Jump to content

macOS authentication and identity management options


Recommended Posts

Posted

Whilst Jamf Connect gives end users the ability to sign into any macOS device with their Azure Credentials, the SSO ability is due to arrive with Ventura. Ventura has Platform SSO which allows identity providers to build an extension to the macOS login window for SSO.

 

https://www.jamf.com/blog/wwdc-2022-sso-extension/

 

Microsoft have a preview of this extension so still in beta only...

https://learn.microsoft.com/en-us/azure/active-directory/develop/apple-sso-plugin

Posted

Jamf Connect in my last place - Worked a treat as long as make sure you the fields are all setup and details match for kerberos to work.

 

You can't set some parts of it up in the console, you have to do it via plists and upload them as a custom payload.

 

SSO works via kerberos and Azure AD Connect as long as pass through is enabled.

Posted
We use Mosyle for students to log in to the Macs! I believe it's a fair amount cheaper.

 

It isn't, you have to buy the premium product to get these features...

Posted
Whilst Jamf Connect gives end users the ability to sign into any macOS device with their Azure Credentials, the SSO ability is due to arrive with Ventura. Ventura has Platform SSO which allows identity providers to build an extension to the macOS login window for SSO.

[

 

Ventura was released yesterday.

 

There's also Google Secure LDAP which has authenticated macos for a few years- so I guess whatever the MS equivalent of that is, Active Directory is LDAP based so sounds like it should do it already.

Posted
Does this mean it will auto sign into OneDrive/office applications? Anyone got this setup already?

 

Yes but not for the OS, yet. Hopefully by the time this project is initiated for us this might be a reality. The Google LDAP is an interesting option ;)

 

Thanks for the pointers everyone 👍🏻

  • Thanks 1
  • 8 months later...
Posted
Just bumping this again. Got a Mac project over the summer. Wondering if we can get the new macs authing with azure without the need for some kind of onsite server/connector. Anyone got this going?
Posted
Yes but not for the OS, yet. Hopefully by the time this project is initiated for us this might be a reality. The Google LDAP is an interesting option ;)

 

Thanks for the pointers everyone 👍🏻

 

I have moved some of our Mac's over to Google LDAP, the only draw back, is that it works on OSX 10.15 and above. Great if you have new Macs. Bad if you still have old Mac's that only run 10.13, like me. boo.

Posted
I have moved some of our Mac's over to Google LDAP, the only draw back, is that it works on OSX 10.15 and above. Great if you have new Macs. Bad if you still have old Mac's that only run 10.13, like me. boo.

 

Just use OpenCore patcher to make the older Mac's use the latest OS, they run fine, its what I've done on some old ones to get them on Ventura.

Posted
Just use OpenCore patcher to make the older Mac's use the latest OS

 

Interesting - I think you're talking about this project:

 

https://dortania.github.io/OpenCore-Legacy-Patcher/

 

It looks like it can keep older Macs running for longer, which is interesting.

 

Logins: we're using Google's OpenLDAP service to provide logins for our MacOS machines - pupils have been using them for the last year with no issues (that anyone's reported). Users can log in with their usual Google username and password, although 2FA isn't supported (i.e. the logins just check username / password, even if 2FA is enabled on an account it isn't checked, but the user can still log in). Unlike using the GCPW Windows login component, the user isn't actually logging in to their cloud Google account, so login cookies aren't passed to Chrome after login (as they are on Windows with the GCPW).

 

I'm guessing you could do the same with Azure AD (now "Microsoft Entra ID"?) accounts, if you can find some way of turning on an OpenLDAP (or plain / Microsoft LDAP?) service in Azure, or syncing from Azure to an OpenLDAP-capable service.

Posted
Interesting - I think you're talking about this project:

 

https://dortania.github.io/OpenCore-Legacy-Patcher/

 

It looks like it can keep older Macs running for longer, which is interesting.

 

 

Yep thats the one, you just make a bootable USB Installer to match the hardware you want to install the OS on, then once installed run the patcher again to just adjust a few settings like booting without the boot selector and its done, really straight forward. We have 100+ 2014 iMac's that won't go above Big Sur officially, but I've done Monterey, Ventura on them and likely do Sonoma early next year. I just keep a batch of USB sticks to do a row of iMacs in 1 hit then move onto the next. Will likely replace them with M3/M4 iMacs on 2 or 3 years since they will be 11/12 years old at that point.

  • Thanks 1
Posted
We have 100+ 2014 iMac's that won't go above Big Sur officially, but I've done Monterey, Ventura on them and likely do Sonoma early next year.

 

Do you have those managed with Jamf or a similar management system, i.e. does Jamf (or similar) still work on these older machines? I have a (2017 model, I think) iMac that is just about to go out of support, one thing it can't run is GarageBand - can this mechanism get GarageBand (and iMovie) working on older machines, would you know?

Posted
Just use OpenCore patcher to make the older Mac's use the latest OS, they run fine, its what I've done on some old ones to get them on Ventura.

Tried that and they did not work with Google LDAP. Tried everything still did not work. Not sure how legal OpenCore patcher is.

  • Thanks 1
Posted
Ventura was released yesterday.

 

There's also Google Secure LDAP which has authenticated macos for a few years- so I guess whatever the MS equivalent of that is, Active Directory is LDAP based so sounds like it should do it already.

This is NOT SSO, sure Secure LDAP allows a user to login to MacOS with their Google credentials but does not automatically sign them into anything else.

  • 11 months later...
Posted

Hi Team,

 

I'm currently struggling with a project that seems very similar to this thread here. In our school we do have something like 40 old macbooks that will now be replaced with M3 devices. At the moment the devices are binded to AD and a profile applying some restrictions. Considering that our kids just use Google, I was tempted to use the Google accounts to avoid the issue with sync folders and forgotten pw. is here someone who uses Google without Jamf?

Thanks,

Dantas

Posted
In our school we do have something like 40 old macbooks that will now be replaced with M3 devices. At the moment the devices are binded to AD and a profile applying some restrictions. Considering that our kids just use Google, I was tempted to use the Google accounts

 

How old are the Macbooks? We're replacing our current late-2015 model iMacs, which are due to run out of MacOS updates this year. We're moving ours on (available, if you're interested - around £150 each, we'd probably take £2,000 for the lot), but they do make very nice ChromeOS devices when reformatted with ChromeOS Flex - I'm using one now, and have been since the start of the year. We even tested the snazzy new web-based version of Photoshop on it, which seemed to work nicely as well.

Posted

Assuming you've got your AD syncing to Google workspace then the passwords are the same so it's still easy

 

Deploy the google drive app and configure it as an open at login item in the OS you should be golden (apart from users having to log into that seperatley).

 

Otherwise you're going to want Jamf Pro/JamfConnect to turn the login screen into a googley one and be able to push out custom payloads to configure Google drive

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...