Workspace ONE UEM integrates with Entra ID platform from Microsoft, as a device compliance partner, to use endpoint compliance and management status to assess risk and enforce conditional access policies. To enable and enforce the conditional access policies, Workspace ONE uses AAD, a command utility tool, for registering macOS devices with Entra. This tool is bundled in macOS Intelligent Hub. For more information, see Conditional Access Using Microsoft Entra ID.
Microsoft has announced a transition for Microsoft Entra ID from Apple's Keychain to Apple's Secure Enclave for storing device identity keys. All new device registrations will use Secure Enclave by default. Existing devices without Secure Enclave will store registration keys in the user's Keychain (not the old Login Keychain), with current functionality staying the same. Applications that use Keychain for Microsoft Entra devices must update to MSAL and the Enterprise SSO plug-in to work with the Microsoft Identity Platform. For more details, see Microsoft Enterprise SSO plug-in for Apple devices. As a result, the older registration with AAD tool is being deprecated in favor of Platform SSO and modern enrollment methods. Intune Company Portal provides a single app for enrollment, compliance, and app access. Intune Company Portal (ICP)-based registration can integrate tightly with Workspace ONE UEM and Conditional Access policies, ensuring devices meet compliance before granting access.
With macOS Hub 25.11, Workspace ONE is aligning with Microsoft’s strategy to adopt modern identity and endpoint management standards by transitioning device registration and compliance workflows to leverage Microsoft Entra ID through Intune Company Portal.
Support for Conditional Access through Hub
To ensure Workspace ONE remains fully compatible with Microsoft Conditional Access and enforces policies seamlessly (such as device compliance and application-based restrictions), it's essential to adopt Secure Enclave-based device identity. To do this, we have updated the Intelligent Hub for macOS version 25.11 to support Secure Enclave-based identity keys for Microsoft Entra ID. To support this capability, the Microsoft Enterprise SSO Plug-in application(Intune Company Portal App) must be installed on the device, as it registers devices with Entra ID and securely stores the identity in the Secure Enclave.
Requirements
- Your Workspace ONE UEM and Microsoft Entra Identity Provider are integrated
- Workspace ONE UEM version 24.10 or later
- macOS Intelligent Hub app version 25.11 or later
- macOS version 14 (Sonoma), 15 (Sequoia), or 26 (Tahoe)
Determine Authentication methods
For enabling Platform SSO with Microsoft Entra ID, required for device registration via Intune Company Portal, you can select between the following authentication methods:
- Secure Enclave key (recommended): This method uses a Secure Enclave backend key for SSO across apps that authenticate with Microsoft’s Entra ID. The user’s local account password remains unchanged and is required for Mac sign-in.
- Password: This method syncs the user’s Microsoft Entra ID password with the local account, enabling SSO across apps that use Microsoft Entra ID for authentication.
Configuring Device Registration and Compliance with Entra ID using Intune Company Portal
Review the Best Practices before configuring requirements for device registration and compliance with Intune Company Portal.
Steps for enabling Conditional Access policy enforcement with Intune Company Portal:
- Enable Feature Flag for Device Registration and Compliance with Entra ID via Intune Company Portal
- Configure a platform single sign-on configuration profile
- Deploy the Intune Company Portal app
Enable Feature Flag for Device Registration and Compliance with Entra ID via Intune Company Portal
Create a custom profile to enable the feature flag - MacOSConditionalAccessUsingCompanyPortalFeatureFlag.
- Navigate to Resources > Profiles & Baselines > Profiles > Add > Add a new device profile.
- In Custom Profile, add Custom Settings as below:
<dict>
<key>FeatureFlags</key>
<dict>
<key>MacOSConditionalAccessUsingCompanyPortalFeatureFlag</key>
<true/>
</dict>
<key>PayloadDisplayName</key>
<string>Intelligent Hub</string>
<key>PayloadIdentifier</key>
<string>Omnissa.4cbaf201-d741-44c6-889c-efb283df4ae9.HubSettings.93f1655a-59fb-42dc-bc31-9571275cb12b</string>
<key>PayloadOrganization</key>
<string></string>
<key>PayloadType</key>
<string>com.ws1.hub.mac</string>
<key>PayloadUUID</key>
<string>1D7F0D17-369B-4766-9CA0-D2B4537657C1</string>
<key>PayloadVersion</key>
<integer>1</integer>
</dict>
For more information on Custom Profiles, see Custom Settings Profiles.
Configuring a Platform Single Sign-On configuration profile
After you have determined the authentication method for your users, the next step is to deploy a configuration profile to devices to enable Platform Single Sign-On with Microsoft Entra ID. The profile includes both the SSO Extension and System Extensions payloads.
Configure an SSO Extension and System Extension Profile
To enable SSO for native macOS apps and websites with various authentication methods, configure the SSO Extension profile with the Generic extension type. This profile is applicable only to macOS 10.15 and later.
-
Navigate to Resources > Profiles & Baselines > Profiles and select Add. Select Apple macOS, and then select Device Profile to apply the profile only to the device's enrollment user or to the entire device.
-
Configure the profile's General settings.
-
Select the SSO Extension payload.
-
Configure the profile settings. For more information, see Configure an SSO extension profile.

Use the configuration options below:
Setting Description Extension Type Select Generic. If Generic is selected, provide the Bundle ID of the application extension that performs the SSO for the specified URLs in the Extension Identifier text box. Type Select Redirect. Team Identifier UBF8T346G9 Extension Identifier com.microsoft.CompanyPortalMac.ssoextensionURLs Authentication Method (macOS 13) Depending on your decision for authentication method, select Password or Secure Enclave Authentication method Set this value same as the above. -
Enter the remaining SSO Extension settings according to your requirements.
-
Select Save and Publish.
Configure System Extension Profile
Configure System Extensions to explicitly allow applications and installers that use system extensions to load on your end users’ devices.
- Navigate to Resources > Profiles & Baselines > Profiles and select Add. Select Apple macOS, and then select Device Profile to apply the profile only to the device's enrollment user or to the entire device.
- Configure the profile's General settings.
- Select the System Extension payload.
Below are the configuration options you can use. For other configuration options, see Configure System Extension Profile
| Settings | Descriptions |
|---|---|
| Use Shared Device Keys | Enable this option when the User Secure Enclave Key authentication method is used to avoid triggering unnecessary re-registration. |
| Whitelisting of the SSO extension | com.microsoft.CompanyPortalMac.ssoextension |
| Team Identifier | UBF8T346G9 |

- Select Save and Publish.
Deploy Intune Company Portal
Add Intune Company Portal as an internal application in UEM. For more details on adding apps, go to Deploy Internal macOS Applications. To get the Inutne Company portal app, refer to Microsoft documentation.
User Experience
The process of enabling platform SSO with Microsoft Entra and setting up device compliance through the Intune Company Portal can vary slightly for users, depending on which authentication method is used.
Using Password as an authentication method
If Password is the authentication method, the user’s Entra ID password is synchronized with the local account password on the macOS device. This allows users to log in to their devices and access Microsoft applications using their Entra ID credentials.
The following steps outline the process for deploying Platform SSO using the password authentication method:
-
Enroll your device.
Once your device is successfully enrolled, based on the assignments, device receives the profile and Intune Company Portal Application.
-
Look for the registration notification.
You will receive an operating system notification prompting you to complete the registration process. Click Register.

-
Start Platform Single Sign-on registration. In the registration window, click Continue to proceed.

-
Enter your macOS device password and click Unlock.

-
Enter your Identity Provider (IDP) credentials.
When prompted, enter your IDP password. This action initiates the following steps:
-
Provide your Microsoft Entra ID password.

-
Provide your Entra ID password to sync with your macOS password.

-
Selecting Entra ID account. At this stage, Hub prompts you to choose the Entra ID account, which enables device compliance using Intune Company Portal.

-
-
Confirm successful registration.
Once your Platform SSO registration is finished, you’ll get a device registration confirmation message.

-
Verify Platform SSO Extension is enabled and your device is registered with the IDP. Navigate to System Settings > Users and Groups > Network Account Server > Edit.

-
Access Microsoft applications.
You can now seamlessly sign in to Microsoft applications and websites without needing to re-enter your credentials.
Deploying PSSO using Secure Enclave as an authentication method
The Secure Enclave method streamlines your login process by generating a unique secure key during synchronization. This key facilitates seamless logins, as your identity is verified using this secure key rather than your Entra ID password directly. When utilizing this method, use your macOS password for device login, as the local and IDP credentials are not synchronized.
Steps to Configure Platform Single Sign-On with Secure Enclave authentication:
-
Look for the registration notification.
You will receive an operating system notification prompting you to complete the registration process. Click Register.

-
Platform Single Sign-On (SSO) initiates. Click Continue to proceed.

-
Enter your macOS password and click Unlock.

-
Provide your Entra ID password.

-
Allow Intune Company Portal to autofill your passkey. As Secure Enclave authentication method is selected, the user will be prompted to allow Company Portal to autofill the passkeys when accessing applications and browsers.

a. Enable Intune Company Portal in Settings.
Navigate to your device's settings path in General > Autofill and Passwords > Autofill form > Enable Company Portal and ensure that Intune Company Portal is enabled.
b. Confirm passkey configuration.
You should receive a notification or message confirming that the passkey for your school or work account has been successfully configured.

-
Choose Entra ID account, which is used to contact Intune Company Portal and obtain the necessary token. Click Continue.

-
You will receive a notification indicating that your Microsoft account is now connected to Intelligent Hub, and device registration is successful.

-
Verify Platform SSO Extension is enabled and your device is registered with the IDP. Navigate to System Settings > Users and Groups > Network Account Server > Edit.

Upon successful configuration, you can launch any Microsoft application without needing to enter a password or key, leveraging the seamless authentication provided by the Secure Enclave method.
Best Practices
This section covers guidance for users who are deciding to move to the Intune Company Portal (ICP)–based Conditional Access flow. The table below is designed to help you understand if your business case and transition plan is supported and recommended. It also provides details on the setup required and the changes you can expect for better planning.
| Present Usecase | Required Usecase (with Hub 25.11 Upgrade) | Supported? | Setup required | Expected experience change | Recommendation |
|---|---|---|---|---|---|
| Devices have Conditional Access enabled using AAD tool | Want Device registration and compliance (Conditional Access) managed with Intune Company Portal | Yes | See Managing Device registration and compliance (Conditional Access) with Intune Company Portal |
| Strongly Recommended |
| Devices have Conditional Access enabled using AAD tool | Want to continue using device registration and compliance (Conditional Access) managed with AAD tool | Yes | No Setup is required.Configuring Device Registration and Compliance with Entra ID using Intune Company Portal is not applicable for this use case | None. Device registration and compliance (Conditional Access) work seamlesly post upgrade | Not recommended. This will be de-supported soon, after official announcement is made. |
| Devices have Conditional Access enabled using AAD tool | Want to enable devices with PSSO with Entra ID AND continue managing compliance (Conditional Access) with AAD tool | No | NA | NA | Not Supported |
| No Conditional Access enabled on device OR Devices not enrolled | Want to enable devices with PSSO with Entra ID AND enable compliance (Conditional Access) with AAD tool | No | NA | NA | Not supported |
| No Conditional Access enabled on device OR Devices not enrolled | Want Device compliance (Conditional Access) managed with Intune Company Portal | Yes | See Managing Device registration and compliance (Conditional Access) with Intune Company Portal |
| Recommended |
| No Conditional Access enabled on device OR Devices not enrolled | Want Device compliance (Conditional Access) managed with Intune Company Portal BUT do not want to enable devices with PSSO with Entra ID | No | NA | NA | Not Supported |
| No Conditional Access enabled on device OR Devices not enrolled OR devices don’t have Intelligent Hub deployed | Do not want Device registration and compliance (Conditional Access) managed with Intune Company Portal or AAD tool | Yes | No Setup is required. Configuring Device Registration and Compliance with Entra ID using Intune Company Portal is not applicable for this use case | None | No recommendation |
| No Conditional Access enabled on device OR Devices not enrolled | Want to enable devices with PSSO with Entra ID BUT Do not want Device compliance (Conditional Access) managed with Intune Company Portal or AAD tool | Yes |
|
| No recommendation |
| Devices not enrolled | Want to use device registration and compliance (Conditional Access) managed with AAD tool | Yes | Refer Conditional Access Using Microsoft Entra ID | User will need to use deeplink to Register device registration in Entra created by AAD tool | Not recommended. This will no longer be supported in the near future. |
Managing Device registration and compliance (Conditional Access) with Intune Company Portal
- Add a Custom Setting profile to enable the feature flag,
MacOSConditionalAccessUsingCompanyPortalFeatureFlag. See Enable Feature Flag for Device Registration and Compliance with Entra ID via Intune Company Portal. - Add Intune Company Portal application as an Internal Application. See Deploy Intune Company Portal
- Add the SSO Extension and System Extension profile. See Configuring a platform single sign-on configuration profile
- Add the sensor (below) to check if the device is at macOS Hub 25.11 or later. This is required so that device registration and compliance with Intune Company Portal is only made available to the devices that are only macOS Hub 25.11 or later and also to prevent the existing registration using AAD tool from breaking. This sensor should be used until the desired device group is upgraded to macOS Hub 25.11 or later.
#!/bin/bash
APP_PATH="/Applications/Workspace ONE Intelligent Hub.app"
INFO_PLIST="$APP_PATH/Contents/Info.plist"
MIN_VERSION="25.11.0"
# Read the version from Info.plist
APP_VERSION=$(/usr/bin/defaults read "$INFO_PLIST" CFBundleShortVersionString 2>/dev/null)
if [ -z "$APP_VERSION" ]; then
echo "Unable to read Hub version."
exit 1
fi
# Function for version comparison
version_ge() {
# returns true if $1 >= $2
[ "$(printf '%s\n%s' "$2" "$1" | sort -V | head -n1)" = "$2" ]
}
# Check version
if version_ge "$APP_VERSION" "$MIN_VERSION"; then
echo "Workspace One Intelligent Hub is COMPATIBLE for ICP registration"
else
echo "The current Workspace One Intelligent Hub version : $APP_VERSION is NOT COMPATIBLE for ICP registration"
fi
- (Optional but Strongly Recommended) Deploy the resources above via workflow. Add a workflow to deploy the components in a specific order.
a. Add the sensor (in Step 4 above) as a condition to check if the output equals Workspace One Intelligent Hub is COMPATIBLE for ICP registration
b. If yes, add the below actions
- Custom Setting profile (Step 1 above)
- Intune Company Portal application(Step 2 above)
- SSO and System extension profile (Step 3 above)
c. If not, then the workflow runs at the next sample interval.
- (Optional) Add script to verify PSSO registration status.
Add this script to get the Platform SSO (PSSO) registration status for the current console user. This helps track if the user has completed device registration.
#!/usr/bin/env bash
# Copyright © Omnissa, LLC. All rights reserved.
# Check Platform SSO (PSSO) registration for the current console user
# - Uses strict mode and pipefail to correctly capture errors in pipelines
# - Provides clear XML <result> output for integrations (Jamf/MDM/etc.)
# - Accepts optional username argument for testing
# - Logs errors to stderr and returns meaningful exit codes
set -euo pipefail
IFS=$'\n\t'
prog_name="$(basename "$0")"
# Print to stderr for diagnostics
log_err() {
printf '%s: %s\n' "$prog_name" "$1" >&2
}
# Print XML result to stdout (keeps single-line result for MDM)
print_result() {
printf '%s\n' "<result>$1</result>"
}
# Usage helper
usage() {
cat <<EOF
Usage: $prog_name [optional_username]
If no username is provided the script will detect the current ConsoleUser.
EOF
}
# Trap unexpected errors
trap 'log_err "An unexpected error occurred."; exit 2' ERR
# Allow optional username (useful for testing)
if [[ ${#@} -gt 1 ]]; then
usage
exit 1
fi
if [[ ${#@} -eq 1 ]]; then
currentUser="$1"
else
# Detect the logged-in console user (excluding loginwindow)
currentUser=$(/usr/sbin/scutil <<< "show State:/Users/ConsoleUser" \
| /usr/bin/awk -F': ' '/[[:space:]]+Name[[:space:]]:/ { if ($2 != "loginwindow") print $2 }' \
|| true)
# If empty, no user is logged in
if [[ -z "$currentUser" ]]; then
print_result "No user logged in"
exit 0
fi
fi
# Read the AltSecurityIdentities attribute and extract PlatformSSO (PSSO) value
# Use set -o pipefail above so failures in either dscl or awk are captured
pssoe_status=$(/usr/bin/dscl . -read "/Users/$currentUser" dsAttrTypeStandard:AltSecurityIdentities 2>/dev/null \
| /usr/bin/awk -F'SSO:' '/PlatformSSO/ { gsub(/^[[:space:]]+|[[:space:]]+$/, "", $2); print $2 }' \
|| true)
# If dscl failed (no such user or other error) then pssoe_status will be empty.
# But we can explicitly check whether the user exists first to give a clearer message.
if ! /usr/bin/id -u "$currentUser" >/dev/null 2>&1; then
print_result "User $currentUser not found"
exit 1
fi
# Determine and print the final result
if [[ -z "$pssoe_status" ]]; then
print_result "No PSSO registration found for $currentUser"
exit 0
else
# pssoe_status may contain the Entra/SSO identifier; include it verbatim
print_result "Yes, Entra ID account $pssoe_status registered to $currentUser"
exit 0
fi
Was this page helpful?