust-main/okta-device-trust), see [Configure Okta Verify for Device Trust](/en/endpoint/integrations/okta-device-trust-main/okta-device-trust-configuring-the-okta-verify-library-item#migrate-from-the-app-store-app-to-the-auto-app-macos) when you need to update ODT on the Auto App.
</Note>

### User Experience and Next Steps

<Note>
  With Platform SSO enabled, macOS hides the **Change** button in the Password field under **Users & Groups** (System Settings). Apple designed this behavior for Platform SSO.
</Note>

After deployment, send users to [User Experience with Okta Desktop Password Sync](/en/endpoint/integrations/okta-desktop-password-sync-user-experience) for registration steps.
