Skip to main content

August 26, 2026

Platform SSO and Device Compliance With Entra ID using Intune Company Portal

Workspace ONE UEM integrates with Entra ID platform from Microsoft, as a device compliance partner, to use endpoint compliance and management status to assess risk and enforce conditional access policies. To enable and enforce the conditional access policies, Workspace ONE uses AAD, a command utility tool, for registering macOS devices with Entra. This tool is bundled in macOS Intelligent Hub. For more information, see Conditional Access Using Microsoft Entra ID.

Microsoft has announced a transition for Microsoft Entra ID from Apple's Keychain to Apple's Secure Enclave for storing device identity keys. All new device registrations will use Secure Enclave by default. Existing devices without Secure Enclave will store registration keys in the user's Keychain (not the old Login Keychain), with current functionality staying the same. Applications that use Keychain for Microsoft Entra devices must update to MSAL and the Enterprise SSO plug-in to work with the Microsoft Identity Platform. For more details, see Microsoft Enterprise SSO plug-in for Apple devices. As a result, the older registration with AAD tool is being deprecated in favor of Platform SSO and modern enrollment methods. Intune Company Portal provides a single app for enrollment, compliance, and app access. Intune Company Portal (ICP)-based registration can integrate tightly with Workspace ONE UEM and Conditional Access policies, ensuring devices meet compliance before granting access.

With macOS Hub 25.11, Workspace ONE is aligning with Microsoft’s strategy to adopt modern identity and endpoint management standards by transitioning device registration and compliance workflows to leverage Microsoft Entra ID through Intune Company Portal.

Support for Conditional Access through Hub

To ensure Workspace ONE remains fully compatible with Microsoft Conditional Access and enforces policies seamlessly (such as device compliance and application-based restrictions), it's essential to adopt Secure Enclave-based device identity. To do this, we have updated the Intelligent Hub for macOS version 25.11 to support Secure Enclave-based identity keys for Microsoft Entra ID. To support this capability, the Microsoft Enterprise SSO Plug-in application(Intune Company Portal App) must be installed on the device, as it registers devices with Entra ID and securely stores the identity in the Secure Enclave.

Requirements

  • Your Workspace ONE UEM and Microsoft Entra Identity Provider are integrated
  • Workspace ONE UEM version 24.10 or later
  • macOS Intelligent Hub app version 25.11 or later
  • macOS version 14 (Sonoma), 15 (Sequoia), or 26 (Tahoe)

Determine Authentication methods

For enabling Platform SSO with Microsoft Entra ID, required for device registration via Intune Company Portal, you can select between the following authentication methods:

  • Secure Enclave key (recommended): This method uses a Secure Enclave backend key for SSO across apps that authenticate with Microsoft’s Entra ID. The user’s local account password remains unchanged and is required for Mac sign-in.
  • Password: This method syncs the user’s Microsoft Entra ID password with the local account, enabling SSO across apps that use Microsoft Entra ID for authentication.

Configuring Device Registration and Compliance with Entra ID using Intune Company Portal

Review the Best Practices before configuring requirements for device registration and compliance with Intune Company Portal.

Steps for enabling Conditional Access policy enforcement with Intune Company Portal:

  1. Enable Feature Flag for Device Registration and Compliance with Entra ID via Intune Company Portal
  2. Configure a platform single sign-on configuration profile
  3. Deploy the Intune Company Portal app

Enable Feature Flag for Device Registration and Compliance with Entra ID via Intune Company Portal

Create a custom profile to enable the feature flag - MacOSConditionalAccessUsingCompanyPortalFeatureFlag.

  1. Navigate to Resources > Profiles & Baselines > Profiles > Add > Add a new device profile.
  2. In Custom Profile, add Custom Settings as below:
<dict>
	<key>FeatureFlags</key>
	<dict>
		<key>MacOSConditionalAccessUsingCompanyPortalFeatureFlag</key>
		<true/>
	</dict>
	<key>PayloadDisplayName</key>
	<string>Intelligent Hub</string>
	<key>PayloadIdentifier</key>
	<string>Omnissa.4cbaf201-d741-44c6-889c-efb283df4ae9.HubSettings.93f1655a-59fb-42dc-bc31-9571275cb12b</string>
	<key>PayloadOrganization</key>
	<string></string>
	<key>PayloadType</key>
	<string>com.ws1.hub.mac</string>
	<key>PayloadUUID</key>
	<string>1D7F0D17-369B-4766-9CA0-D2B4537657C1</string>
	<key>PayloadVersion</key>
	<integer>1</integer>
</dict>

For more information on Custom Profiles, see Custom Settings Profiles.

Configuring a Platform Single Sign-On configuration profile

After you have determined the authentication method for your users, the next step is to deploy a configuration profile to devices to enable Platform Single Sign-On with Microsoft Entra ID. The profile includes both the SSO Extension and System Extensions payloads.

Configure an SSO Extension and System Extension Profile

To enable SSO for native macOS apps and websites with various authentication methods, configure the SSO Extension profile with the Generic extension type. This profile is applicable only to macOS 10.15 and later.

  1. Navigate to Resources > Profiles & Baselines > Profiles and select Add. Select Apple macOS, and then select Device Profile to apply the profile only to the device's enrollment user or to the entire device.

  2. Configure the profile's General settings.

  3. Select the SSO Extension payload.

  4. Configure the profile settings. For more information, see Configure an SSO extension profile.

    The SSO extension payload displays option to configure Platform SSO extensions for specific apps

    Use the configuration options below:

    SettingDescription
    Extension TypeSelect Generic. If Generic is selected, provide the Bundle ID of the application extension that performs the SSO for the specified URLs in the Extension Identifier text box.
    TypeSelect Redirect.
    Team IdentifierUBF8T346G9
    Extension Identifiercom.microsoft.CompanyPortalMac.ssoextension
    URLs
    Authentication Method (macOS 13)Depending on your decision for authentication method, select Password or Secure Enclave
    Authentication methodSet this value same as the above.
  5. Enter the remaining SSO Extension settings according to your requirements.

  6. Select Save and Publish.

Configure System Extension Profile

Configure System Extensions to explicitly allow applications and installers that use system extensions to load on your end users’ devices.

  1. Navigate to Resources > Profiles & Baselines > Profiles and select Add. Select Apple macOS, and then select Device Profile to apply the profile only to the device's enrollment user or to the entire device.
  2. Configure the profile's General settings.
  3. Select the System Extension payload.

Below are the configuration options you can use. For other configuration options, see Configure System Extension Profile

SettingsDescriptions
Use Shared Device KeysEnable this option when the User Secure Enclave Key authentication method is used to avoid triggering unnecessary re-registration.
Whitelisting of the SSO extensioncom.microsoft.CompanyPortalMac.ssoextension
Team IdentifierUBF8T346G9

The system extension payload displays options to control extensions and restrictions for system extensions

  1. Select Save and Publish.

Deploy Intune Company Portal

Add Intune Company Portal as an internal application in UEM. For more details on adding apps, go to Deploy Internal macOS Applications. To get the Inutne Company portal app, refer to Microsoft documentation.

User Experience

The process of enabling platform SSO with Microsoft Entra and setting up device compliance through the Intune Company Portal can vary slightly for users, depending on which authentication method is used.

Using Password as an authentication method

If Password is the authentication method, the user’s Entra ID password is synchronized with the local account password on the macOS device. This allows users to log in to their devices and access Microsoft applications using their Entra ID credentials.

The following steps outline the process for deploying Platform SSO using the password authentication method:

  1. Enroll your device.

    Once your device is successfully enrolled, based on the assignments, device receives the profile and Intune Company Portal Application.

  2. Look for the registration notification.

    You will receive an operating system notification prompting you to complete the registration process. Click Register.

    OS notification

  3. Start Platform Single Sign-on registration. In the registration window, click Continue to proceed.

    PSSO registration

  4. Enter your macOS device password and click Unlock.

    Password sync

  5. Enter your Identity Provider (IDP) credentials.

    When prompted, enter your IDP password. This action initiates the following steps:

    • Provide your Microsoft Entra ID password.

      Entra ID registration

    • Provide your Entra ID password to sync with your macOS password.

      Sync macOS password with Entra id password

    • Selecting Entra ID account. At this stage, Hub prompts you to choose the Entra ID account, which enables device compliance using Intune Company Portal.

      Hub

  6. Confirm successful registration.

    Once your Platform SSO registration is finished, you’ll get a device registration confirmation message.

    Device registration successful message

  7. Verify Platform SSO Extension is enabled and your device is registered with the IDP. Navigate to System Settings > Users and Groups > Network Account Server > Edit.

    PSSO confirmation

  8. Access Microsoft applications.

    You can now seamlessly sign in to Microsoft applications and websites without needing to re-enter your credentials.

Deploying PSSO using Secure Enclave as an authentication method

The Secure Enclave method streamlines your login process by generating a unique secure key during synchronization. This key facilitates seamless logins, as your identity is verified using this secure key rather than your Entra ID password directly. When utilizing this method, use your macOS password for device login, as the local and IDP credentials are not synchronized.

Steps to Configure Platform Single Sign-On with Secure Enclave authentication:

  1. Look for the registration notification.

    You will receive an operating system notification prompting you to complete the registration process. Click Register.

    OS notification

  2. Platform Single Sign-On (SSO) initiates. Click Continue to proceed.

PSSO registration

  1. Enter your macOS password and click Unlock.

    Password sync

  2. Provide your Entra ID password.

    Entra ID registration

  3. Allow Intune Company Portal to autofill your passkey. As Secure Enclave authentication method is selected, the user will be prompted to allow Company Portal to autofill the passkeys when accessing applications and browsers.

ICP

a. Enable Intune Company Portal in Settings.

Navigate to your device's settings path in General > Autofill and Passwords > Autofill form > Enable Company Portal and ensure that Intune Company Portal is enabled.

b. Confirm passkey configuration.

You should receive a notification or message confirming that the passkey for your school or work account has been successfully configured.

Passkey configuration

  1. Choose Entra ID account, which is used to contact Intune Company Portal and obtain the necessary token. Click Continue.

    Sign into Hub

  2. You will receive a notification indicating that your Microsoft account is now connected to Intelligent Hub, and device registration is successful.

    Device registration

  3. Verify Platform SSO Extension is enabled and your device is registered with the IDP. Navigate to System Settings > Users and Groups > Network Account Server > Edit.

    PSSO confirmation

    Upon successful configuration, you can launch any Microsoft application without needing to enter a password or key, leveraging the seamless authentication provided by the Secure Enclave method.

Best Practices

This section covers guidance for users who are deciding to move to the Intune Company Portal (ICP)–based Conditional Access flow. The table below is designed to help you understand if your business case and transition plan is supported and recommended. It also provides details on the setup required and the changes you can expect for better planning.

Present UsecaseRequired Usecase (with Hub 25.11 Upgrade)Supported?Setup requiredExpected experience changeRecommendation
Devices have Conditional Access enabled using AAD toolWant Device registration and compliance (Conditional Access) managed with Intune Company PortalYesSee Managing Device registration and compliance (Conditional Access) with Intune Company Portal
  • User should not use weblink/deeplink to register their device. It will not work.
  • User will be notified to complete the registration as listed in User Experience. This will also enable PSSO with Entra ID.
  • Existing device registration in Entra is silently updated to be managed by Intune Company Portal.
  • No change is required on Entra Portal
Strongly Recommended
Devices have Conditional Access enabled using AAD toolWant to continue using device registration and compliance (Conditional Access) managed with AAD toolYesNo Setup is required.Configuring Device Registration and Compliance with Entra ID using Intune Company Portal is not applicable for this use caseNone. Device registration and compliance (Conditional Access) work seamlesly post upgradeNot recommended. This will be de-supported soon, after official announcement is made.
Devices have Conditional Access enabled using AAD toolWant to enable devices with PSSO with Entra ID AND continue managing compliance (Conditional Access) with AAD toolNoNANANot Supported
No Conditional Access enabled on device OR Devices not enrolledWant to enable devices with PSSO with Entra ID AND enable compliance (Conditional Access) with AAD toolNoNANANot supported
No Conditional Access enabled on device OR Devices not enrolledWant Device compliance (Conditional Access) managed with Intune Company PortalYesSee Managing Device registration and compliance (Conditional Access) with Intune Company Portal
  • User will be notified to complete the registration as listed in User Experience.
  • This will enable PSSO with Entra ID.
  • New device registration is created in Entra to be managed by Intune Company Portal
Recommended
No Conditional Access enabled on device OR Devices not enrolledWant Device compliance (Conditional Access) managed with Intune Company Portal BUT do not want to enable devices with PSSO with Entra IDNoNANANot Supported
No Conditional Access enabled on device OR Devices not enrolled OR devices don’t have Intelligent Hub deployedDo not want Device registration and compliance (Conditional Access) managed with Intune Company Portal or AAD toolYesNo Setup is required. Configuring Device Registration and Compliance with Entra ID using Intune Company Portal is not applicable for this use caseNoneNo recommendation
No Conditional Access enabled on device OR Devices not enrolledWant to enable devices with PSSO with Entra ID BUT Do not want Device compliance (Conditional Access) managed with Intune Company Portal or AAD toolYes
  • User should not use weblink/deeplink to register their device. It wil not work.
  • User will be notified to complete the registration as listed in User Experience.
  • This will enable PSSO with Entra ID
No recommendation
Devices not enrolledWant to use device registration and compliance (Conditional Access) managed with AAD toolYesRefer Conditional Access Using Microsoft Entra IDUser will need to use deeplink to Register device registration in Entra created by AAD toolNot recommended. This will no longer be supported in the near future.

Managing Device registration and compliance (Conditional Access) with Intune Company Portal

  1. Add a Custom Setting profile to enable the feature flag, MacOSConditionalAccessUsingCompanyPortalFeatureFlag. See Enable Feature Flag for Device Registration and Compliance with Entra ID via Intune Company Portal.
  2. Add Intune Company Portal application as an Internal Application. See Deploy Intune Company Portal
  3. Add the SSO Extension and System Extension profile. See Configuring a platform single sign-on configuration profile
  4. Add the sensor (below) to check if the device is at macOS Hub 25.11 or later. This is required so that device registration and compliance with Intune Company Portal is only made available to the devices that are only macOS Hub 25.11 or later and also to prevent the existing registration using AAD tool from breaking. This sensor should be used until the desired device group is upgraded to macOS Hub 25.11 or later.
#!/bin/bash

APP_PATH="/Applications/Workspace ONE Intelligent Hub.app"
INFO_PLIST="$APP_PATH/Contents/Info.plist"
MIN_VERSION="25.11.0"

# Read the version from Info.plist
APP_VERSION=$(/usr/bin/defaults read "$INFO_PLIST" CFBundleShortVersionString 2>/dev/null)

if [ -z "$APP_VERSION" ]; then
    echo "Unable to read Hub version."
    exit 1
fi

# Function for version comparison
version_ge() {
    # returns true if $1 >= $2
    [ "$(printf '%s\n%s' "$2" "$1" | sort -V | head -n1)" = "$2" ]
}

# Check version
if version_ge "$APP_VERSION" "$MIN_VERSION"; then
    echo "Workspace One Intelligent Hub is COMPATIBLE for ICP registration"
else
    echo "The current Workspace One Intelligent Hub version : $APP_VERSION is NOT COMPATIBLE for ICP registration"
fi

  1. (Optional but Strongly Recommended) Deploy the resources above via workflow. Add a workflow to deploy the components in a specific order.

a. Add the sensor (in Step 4 above) as a condition to check if the output equals Workspace One Intelligent Hub is COMPATIBLE for ICP registration

b. If yes, add the below actions

  • Custom Setting profile (Step 1 above)
  • Intune Company Portal application(Step 2 above)
  • SSO and System extension profile (Step 3 above)

c. If not, then the workflow runs at the next sample interval.

  1. (Optional) Add script to verify PSSO registration status.

Add this script to get the Platform SSO (PSSO) registration status for the current console user. This helps track if the user has completed device registration.

#!/usr/bin/env bash
# Copyright © Omnissa, LLC. All rights reserved.
# Check Platform SSO (PSSO) registration for the current console user
# - Uses strict mode and pipefail to correctly capture errors in pipelines
# - Provides clear XML <result> output for integrations (Jamf/MDM/etc.)
# - Accepts optional username argument for testing
# - Logs errors to stderr and returns meaningful exit codes
set -euo pipefail
IFS=$'\n\t'
prog_name="$(basename "$0")"
# Print to stderr for diagnostics
log_err() {
    printf '%s: %s\n' "$prog_name" "$1" >&2
}
# Print XML result to stdout (keeps single-line result for MDM)
print_result() {
    printf '%s\n' "<result>$1</result>"
}
# Usage helper
usage() {
    cat <<EOF
Usage: $prog_name [optional_username]
If no username is provided the script will detect the current ConsoleUser.
EOF
}
# Trap unexpected errors
trap 'log_err "An unexpected error occurred."; exit 2' ERR
# Allow optional username (useful for testing)
if [[ ${#@} -gt 1 ]]; then
    usage
    exit 1
fi
if [[ ${#@} -eq 1 ]]; then
    currentUser="$1"
else
    # Detect the logged-in console user (excluding loginwindow)
    currentUser=$(/usr/sbin/scutil <<< "show State:/Users/ConsoleUser" \
        | /usr/bin/awk -F': ' '/[[:space:]]+Name[[:space:]]:/ { if ($2 != "loginwindow") print $2 }' \
        || true)
    # If empty, no user is logged in
    if [[ -z "$currentUser" ]]; then
        print_result "No user logged in"
        exit 0
    fi
fi
# Read the AltSecurityIdentities attribute and extract PlatformSSO (PSSO) value
# Use set -o pipefail above so failures in either dscl or awk are captured
pssoe_status=$(/usr/bin/dscl . -read "/Users/$currentUser" dsAttrTypeStandard:AltSecurityIdentities 2>/dev/null \
    | /usr/bin/awk -F'SSO:' '/PlatformSSO/ { gsub(/^[[:space:]]+|[[:space:]]+$/, "", $2); print $2 }' \
    || true)
# If dscl failed (no such user or other error) then pssoe_status will be empty.
# But we can explicitly check whether the user exists first to give a clearer message.
if ! /usr/bin/id -u "$currentUser" >/dev/null 2>&1; then
    print_result "User $currentUser not found"
    exit 1
fi
# Determine and print the final result
if [[ -z "$pssoe_status" ]]; then
    print_result "No PSSO registration found for $currentUser"
    exit 0
else
    # pssoe_status may contain the Entra/SSO identifier; include it verbatim
    print_result "Yes, Entra ID account $pssoe_status registered to $currentUser"
    exit 0
fi

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…