Skip to main content

August 26, 2026

Configure Platform SSO in Setup Assistant

Platform Single Sign-On (PSSO) reduces repeated credential prompts by completing registration during the macOS Setup Assistant for devices enrolled through Automated Device Enrollment (ADE). By configuring PSSO during ADE, users authenticate with their corporate Identity Provider (IdP) before reaching the desktop. This process creates a local macOS account which maps to the user's IdP identity, ensuring the device is in an SSO-ready state immediately after provisioning.

Supported Identity Providers

  • Omnissa Access
  • Microsoft Entra ID
  • Okta

Authentication methods

  • Password Synchronization: Traditional authentication where the user enters their IdP username and password, which is synchronized with the macOS local account password.
  • Secure Enclave key authentication (Recommended): Hardware-backed cryptographic authentication. Requires Touch ID (Apple Silicon or Intel Mac with Touch ID).

Prerequisites

  • Devices must run macOS 26 or later.
  • Workspace ONE UEM 2604 or later is required for Access Microsoft Entra ID and Okta as Identity Provider (IdP).
  • Workspace ONE Access 26.07 and Hub 26.06.
  • The Identity Provider (IdP) application required for authentication — such as Workspace ONE Intelligent Hub for Workspace ONE Access, Microsoft Company Portal for Entra ID, or Okta Verify for Okta — must be present and managed within Workspace ONE UEM.
  • An SSO Extension profile must be configured and assigned to the target Smart Group. For more information, see Configure an SSO Extension Profile.

Procedure

Step 1: Configure a PSSO Profile

Step 2: Enable PSSO in the ADE Profile

  1. In the Workspace ONE UEM console, navigate to Settings > Apple > Automated Enrollment.
  2. Select Add Profile to create a new ADE profile, or select an existing profile to edit.
  3. In the Onboarding section, enable the Await Configuration and PSSO during Setup Assistant setting.

PSSO during Setup Assistant option in the Onboarding section

  1. From the drop-down menu, select the appropriate PSSO profile (the SSO Extension profile that you have created in Step 1).
  2. From the drop-down menu, select the corresponding PSSO Extension application (Intelligent Hub, Company Portal, or Okta Verify).
  3. Select Save to apply the configuration.
  4. On the Automated Device Enrollment page, under the Profiles section, set the default macOS enrollment profile to the profile that includes both the Platform SSO profile and the PSSO Extension app.

User Experience during Setup Assistant

You can now integrate SSO registration directly into the Setup Assistant. From the moment a user powers on a new corporate device, SSO registration is already part of the experience, with no additional IT intervention required afterward.

During onboarding, the end-to-end experience proceeds as follows:

  1. Power On the device. The macOS Setup Assistant launches and guides you through the standard initial screens.
  2. Tap Enroll to complete ADE enrollment.
  3. In the Single Sign-On for Mac prompt, click Continue.

Single Sign On page

  1. On the IdP login screen, sign in with your corporate IdP credentials.

Upon successful authentication, the IdP generates an identity token and passes it to the Platform SSO extension on the device. This token forms the basis of your SSO session and does not require any action on your part.

  1. (Secure Enclave authentication only) Create a local macOS account password.

Because Secure Enclave authentication is hardware-bound, you are prompted to set a local macOS account password. You can use the same password as your IdP credentials for convenience. This password secures the local account and unlocks the Secure Enclave key.

Option to create a local macOS account Password

  1. Local macOS account is provisioned automatically.

macOS creates a local account permanently mapped to your IdP identity, giving you a single unified account — no separate macOS login distinct from your corporate identity.

  1. (Secure Enclave authentication only) Click Set up Touch ID to enroll your fingerprint.

When prompted, enroll your fingerprint to activate the Secure Enclave key. This enables hardware-backed authentication and eliminates password prompts for subsequent logins and application access.

Enter your fingerprint

  1. Reach the desktop with Platform SSO active.

Once Setup Assistant completes, your Platform SSO session is fully established. You can immediately access managed web applications and native applications registered with the configured IdP, without being prompted to sign in again.

Note: The IdP authentication step during Setup Assistant cannot be skipped.

Validating PSSO Registration

After the user reaches the desktop, you can verify the PSSO registration status:

  1. Open System Settings > Users and Groups.
  2. Select the user account.
  3. Confirm that Registration shows as Registered.

Validate the PSSO Registration by checking Registration and Token fields

  1. Confirm that SSO token shows as Present.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…