Apple and Microsoft together: how Single Sign-On with Entra ID really works

Clients often assume that Apple and Microsoft do not work well together: a Mac in a Microsoft environment would always mean a second password and login hassle. That used to be true for a long time, but it is outdated by now. Over the past few years Apple and Microsoft have invested heavily in Single Sign-On between macOS, iOS, iPadOS, and Microsoft Entra ID. The result: users log in once and are then signed in almost everywhere afterward, while IT actually gets more control through Conditional Access. This whitepaper explains how this works technically and how to set it up.

What is Single Sign-On on an Apple device, really?

Apple has a built-in framework for this: Extensible Single Sign-on. An identity provider such as Microsoft supplies an SSO extension that uses this framework to recognize sign-in requests and automatically fill in credentials, without an app having to do anything itself. There are two types of extensions, and the difference is exactly why two names are used: the Enterprise SSO plug-in and Platform SSO.

The Microsoft Enterprise SSO plug-in on iPhone and iPad

On iOS and iPadOS, the SSO plug-in is built into the Microsoft Authenticator app. Once a device is enrolled through MDM and the configuration has been deployed, the plug-in recognizes sign-ins to Entra ID in any app that uses the standard protocols: OAuth 2, OpenID Connect, or SAML. Apps that use the Microsoft Authentication Library get this automatically. Older apps that do not can still be included by adding their bundle ID to an allowed list, without repeated password prompts.

Platform SSO on the Mac: beyond just apps

On the Mac this goes a step further. Platform SSO does not just handle SSO within apps, it also links the local Mac account to the Entra ID identity, starting right at the login screen. This is handled through the Intune Company Portal app, which takes on the role of SSO extension. An administrator configures Platform SSO through Intune or another supported MDM solution and chooses one of three sign-in methods.

For the best security, Microsoft recommends the Secure Enclave method: it is phishing-resistant and based on the same technology as Touch ID, since the key can only be accessed with Touch ID, with no fallback to a password.

Kerberos SSO: if there is still an on-premises Active Directory

Many SMBs have not fully migrated to the cloud and still run an on-premises Active Directory alongside Entra ID, for example for a file server or an older application. For that situation, macOS offers a separate, optional Kerberos SSO extension within Platform SSO. It handles Kerberos-based SSO to both on-premises AD resources and Entra ID Kerberos resources, alongside regular SSO to Entra ID itself. You only use it if users genuinely still need access to classic Kerberos authentication.

Requirements and things to watch for

Most problems with Apple-Microsoft SSO do not originate in the configuration itself, but in the network or the choice of browser.

A step-by-step setup plan

  1. Make sure the Mac, iPhone, or iPad is already set up through Automated Device Enrollment and Intune, so this happens automatically during enrollment.
  2. In Intune, configure an Enterprise SSO profile for iOS and iPadOS through the Settings Catalog, with Enable_SSO_On_All_ManagedApps set to 1 for the simplest coverage.
  3. For macOS, configure a Platform SSO profile and choose the sign-in method: Secure Enclave for the best security, smart card if that is already in use, or password sync as an intermediate step.
  4. Consider the EnableRegistrationDuringSetup setting, so Platform SSO is already registered during the Setup Assistant and a new Mac is ready to use right away.
  5. Allow the required network domains and exclude them from any TLS inspection on the firewall or proxy.
  6. Test the result by signing in to a second Microsoft app without being asked for a password again, and check whether device-based Conditional Access recognizes the device as compliant.

A practical scenario for SMBs

A company of thirty employees works with Microsoft 365, Entra ID, and a mix of Windows laptops and MacBooks. Until recently, the MacBooks went through the same ritual every morning: sign in on the Mac, then again on Outlook, then again on Teams. After setting up Platform SSO with the Secure Enclave method and the Enterprise SSO plug-in on the matching iPhones, that has been reduced to one sign-in per day. At the same time, the IT department can now use Conditional Access to enforce that only devices known to and compliant with Intune can access the company mail account, regardless of whether it is a Mac, iPhone, or Windows laptop.


Analyst ICT is an officially recognised Apple Technical Partner. Want to know more about Apple within your organisation? See our overview for business or email frank@analystict.nl.

One email. Every last Friday of the month.

The week in Apple, read in three minutes. No rumors, no affiliate filler.

Scroll to Top