ohhh I went trought on a lot of documentation, blog post, reddit post, yt video, but this is far away the most useful and informative content! Thank you so much!
@getrubix5 ай бұрын
Thanks!
@timlarkman96575 ай бұрын
Amazing video, I love how you explain everything. I was able to get my mac fully registered as you did. When the Authentication Method is set to Secure Enclave, is there a way to login to the mac using your Entra credentials? I thought that is the purpose of Platform SSO?
@getrubix5 ай бұрын
Yeah, it turns out it can only be 'Password' right now. I assume this is something MS is working...
@chriso15235 ай бұрын
Excellent video. All works for me except the registration piece. Once logged in, I’m not being asked to register. Policies seem correct…or at least I think so😅. What am I missing?
@B4D4617f4 ай бұрын
having this issue too
@mikealrifae54674 ай бұрын
Same with me !
@lulutratra65 ай бұрын
Hello, How did you assign the configuration profil to the device before it's enrolled and how did you do iit with the app?
@getrubix5 ай бұрын
Apple Business Manager
@CheddarBobChadАй бұрын
Do we need to create a dynamic device group of ADE/DEP devices pulling from Apple Business Manager and assign that to the app group for Company Portal or does that install from the SSO Profile?
@getrubixАй бұрын
I would recommend a dynamic group, if not "All Macs"
@onoriodeeko40732 ай бұрын
could not create an apple business account from Nigeria as I cannot see Nigeria in the country list. Any idea will be appreciated. after selecting just any country, I was not getting the email verification code. Your advise will be appreciated.
@Dynomitech5 ай бұрын
I've been trying to add the user account under the Platform SSO config settings, but it nevers pulls down. I see you added it on the Enrollment Profile. Have you had a chance to test the account setup under Platform SSO settings? I guess I'll do the enrollment option for now to test.
@getrubix5 ай бұрын
I believe so but I'll double check.
@Dynomitech5 ай бұрын
@@getrubix thanks! When I saw there were two spots to enter user account information I was confused which part to add it to. I know this whole Platform SSO is in early stages so some things may not be working yet.
@Dynomitech5 ай бұрын
After doing some more research, I saw someone mention that the PSSO create login might only be viable for Non-User Affinity. I am doing User Affinity so that could be the problem. I just tried with your method and it pulled down perfectly.
@B4D4617f4 ай бұрын
Question for you. We already have devices in production. Does turning on "Await final configuration" and setting up "local Primary account", have an effect on already set-up devices?
@getrubix4 ай бұрын
I believe it's for new deployments only but have not tested
@IamHere2007de2 ай бұрын
Will the local account also be created for non DEP devices hence only enrolling via the company portal? Entra join worked, also SSO within the browser. But I have no local account
@getrubix2 ай бұрын
I haven't tried that yet. I will say, this video was definitely one of my more popular ones, so a follow seems to be inbound :)
@IamHere2007de2 ай бұрын
@@getrubix since the company portal needs to be installed while logged on with an local admin account, I doubt that a new local account like the one configured within the DEP profile can be created automatically.
@abelbeans2 ай бұрын
Does this allow users to log into their macbooks with the Entra ID credentials and keep them synced? Looking into Jamf Connect for this and wondering if this is an alternate option
@getrubix2 ай бұрын
Correct!
@kamilprokopowicz21 күн бұрын
company portal didn't initialize, I can't add applications, I did everything according to the intructions, where could be the error?
@chavdaroff2 ай бұрын
I'm trying to configure this using the Jamf MDM but i'm having troubles getting the Entra ID registration at initial set-up after enrollement. Anyone have any ideas?
@snipereye1196 ай бұрын
First, great video! Second, if you're using Entra as your IdP, have you experienced any challenges with users not getting a kerberos ticket while remote? By remote, I mean off-site with no active VPN connection to on-prem network/resources. Seems like cloud kerberos should be the solution, but I'm not sure how to get Macs to point to that.
@getrubix6 ай бұрын
I have only tested this remote, so no line of site at all. Have not had issues, but will dig a bit further and report back ☺️
@NelsonSaenz7 ай бұрын
Looks promising. Can the Microsoft Apps, namely OneDrive be automatically configured and setup for backup of Desktop and Documents folders like on Windows?
@getrubix7 ай бұрын
Yes- OneDrive can be pushed and KFM (Known Folder Move) can be enforced via Settings Catalog policy.
@ZebSmithulon7 ай бұрын
Looks like pretty much the same process to onboard iOS devices through ABM.
@getrubix7 ай бұрын
Exactly!
@lespinozaq5 ай бұрын
Hi, do you know what configuration would allow the Mac login password to be the same as SSO? The idea is that the user does not have 2 different passwords.
@getrubix5 ай бұрын
The "Authentication method" needs to be set to 'Password' in order for them to sync
@sethzwicker36315 ай бұрын
@@getrubix I've been trying that but seems to choke when prompting to put in my Entra Password. Very frustrating, ugh.
@dontknowyet75034 ай бұрын
is it applicable for new device setup or existing devices too?
@getrubix4 ай бұрын
It can be applied to existing Macs
@dontknowyet75034 ай бұрын
@@getrubix my bad there was space in system extension. thank you very much helped alot
@dontknowyet75034 ай бұрын
i would like to also know what happens if local and entra ID password is different? whats happens when password is expired
@jonathang85715 ай бұрын
I noticed if I hit "dismiss" on the popup for enabling Company Portal to be used as a Passkey, I don't get the prompt again. There a way we could automatically permit this access?
@getrubix5 ай бұрын
I'll look into it.
@KJA0096 ай бұрын
Hey, Do you assign the SSO Config profile and Company Portal App to a group with the User or Device ?
@getrubix6 ай бұрын
Device group
@KJA0096 ай бұрын
@@getrubix So you add the device to the group once its enrolled or can you create a dynamic group, similar to the ones we use for AP (Group Tags?).
@sneeziaz6 ай бұрын
@@getrubix In the documentation it says: In Assignments, select the users or user groups that will receive your profile. Platform SSO policies are user-based policies. Don't assign the platform SSO policy to devices.
@KJA0096 ай бұрын
Confirmed.. switched to user groups and it's all working.. Thanks
@jmanuelng7 ай бұрын
Compadre!! Thumbs up before even seeing the video 👍👍👍👍
@getrubix7 ай бұрын
Thanks!
@Kvikku7 ай бұрын
Were you able to sign into the Mac with your Entra credentials instead of the local account?
@sivaram11227 ай бұрын
You have to select credentials in your platform sso MDM profile instead of security enclave.
@getrubix7 ай бұрын
Is that to avoid the local password first? My understanding is the first password will be local, until the Company Portal reg- please let me know!
@sivaram11227 ай бұрын
@@getrubix it's a local password first and after company portal + platform sso profile it will ask you to register your entra credential. If you choose authendication method to password then your entra password sync with your mac local account. If you select security enclave then you need to use local password to login. But your sso will work after you sign in to mac.
@sivaram11227 ай бұрын
Yes first password is a local one and CP + PSSO MDM policy sync entra password to mac login profile after.
@ezmonet76187 ай бұрын
When I enable Extension Identifier, I do not have the Type option.
@getrubix7 ай бұрын
Type should be automatically selected from the catalog when selecting 'Extension Identifier'
@mani2care7 ай бұрын
How to do using the JAMF with mac device
@jmanuelng2 ай бұрын
Anyone using "Managed AppleID" federated with Entra? Pros? Cons? Comments?
@SeanJackson-zb1gb6 ай бұрын
Hey anybody know how to get the same working with JAMF pro instead of Intune. Any help would be greatly appreciated. Thanks
@getrubix6 ай бұрын
Sorry, I don't know much about JAMF.
@excusetheblood5 ай бұрын
Microsoft Platform SSO doesn't work with Jamf Pro yet. Microsoft is in the process of adding other MDM's besides Intune but nothing yet, it has to be Intune. Could look into Jamf Connect though, same functionality. More, in fact.
@ToTCaMbIu7 ай бұрын
My client has OKTA as the primary IDP synced to EntraID (don't ask why). I'm still trying to figure out if OKTA supports this.
@getrubix7 ай бұрын
Not sure, to be honest. I would think based on the auth flow that Entra ID needs to be the IDP, but could be wrong.
@dc93-v4s6 ай бұрын
@@getrubix If M365 is federated with Okta, the Microsoft login will appear, but once it picks up the email of a federated account, it will redirect to that IdP, in this case Okta for authentication and then return back to finish the enrollment.
@seankearney70706 ай бұрын
I'm guessing there's no support to do this retroactivity for existing user accounts already configured on the Mac. It's a great start but the additional user steps required once logged in don't make it nearly as streamlined as Autopilot, and definitely something that will be misunderstood during employee onboarding. I'm just moaning at this point, but having the ability to add devices to ABM without wiping and via Apple Config (or purchasing through Apple Business) is long overdue.
@getrubix6 ай бұрын
I agree (and I do plenty of moaning, so no worries). The bit about having to do the post sign in steps on first enrollment are definitely not as smooth as Autopilot, but this is just a first pass and I'm sure this will be addressed. You should be able to deploy platform SSO to current Mac devices as long as they're enrolled with Intune.
@seankearney70706 ай бұрын
I haven’t had a chance to do my own deployment yet. Do you know how you sync up the local user with EntraID? I’m assuming that it will just link the currently logged in account used to authenticate the company portal. Just wondering what happens with a mismatch between the UPN and local account name where we have say amyw as the local account name, but their Microsoft UPN starts as Amy.White@