Skip to main content

June 26, 2026

Configure Workspace ONE UEM to use Workspace ONE Access Mobile SSO (for Apple) Authentication for Managed iOS Devices - Cloud only

For Workspace ONE UEM managed devices to use the Mobile SSO (for Apple) authentication method, in the Workspace ONE UEM console, you configure the Apple iOS device profile with a SCEP or CA certificate and the Apple single sign-on extension and then assign the profile to a smart group.

The profile contains the required information for the device to establish a connection with the Workspace ONE Access identity provider and the certificate necessary for authentication.

The Apple iOS profile contains the settings, configurations, and restrictions that you want to enforce on devices. For more information about profiles, see the Introduction to Managing iOS Devices guide on the Workspace ONE UEM Documentation landing page.

How to configure Apple Device Profile in Workspace ONE UEM

Workspace ONE UEM device profiles are used to manage devices. They contain the settings, configurations, and restrictions that you want to enforce on devices. To use the Workspace ONE Access Mobile SSO (for Apple) authentication method for SSO into managed Apple iOS devices, you create an Apple iOS profile with either a SCEP or a Credentials certificate to use and the Apple single sign-on extension.

  • SCEP. Workspace ONE UEM supports SCEP (Simple Certificate Enrollment Protocol) for iOS and macOS devices. The integration includes the use of key pairs and the submission of the certificate signing request (CSR) that results in a signed certificate from the SCEP endpoint to devices. See Workspace ONE Certificate Authority Integrations - SCEP for more information about SCEP.
  • Credentials. The credential is a certificate authority (CA) that is issued by a third-party that certifies the ownership of a public key by the named subject of the certificate. See Workspace ONE UEM Certificate Authority Integrations.

You enable the Apple single sign-on extension in the device profile to provide users with single sign-on to apps and websites without having to re-enter their credentials. The Apple SSO extension handles authentication for users. When users enroll their Apple IOS devices in Workspace ONE UEM MDM, the extension profile is added to the app installer and the certificate is copied to the local certificate store on Apple devices. Clients can then authenticate with the certificate for single sign-on.

You can also list the application names that can be authenticated with the Apple SSO extension.

  1. In the Workspace ONE UEM console, select the desired organization group and navigate to Resources > Profiles.

  2. Click Add > Add Profile and select iOS Apple iOS > Device Profile.

  3. Name the profile.

  4. Select either the SCEP or Credentials section and configure the certificate information.

    To configure a SCEP certificate

    Click ADD.

    Option  Description 
    Credential Source The source is Defined Certificate Authority.
    Certificate Authority Select the certificate. If one is not available, go toGroups and Settings > All settings > System > Enterprise Integration > Certificate Authorities and follow the prompts to add a certificate.
    Certificate Template Select the certificate template. If one is not available, go to Groups and Settings > All settings > System > Enterprise Integration > Certificate Authorities > Request Templates and follow the prompts to add a certificate template.

    Or

    To configure the credentials for a third-party certificate

    Click ADD.

    Option  Description 
    Credential Source Select the source Upload.
    Credential Name The credential name is automatically populated when the certificate is uploaded
    Certificate Select the certificate file to upload.
  5. Configure SSO Extension to enable single sign-on to the Workspace ONE Intelligent Hub app without requiring authentication into each app.

    Click +ADD.

    Option  Description 
    Extension Type Select WS1 Access
    Extension Identifier This value is populated with the Workspace ONE Access identifier.
    Type This value is populated with the Credential value.
    Additional Settings - Allowed Bundle IDs If the SSO extension is to be limited to specific app bundle IDs, click ADD and enter the app bundle IDs.
  6. In the Assignment page, assign the profile to a Smart Group; set Assignment Type to Auto and Allow Remove to Never.

  7. Click Save and Publish.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…