How to Setup Platform SSO to Entra ID Join a Mac

  Рет қаралды 8,476

Get Rubix

Get Rubix

Күн бұрын

Пікірлер: 65
@takacsi
@takacsi 5 ай бұрын
ohhh I went trought on a lot of documentation, blog post, reddit post, yt video, but this is far away the most useful and informative content! Thank you so much!
@getrubix
@getrubix 5 ай бұрын
Thanks!
@timlarkman9657
@timlarkman9657 5 ай бұрын
Amazing video, I love how you explain everything. I was able to get my mac fully registered as you did. When the Authentication Method is set to Secure Enclave, is there a way to login to the mac using your Entra credentials? I thought that is the purpose of Platform SSO?
@getrubix
@getrubix 5 ай бұрын
Yeah, it turns out it can only be 'Password' right now. I assume this is something MS is working...
@chriso1523
@chriso1523 5 ай бұрын
Excellent video. All works for me except the registration piece. Once logged in, I’m not being asked to register. Policies seem correct…or at least I think so😅. What am I missing?
@B4D4617f
@B4D4617f 4 ай бұрын
having this issue too
@mikealrifae5467
@mikealrifae5467 4 ай бұрын
Same with me !
@lulutratra6
@lulutratra6 5 ай бұрын
Hello, How did you assign the configuration profil to the device before it's enrolled and how did you do iit with the app?
@getrubix
@getrubix 5 ай бұрын
Apple Business Manager
@CheddarBobChad
@CheddarBobChad Ай бұрын
Do we need to create a dynamic device group of ADE/DEP devices pulling from Apple Business Manager and assign that to the app group for Company Portal or does that install from the SSO Profile?
@getrubix
@getrubix Ай бұрын
I would recommend a dynamic group, if not "All Macs"
@onoriodeeko4073
@onoriodeeko4073 2 ай бұрын
could not create an apple business account from Nigeria as I cannot see Nigeria in the country list. Any idea will be appreciated. after selecting just any country, I was not getting the email verification code. Your advise will be appreciated.
@Dynomitech
@Dynomitech 5 ай бұрын
I've been trying to add the user account under the Platform SSO config settings, but it nevers pulls down. I see you added it on the Enrollment Profile. Have you had a chance to test the account setup under Platform SSO settings? I guess I'll do the enrollment option for now to test.
@getrubix
@getrubix 5 ай бұрын
I believe so but I'll double check.
@Dynomitech
@Dynomitech 5 ай бұрын
@@getrubix thanks! When I saw there were two spots to enter user account information I was confused which part to add it to. I know this whole Platform SSO is in early stages so some things may not be working yet.
@Dynomitech
@Dynomitech 5 ай бұрын
After doing some more research, I saw someone mention that the PSSO create login might only be viable for Non-User Affinity. I am doing User Affinity so that could be the problem. I just tried with your method and it pulled down perfectly.
@B4D4617f
@B4D4617f 4 ай бұрын
Question for you. We already have devices in production. Does turning on "Await final configuration" and setting up "local Primary account", have an effect on already set-up devices?
@getrubix
@getrubix 4 ай бұрын
I believe it's for new deployments only but have not tested
@IamHere2007de
@IamHere2007de 2 ай бұрын
Will the local account also be created for non DEP devices hence only enrolling via the company portal? Entra join worked, also SSO within the browser. But I have no local account
@getrubix
@getrubix 2 ай бұрын
I haven't tried that yet. I will say, this video was definitely one of my more popular ones, so a follow seems to be inbound :)
@IamHere2007de
@IamHere2007de 2 ай бұрын
@@getrubix since the company portal needs to be installed while logged on with an local admin account, I doubt that a new local account like the one configured within the DEP profile can be created automatically.
@abelbeans
@abelbeans 2 ай бұрын
Does this allow users to log into their macbooks with the Entra ID credentials and keep them synced? Looking into Jamf Connect for this and wondering if this is an alternate option
@getrubix
@getrubix 2 ай бұрын
Correct!
@kamilprokopowicz
@kamilprokopowicz 21 күн бұрын
company portal didn't initialize, I can't add applications, I did everything according to the intructions, where could be the error?
@chavdaroff
@chavdaroff 2 ай бұрын
I'm trying to configure this using the Jamf MDM but i'm having troubles getting the Entra ID registration at initial set-up after enrollement. Anyone have any ideas?
@snipereye119
@snipereye119 6 ай бұрын
First, great video! Second, if you're using Entra as your IdP, have you experienced any challenges with users not getting a kerberos ticket while remote? By remote, I mean off-site with no active VPN connection to on-prem network/resources. Seems like cloud kerberos should be the solution, but I'm not sure how to get Macs to point to that.
@getrubix
@getrubix 6 ай бұрын
I have only tested this remote, so no line of site at all. Have not had issues, but will dig a bit further and report back ☺️
@NelsonSaenz
@NelsonSaenz 7 ай бұрын
Looks promising. Can the Microsoft Apps, namely OneDrive be automatically configured and setup for backup of Desktop and Documents folders like on Windows?
@getrubix
@getrubix 7 ай бұрын
Yes- OneDrive can be pushed and KFM (Known Folder Move) can be enforced via Settings Catalog policy.
@ZebSmithulon
@ZebSmithulon 7 ай бұрын
Looks like pretty much the same process to onboard iOS devices through ABM.
@getrubix
@getrubix 7 ай бұрын
Exactly!
@lespinozaq
@lespinozaq 5 ай бұрын
Hi, do you know what configuration would allow the Mac login password to be the same as SSO? The idea is that the user does not have 2 different passwords.
@getrubix
@getrubix 5 ай бұрын
The "Authentication method" needs to be set to 'Password' in order for them to sync
@sethzwicker3631
@sethzwicker3631 5 ай бұрын
@@getrubix I've been trying that but seems to choke when prompting to put in my Entra Password. Very frustrating, ugh.
@dontknowyet7503
@dontknowyet7503 4 ай бұрын
is it applicable for new device setup or existing devices too?
@getrubix
@getrubix 4 ай бұрын
It can be applied to existing Macs
@dontknowyet7503
@dontknowyet7503 4 ай бұрын
@@getrubix my bad there was space in system extension. thank you very much helped alot
@dontknowyet7503
@dontknowyet7503 4 ай бұрын
i would like to also know what happens if local and entra ID password is different? whats happens when password is expired
@jonathang8571
@jonathang8571 5 ай бұрын
I noticed if I hit "dismiss" on the popup for enabling Company Portal to be used as a Passkey, I don't get the prompt again. There a way we could automatically permit this access?
@getrubix
@getrubix 5 ай бұрын
I'll look into it.
@KJA009
@KJA009 6 ай бұрын
Hey, Do you assign the SSO Config profile and Company Portal App to a group with the User or Device ?
@getrubix
@getrubix 6 ай бұрын
Device group
@KJA009
@KJA009 6 ай бұрын
@@getrubix So you add the device to the group once its enrolled or can you create a dynamic group, similar to the ones we use for AP (Group Tags?).
@sneeziaz
@sneeziaz 6 ай бұрын
@@getrubix In the documentation it says: In Assignments, select the users or user groups that will receive your profile. Platform SSO policies are user-based policies. Don't assign the platform SSO policy to devices.
@KJA009
@KJA009 6 ай бұрын
Confirmed.. switched to user groups and it's all working.. Thanks
@jmanuelng
@jmanuelng 7 ай бұрын
Compadre!! Thumbs up before even seeing the video 👍👍👍👍
@getrubix
@getrubix 7 ай бұрын
Thanks!
@Kvikku
@Kvikku 7 ай бұрын
Were you able to sign into the Mac with your Entra credentials instead of the local account?
@sivaram1122
@sivaram1122 7 ай бұрын
You have to select credentials in your platform sso MDM profile instead of security enclave.
@getrubix
@getrubix 7 ай бұрын
Is that to avoid the local password first? My understanding is the first password will be local, until the Company Portal reg- please let me know!
@sivaram1122
@sivaram1122 7 ай бұрын
@@getrubix it's a local password first and after company portal + platform sso profile it will ask you to register your entra credential. If you choose authendication method to password then your entra password sync with your mac local account. If you select security enclave then you need to use local password to login. But your sso will work after you sign in to mac.
@sivaram1122
@sivaram1122 7 ай бұрын
Yes first password is a local one and CP + PSSO MDM policy sync entra password to mac login profile after.
@ezmonet7618
@ezmonet7618 7 ай бұрын
When I enable Extension Identifier, I do not have the Type option.
@getrubix
@getrubix 7 ай бұрын
Type should be automatically selected from the catalog when selecting 'Extension Identifier'
@mani2care
@mani2care 7 ай бұрын
How to do using the JAMF with mac device
@jmanuelng
@jmanuelng 2 ай бұрын
Anyone using "Managed AppleID" federated with Entra? Pros? Cons? Comments?
@SeanJackson-zb1gb
@SeanJackson-zb1gb 6 ай бұрын
Hey anybody know how to get the same working with JAMF pro instead of Intune. Any help would be greatly appreciated. Thanks
@getrubix
@getrubix 6 ай бұрын
Sorry, I don't know much about JAMF.
@excusetheblood
@excusetheblood 5 ай бұрын
Microsoft Platform SSO doesn't work with Jamf Pro yet. Microsoft is in the process of adding other MDM's besides Intune but nothing yet, it has to be Intune. Could look into Jamf Connect though, same functionality. More, in fact.
@ToTCaMbIu
@ToTCaMbIu 7 ай бұрын
My client has OKTA as the primary IDP synced to EntraID (don't ask why). I'm still trying to figure out if OKTA supports this.
@getrubix
@getrubix 7 ай бұрын
Not sure, to be honest. I would think based on the auth flow that Entra ID needs to be the IDP, but could be wrong.
@dc93-v4s
@dc93-v4s 6 ай бұрын
@@getrubix If M365 is federated with Okta, the Microsoft login will appear, but once it picks up the email of a federated account, it will redirect to that IdP, in this case Okta for authentication and then return back to finish the enrollment.
@seankearney7070
@seankearney7070 6 ай бұрын
I'm guessing there's no support to do this retroactivity for existing user accounts already configured on the Mac. It's a great start but the additional user steps required once logged in don't make it nearly as streamlined as Autopilot, and definitely something that will be misunderstood during employee onboarding. I'm just moaning at this point, but having the ability to add devices to ABM without wiping and via Apple Config (or purchasing through Apple Business) is long overdue.
@getrubix
@getrubix 6 ай бұрын
I agree (and I do plenty of moaning, so no worries). The bit about having to do the post sign in steps on first enrollment are definitely not as smooth as Autopilot, but this is just a first pass and I'm sure this will be addressed. You should be able to deploy platform SSO to current Mac devices as long as they're enrolled with Intune.
@seankearney7070
@seankearney7070 6 ай бұрын
I haven’t had a chance to do my own deployment yet. Do you know how you sync up the local user with EntraID? I’m assuming that it will just link the currently logged in account used to authenticate the company portal. Just wondering what happens with a mismatch between the UPN and local account name where we have say amyw as the local account name, but their Microsoft UPN starts as Amy.White@
How to Setup Windows Autopilot in Microsoft Intune
26:10
Jonathan Edwards
Рет қаралды 69 М.
Windows Autopilot V2? Or just a new profile type? Who cares! It's here!
12:11
99.9% IMPOSSIBLE
00:24
STORROR
Рет қаралды 31 МЛН
Smart Sigma Kid #funny #sigma
00:33
CRAZY GREAPA
Рет қаралды 39 МЛН
2023E17 - macOS Platform SSO and Much More! (I.T)
42:19
Intune Training
Рет қаралды 6 М.
425 Show | Best Practices for Deploying Platform SSO with Microsoft Entra ID
56:09
Microsoft Security Community
Рет қаралды 2,7 М.
How to configure Platform SSO for macOS via Intune
17:29
Cybersecurity World
Рет қаралды 353
How to enable Entra ID Single Sign on on macOS device
7:47
Cybersecurity World
Рет қаралды 233
One Big Step for Apple SSO and One Giant Leap for Platform SSO
25:19
CloudManagement.Community
Рет қаралды 2,2 М.
How to Bind a Mac to Active Directory (Join macOS to AD)
9:54
Tech With Emilio
Рет қаралды 65 М.
What's the BEST Mac Window Manager for 2024? Part 1
20:07
it-alex
Рет қаралды 7 М.
I'm switching to Mac, after a lifetime of Windows
18:12
Fstoppers
Рет қаралды 1 МЛН
Passkeys with Entra ID on a Mac? Configure Platform SSO with Secure Enclave in Intune today!
8:44
Intune for Education Customer Acceleration Team
Рет қаралды 3,7 М.
99.9% IMPOSSIBLE
00:24
STORROR
Рет қаралды 31 МЛН