Jump to content

Recommended Posts

Posted

I have moved to managing our ipads to MEM/intune now. What I am trying to get set up is 365 SSO via https://docs.microsoft.com/en-us/mem/intune/configuration/device-features-configure#single-sign-on-app-extension

 

1) Apple ID is federated from Azure - AppleID is the azure UPN

2) ipads are enrolled from ASM and enrolled into MEM as shared ipads.

3) Microsoft authenticator is installed.

4) users can log in just fine. First login does prompt our 365 login, then apple prompts for a PIN creation for future profile logons.

5) SSO profile is assigned to the ipads. A dynamic group supports this (profile has been successfully applied on ipad according to the "Device Configuration" page of the ipad.)

6) neither browser going to 365 portal nor installed apps SSO at all, they all prompt for an email address and then password.

 

As a supplementary, is there a way to set an app configuration in the MDM to prepopulate 365 apps with the appleID or email of logged in user? Im guessing this will be an XML config.

Posted
Sounds like your pushing apps which are not synced with ASM purchase the app in ASM with enough licences and then sync this to intune. These shouldn't ask for credentials then.
  • 3 weeks later...
Posted
there are plenty of licenses available. Im not sure how I could push an app that doesnt have enough licenses in either ASM or azure/intune, I wouldnt have thought it would let me? Either way I can see that there are about 80 free licenses for each microsoft app (for "free" apps I usually purchase way more than I need just in case)
Posted
There are two ways to do it you can add it via intune or purchase the free app in ASM and then this syncs to intune. These ones when deployed do not prompt for credentials
  • 1 month later...
Posted (edited)

I did. You cant (big *: without 3rd party software with other MDMs).

 

This is the workflow for optimum "zero touch" sso.

 

1) log in with apple id and ipad pin (note this does NOT pass any sort of authentication other than userID to microsoft authenticator, there is no handshake with azureAD and apple at ipad logon whatsoever)

2) click microsoft authenticator. Log in as appriopriate

3) all other MS apps work fine now with no logon. NOTE! Outlook may ask the user to add the mailbox (if not done already)

 

what SHOULD happen is that you open any MS app and it should spawn the microsoft authenticator for you, thus accomplishing step 2. I have found this to be unreliable. We use the intune 365 template we did not create a custom payload so all the MS authentication URLs that are called should be correct, so technically speaking all the apps should be redirecting their authentication calls through the MS authenticator. However we have found that sometimes each app will still ask you to authenticate and to make matters worse, if you were to open the MS authenticator it will let you in and say you ARE authenticated (after this the remaining apps open without issue) so there is still something not 100%

 

That being said, the process is stupidly simple to set up so I have no idea where I have gone wrong (if anywhere).

 

1) purchase ipad from company who puts the ipad into ASM for you.

2) create a profile in intune that says "shared ipad", "supervised device" as a minimum. I dont care about naming, I dont care about setup screens, keep it as simply as possible for testing.

3) make the profile the default profile for all ipad devices enroled - again for testing, I do have a couple of profiles in reality but for testing purposes this will ensure im not assigning an incorrect profile!

4) have an AAD group for devices enrolled with the profile. This makes your dynamic group much simpler to manage for "do this to all ipads" configuration or software profiles in intune

5) create the necessary configuration profiles in intune plus assign to the dynamic group. To keep it simple I install the office apps plus ms auth app, set up sso, add our enterprise CA cert and thats about it for testing. Im going to use a guest WIFI logon so there is little other config to interfere. I set up the 365 SSO as per ms doc. It is literally a couple of clicks plus two extra copy/paste settings.

6) assign ipad in ASM to intune.

7) switch on ipad for first time. Add to wifi. accept the remote management, let it reboot

8) log onto ipad with school email and school password when the MS prompt appears (for first time user they will need to create an apple pin) or apple pin as appropriate

9) open ms auth app and authenticate.

10) thats it really.

 

in short, you cannot have a native zero touch SSO between apple and ms with intune. I believe other MDM have their own apps that will do this (Manage engine doesnt, I know that) but I have seen anecdotal evidence of jamf working with MacOS but nothing about ipads. There is notes about conditional access but this wont work with shared ipads of course.

 

We have now educated users to click microsoft authenticator before other apps.

Edited by KK20

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...