News
Apple and Microsoft together: how Single Sign-On with Entra ID really works
Clients often assume that Apple and Microsoft do not work well together: a Mac in a Microsoft environment would always mean a second password and login hassle. That used to be true for a long time, but it is outdated by now. Over the past few years Apple and Microsoft have invested heavily in Single Sign-On between macOS, iOS, iPadOS, and Microsoft Entra ID. The result: users log in once and are then signed in almost everywhere afterward, while IT actually gets more control through Conditional Access. This whitepaper explains how this works technically and how to set it up.
What is Single Sign-On on an Apple device, really?
Apple has a built-in framework for this: Extensible Single Sign-on. An identity provider such as Microsoft supplies an SSO extension that uses this framework to recognize sign-in requests and automatically fill in credentials, without an app having to do anything itself. There are two types of extensions, and the difference is exactly why two names are used: the Enterprise SSO plug-in and Platform SSO.
Redirect-type extension
Recognizes sign-in requests to specific web addresses, such as login.microsoftonline.com, and fills in the correct credentials there. This is what the Microsoft Enterprise SSO plug-in does, and it works for apps and Safari.
Credential-type extension
Handles sign-in for the account itself, starting right at the device’s login screen. This is the basis of Platform SSO on the Mac and of the Kerberos SSO extension for on-premises Active Directory.
What it solves
Sign in once to Entra ID, then get automatically signed in to Outlook, Teams, Safari, and any other participating app, without repeated password prompts.
The Microsoft Enterprise SSO plug-in on iPhone and iPad
On iOS and iPadOS, the SSO plug-in is built into the Microsoft Authenticator app. Once a device is enrolled through MDM and the configuration has been deployed, the plug-in recognizes sign-ins to Entra ID in any app that uses the standard protocols: OAuth 2, OpenID Connect, or SAML. Apps that use the Microsoft Authentication Library get this automatically. Older apps that do not can still be included by adding their bundle ID to an allowed list, without repeated password prompts.
Requirements
iOS or iPadOS 13 or higher, the Microsoft Authenticator app, and enrollment in an MDM solution such as Intune that pushes the configuration to the device.
Conditional Access
The plug-in also passes the device certificate to Entra ID, so device-based Conditional Access policy can check whether the device is known and compliant.
browser_sso_interaction_enabled is turned on in the configuration profile. This setting is required to share the SSO session with Safari and separate browser windows too.Platform SSO on the Mac: beyond just apps
On the Mac this goes a step further. Platform SSO does not just handle SSO within apps, it also links the local Mac account to the Entra ID identity, starting right at the login screen. This is handled through the Intune Company Portal app, which takes on the role of SSO extension. An administrator configures Platform SSO through Intune or another supported MDM solution and chooses one of three sign-in methods.
Platform Credential (Secure Enclave)
A hardware-bound key is created in the Mac’s Secure Enclave. The user can then sign in passwordlessly with Touch ID to apps that use Entra ID, while the Mac’s local password continues to exist separately.
Smart card
The user unlocks the Mac with a smart card or hardware token such as a YubiKey. Once the device is unlocked, that same smart card is used for SSO to Entra ID.
Password sync
The Entra ID password is synced with the local Mac account. Simple to manage, but less strong than the other two methods since a password is still involved.
For the best security, Microsoft recommends the Secure Enclave method: it is phishing-resistant and based on the same technology as Touch ID, since the key can only be accessed with Touch ID, with no fallback to a password.
Kerberos SSO: if there is still an on-premises Active Directory
Many SMBs have not fully migrated to the cloud and still run an on-premises Active Directory alongside Entra ID, for example for a file server or an older application. For that situation, macOS offers a separate, optional Kerberos SSO extension within Platform SSO. It handles Kerberos-based SSO to both on-premises AD resources and Entra ID Kerberos resources, alongside regular SSO to Entra ID itself. You only use it if users genuinely still need access to classic Kerberos authentication.
Requirements and things to watch for
Most problems with Apple-Microsoft SSO do not originate in the configuration itself, but in the network or the choice of browser.
Network access
Devices need to be able to reach both Apple’s own CDN domains and the Microsoft sign-in domains. If there is a proxy in between that inspects SSL traffic, explicitly exclude these domains from TLS inspection. If you do not, device-based Conditional Access will behave unreliably.
Safari
Has built-in SSO integration. No separate configuration is needed.
Chrome, Edge, and Firefox
Chrome needs the Microsoft Single Sign-on extension, or version 135 and up for automatic support. Edge works automatically once the user is signed in to the Edge profile. Firefox requires setting the MicrosoftEntraSSO policy.
Device is required to be managed to access this resource), check whether the SSO extension is actually active.A step-by-step setup plan
- Make sure the Mac, iPhone, or iPad is already set up through Automated Device Enrollment and Intune, so this happens automatically during enrollment.
- In Intune, configure an Enterprise SSO profile for iOS and iPadOS through the Settings Catalog, with
Enable_SSO_On_All_ManagedAppsset to 1 for the simplest coverage. - For macOS, configure a Platform SSO profile and choose the sign-in method: Secure Enclave for the best security, smart card if that is already in use, or password sync as an intermediate step.
- Consider the EnableRegistrationDuringSetup setting, so Platform SSO is already registered during the Setup Assistant and a new Mac is ready to use right away.
- Allow the required network domains and exclude them from any TLS inspection on the firewall or proxy.
- Test the result by signing in to a second Microsoft app without being asked for a password again, and check whether device-based Conditional Access recognizes the device as compliant.
A practical scenario for SMBs
A company of thirty employees works with Microsoft 365, Entra ID, and a mix of Windows laptops and MacBooks. Until recently, the MacBooks went through the same ritual every morning: sign in on the Mac, then again on Outlook, then again on Teams. After setting up Platform SSO with the Secure Enclave method and the Enterprise SSO plug-in on the matching iPhones, that has been reduced to one sign-in per day. At the same time, the IT department can now use Conditional Access to enforce that only devices known to and compliant with Intune can access the company mail account, regardless of whether it is a Mac, iPhone, or Windows laptop.
Analyst ICT is an officially recognised Apple Technical Partner. Want to know more about Apple within your organisation? See our overview for business or email frank@analystict.nl.