For diagnosing an existing deployment only. To set up the configuration profile,
the app, and registration, see
Deploy Iru Access.
Values used below.
N5M3B34269 is Iru’s Apple Team ID, the same value in
your Iru Access MDM profile, so the Iru Access App ID is always
N5M3B34269.com.iru.Access. yourcompany.id.iru.com stands in for your
organization’s Iru sign-in domain; your real output shows your actual domains.1
Confirm the associated domains are approved
The most common cause of a non-working SSO extension is that macOS has not approved
the associated domains. List every associated-domain approval on the Mac:Look for an entry with Service What to check:
authsrv, the Iru Access App ID
N5M3B34269.com.iru.Access, and your Iru sign-in domain (one entry per domain
your connection uses):Flags: enterpriseManagedindicates the domain was pushed by your MDM, as expected for a managed deployment. If it is missing, the configuration profile with the Associated Domains payload may not have reached this Mac.- There should be one entry per Iru domain your connection uses (a connection may include more than one). A missing domain points to an incomplete profile.
2
Confirm the extension is installed
List the Iru Access app extensions registered with macOS:You should see the SSO extension listed, for example:What to check:
- A
com.iru.Access.SSOExtensionline means the extension is registered. - No line at all means the Iru Access app is not installed, or its extension has not registered yet. Confirm the app is deployed and has been launched once.
3
Confirm the system loaded the extension
Stream the system’s SSO extension manager and look for Iru Access being loaded:A healthy system logs the Iru extension as loaded (output similar to):Any other single sign-on extensions installed on the Mac appear in the same list;
the one that matters here is
com.iru.Access.SSOExtension.4
Watch approvals and sign-in activity live
Two live streams help when an approval is slow to land, or when a sign-in is not
being intercepted.Associated-domain checks: watch macOS schedule and record domain approvals:The SSO agent: watch the process that runs the extension during sign-in:When the associated domains are not yet approved, the agent logs messages like
these, which point straight at the cause:
hasAssociatedDomainsApproved = 0 means the domains are not approved yet. Once
approval lands, these errors stop and sign-ins to your Iru domains are intercepted
by Iru Access.Common causes and fixes
Where to go next
Deploy Iru Access
Set up the configuration profile, the app, and registration.
MDM connections
The connection that pushes the profile and makes a device count as managed.
Device trust
Require managed, healthy devices as a condition of access.
Authenticators
How Iru Access fits alongside passkeys as an authenticator.