What is a Single Sign-On Extension?
A Single Sign-On (SSO) extension is a type of application for macOS, iOS, iPadOS, and visionOS that uses Apple’s Extensible Enterprise Single Sign-on framework. These applications, or extensions, let identity providers (IdPs) build applications that allow for a seamless SSO experience across native macOS applications and browsers. This allows you to sign in once to the extension and be authenticated across macOS, iOS, iPadOS, and visionOS. SSO extensions can also allow for synchronizing a user’s local macOS password with their IdP password.How Can I Deploy a Single Sign-On Extension?
- For iOS, iPadOS, and visionOS extensions, you must first deploy the app containing the SSO extension via Apps and Books from Apple Business or Apple School Manager.
- For macOS extensions, you must first deploy the app containing the SSO extension via Apps and Books from Apple Business or Apple School Manager or via a Custom App in Iru.
- After deploying the extension, you will then configure and deploy a Single Sign-On profile to the devices.
Configure a Single Sign-On Extension Profile
To add this Library Item to your Iru Endpoint Library, follow the steps outlined in the Library Overview article.Name the Library Item
Assign to Blueprints
Redirect Single Sign-On Extension Profile
Select Extension Type
Configure Extension Identifier
Set Team Identifier
Configure URLs
Set Denied Bundle Identifiers
Configure Additional Extension Settings
Credential Single Sign-On Extension Profile
Select Extension Type
Configure Extension Identifier
Set Team Identifier
Configure Realm
Set Hosts
Set Denied Bundle Identifiers
Configure Additional Extension Settings
Configure a Single Sign-On Extension Profile for Apple’s Kerberos Extension
Select Extension Type
Configure Realm
Set Hosts
Configure Password Options
What is Platform SSO?
Platform SSO allows Single Sign-On Extensions to extend their functionality to the macOS login window. This lets users unlock their Mac using an IdP password and enables just-in-time creation of local accounts on a shared Mac using credentials from your organization’s Identity Provider (IdP). The local account password is automatically kept in sync, so the cloud password and local passwords match. Permissions and local group memberships can be managed, and this also extends to IdP users who don’t have a local account, so those credentials can be used at authorization prompts.Configure Platform SSO
Enable Platform SSO
Select authentication method
Enter Registration token (optional)
Configure existing account permissions
Configure new account permissions
Configure shared device settings
Enable shared device keys
Allow authorization with IdP
Enable automatic account creation
Login Options & Groups
Configure login options
- The account display name will typically be your organization’s name or something your users will recognize as it appears in notifications and authentication requests.
- A full login can be required after a certain amount of time. The default is 18 hours (64800 seconds), and the minimum value is 1 hour (3600 seconds).
- The attribute mapping to use when creating new users or for authorization.
Configure authorization groups
- Admin groups are groups from your IdP that should have administrator access on the device.
- Additional groups are ones you would like to see created in the device’s local directory.
- User groups are most useful: They let you map specific macOS systems rights to arbitrary groups that will be created in the local directory. For example, to grant ‘sudo’ or printer management access.
Enable Registration During Setup Assistant (macOS 26 and later)
Starting in macOS 26, Platform SSO can run during Setup Assistant so the Mac can register with your identity provider earlier in the enrollment flow. This section lets you configure registration during setup, first-user creation, profile picture sync behavior, and Authenticated Guest Mode for shared-device workflows.Open the Mac macOS 26 and later section
Set Enable registration during Setup Assistant
Set Create first user during Setup Assistant
Set Synchronize profile picture
Set Enable Authenticated Guest Mode
Set New user authentication methods
Save the Library Item
Install Platform SSO Library Items during Automated Device Enrollment