toffee_paul Posted December 1, 2022 Posted December 1, 2022 (edited) Hi, I've recently federated our Azure AD users with Apple and set up some iPads in Shared iPad mode using Endpoint Manager and assign a couple of test devices (settings used documented below. This seems to work fine with users signing in to the iPad for the first time with their Managed Apple ID and password. They are then prompted to set up a Shared Passcode. I'm now looking to get a true single sign-on experience for the Microsoft 365 iOS apps I've deployed such as Word and Excel. I've read the docs on this and deployed Microsoft Authenticator to the devices and also created and assigned an iOS Device features profile with the 'Single sign-on app extension' option (settings used documented below). I was hoping that this would mean that as the user had authenticated by signing in to the iPad once, they would not be required to sign in to the likes of Word and Excel but they are being presented with the "Get started wih Microsoft 365 screen with the following three options "Try 1 month free | Existing Microsoft 365 Users? Sign in | Not now". I'd expect to see this screen if I hadn't enable SSO but I thought with the SSO enabled the user would be seamlessly signed in to M365 apps without the need to authenticate? Has anyone had any joy setting this up? Is it by design that it's this way or am I missing something? Cheers, Paul Enrollment profile settings:User affinity: Enroll without User Affinity Supervised: Yes Locked enrollment: Yes Shared iPad: Yes Maximum cached users: 24 Maximum seconds after screen lock before password is required: 5 Maximum seconds of inactivity until user session logs out: 5400 Require Shared iPad temporary session only: Not configured Maximum seconds of inactivity until temporary session logs out: 0 Sync with computers: Allow All Device Name: Apply device name template (supervised only): Yes Device Name Template: SHARED-{{SERIAL}} iOS Device features profile: Single sign-on app extension settings: SSO app extension type: Microsoft Azure AD Enable shared device mode: Not configured (also tried this with 'Yes' option enable too, same result) Edited December 1, 2022 by toffee_paul
Brimstone Posted December 1, 2022 Posted December 1, 2022 Your are trying to so something which is not possible yet, SSO currently requires an Extension App that passes the authentication ticket between the sign in App and and the SSO services. A federated Managed Apple ID is only that, a federated ID that replicates the Azure Credentials so is not an SSO solution. On top of that any future SSO configuration will require User MDM Enrolment and Shared iPad does NOT use a user MDM enrolment configuration. MS have an Enterprise SSO plug in but this is in preview (beta) and I have told this will be mothballed shortly.
toffee_paul Posted December 2, 2022 Author Posted December 2, 2022 Thanks for the reply @Brimstone. So as things stand, if we want to continue to use Shared iPad, and the teacher wants the pupils to work on documents in the Office apps, the pupils would have to sign in manually, and repeat this process on every shared iPad they use?
Brimstone Posted December 2, 2022 Posted December 2, 2022 Thanks for the reply @Brimstone. So as things stand, if we want to continue to use Shared iPad, and the teacher wants the pupils to work on documents in the Office apps, the pupils would have to sign in manually, and repeat this process on every shared iPad they use? Yes, this is the case.
toffee_paul Posted December 6, 2022 Author Posted December 6, 2022 Thanks. For iPads that arent Shared iPads, where enrolment is done with user affinity, I'm guessing the SSO solution would work? So as soon as the iPad is enrolled and they open up Word it sign's them in automatically?
KK20 Posted December 7, 2022 Posted December 7, 2022 (edited) As above, I have wrestled this for a long time. I believe you can do this with the JAMF management app, this is merely hearsay though as I dont have JAMF plus my notes are sketchy on this (I use Intune). The problem is that Apple do not pass anything along following an appleID+passcode "log in" to a shared ipad. the best you can get is the email address but certainly not an authentication ticket. So the minimum is appleID+passcode then open microsoft auth app and use azureAD+azurepassword and you are sorted for that logon on that shared ipad. If you set up the microsoft authenticator and the SSO extension then theoretically once you log into one MS app then all of them should recognise SSO, I have the most issues with outlook - it works SSO almost all of the time but occasionally will spit its dummy out and ignore the fact you can open word, lens, onedrive without prompt. There are other things you cannot do on shared ipads, the big one being screen timeout. You can set the passcode grace time but the screen will be off during this grace time. This grace time is also bad because you cannot manually lock the device as the grace time also runs. This catches teacher out a lot. The passcode is only for logging onto the shared ipads, the icloud logons are still the azureID+azurePW. Again our pupils get this wrong (even though it is a 365 logon page). We tend to tell people to manually save in onedrive (and dont tell them about the icloud sync) I have never used user affinity as we only have ipad trolleys. Even for the teachers. On top of that any future SSO configuration will require User MDM Enrolment and Shared iPad does NOT use a user MDM enrolment configuration. Im not sure what you mean by this? If you mean "should you want to change the grace lock time this is not easy on a shared ipad that is in use" then you are correct, its a full wipe and redeploy profile, not just a configuration profile change. Luckily there arent many settings in the shared ipad configuration. Manageengine were working on their MDM app to replicate some mimicry but we couldnt afford to double budget a 3rd party MDM when we get intune with the rest of our licensing so I need to make do with Intune. Edited December 7, 2022 by KK20
Brimstone Posted December 7, 2022 Posted December 7, 2022 Despite everything you have said the MS SSO Extension is in preview (beta) mode only so do not expect this to work everytime. As previosly said I think MS may well mothball this preview
toffee_paul Posted December 15, 2022 Author Posted December 15, 2022 Thanks @KK20 and @Brimstone for the replies. At least I'm well informed now when the teachers start moaning I mean asking questions.
DalekSec Posted December 15, 2022 Posted December 15, 2022 Glad i came across this thread, having same issue at current! Gone from Mosyle at last gaffe for iPads to MEM at this Gaffe... can confirm MEM is 3/10 where as mosyle is 9/10 atm! So many annoying issues to deal with.
toffee_paul Posted December 15, 2022 Author Posted December 15, 2022 Not heard of Mosyle before but just had a quick look, seems decent. I've moved from Meraki for iPads to MEM as we have everything else in there (laptops/Samsung tablets and phones) so thought why not have it all under one roof!). Wouldn't say I'm completely regretting it but the MEM way of creating configs etc is so unintuitive it's unreal. I love and miss the device tags feature in Meraki SM so you can switch the purpose of an iPad so quickly. It's a right faff in MEM. That said it is handy having just one portal.
supportman Posted December 15, 2022 Posted December 15, 2022 (edited) Where does everyone stand on the Mosyle vs jamf debate these days ? I've been out of the loop for a while Edited December 15, 2022 by supportman
DalekSec Posted December 15, 2022 Posted December 15, 2022 Where does everyone stand on the Mosyle vs jamf debate these days ? I've been out of the loop for a while Jamf is better but more money, Mosyle will do 90% of what you need. Intune does about 30% 1
Dan2025 Posted December 15, 2022 Posted December 15, 2022 Where does everyone stand on the Mosyle vs jamf debate these days ? I've been out of the loop for a while I prefer Jamf after using them both but it is slightly more expensive especially if you buy Mosyle over 3 years. Mosyle also has a free version which might meet some schools needs.
ITJAY2023 Posted July 4, 2023 Posted July 4, 2023 Hey all, has anyone had any Joy now that its been 7 months since the original post?
KK20 Posted July 4, 2023 Posted July 4, 2023 This never worked properly for us. The best we could do was get people to sign into the authenticator, this seemed to satisfy SSO for a few days at a time. We also hit another massive block with shared ipads, the ipad will carve up the storage for potential profiles. There did not seem to be a way to find out how much space was remaining in the storage for each logged on user. This meant that users suddenly ran out of space. We have binned shared ipads now, pupils are getting full devices each and the ipads have all gone to single user teachers. In short, shared ipads was awful, didnt work with SSO properly, syncing classroom with azure AD was poor, PIN resets apple side was a pain in the backside for smaller kids, storage limitations was unworkable on 32gb ipads. I have no idea how schools with pure ipads and shared user actually work with them, we found it a nightmare.
CTIDTech Posted July 7, 2023 Posted July 7, 2023 I've seem some videos where whole schools using iPads use a sign in app from which all the users can sign in (even on shared devices) and then access the resources they want - even if they only ever sign in once - See this youtube video for info - - - Updated - - - - forgot the link doh!
Brimstone Posted July 7, 2023 Posted July 7, 2023 Jamf is better but more money, Mosyle will do 90% of what you need. Intune does about 30% Jamf School is CHEAPER than paid for Mosyle and far better.
Brimstone Posted July 7, 2023 Posted July 7, 2023 (edited) This never worked properly for us. The best we could do was get people to sign into the authenticator, this seemed to satisfy SSO for a few days at a time. We also hit another massive block with shared ipads, the ipad will carve up the storage for potential profiles. There did not seem to be a way to find out how much space was remaining in the storage for each logged on user. This meant that users suddenly ran out of space. We have binned shared ipads now, pupils are getting full devices each and the ipads have all gone to single user teachers. In short, shared ipads was awful, didnt work with SSO properly, syncing classroom with azure AD was poor, PIN resets apple side was a pain in the backside for smaller kids, storage limitations was unworkable on 32gb ipads. I have no idea how schools with pure ipads and shared user actually work with them, we found it a nightmare. This is because you are looking at the Shared iPad with your Windows hat on. Shared iPad has never been designed for significant multiple accounts to login and log-out of. There are many caveats to using Shared iPad successfully, here's a good example of where it works well. I have a 1:1 2 form entry primary, the school is 1:1 iPads from Yr3. So Yr1 and Yr2 use a shared iPad 60 x iPads with 4 x users for each iPad, as the students are very young they don't need huge amounts of space on each iPad but they get to access all their on device photo's and documents. Each iPad has 64GB of storage. And finally....SSO on an iPad is still in preview, don't expect this to work 100% of the time Edited July 7, 2023 by Brimstone
Brimstone Posted July 7, 2023 Posted July 7, 2023 I've seem some videos where whole schools using iPads use a sign in app from which all the users can sign in (even on shared devices) and then access the resources they want - even if they only ever sign in once - See this youtube video for info - - - Updated - - - - forgot the link doh! 1. This is using Google Workspace SSO with Class Link Launcher, where the Google SSO extension has been linked directly to the district wide Class Link Platform, users can only access apps with SSO from within the Class Link launcher not anywhere else on the iPad and there are no MS apps in fact there is only 1 x third party app in there.
CTIDTech Posted July 7, 2023 Posted July 7, 2023 1. This is using Google Workspace SSO with Class Link Launcher, where the Google SSO extension has been linked directly to the district wide Class Link Platform, users can only access apps with SSO from within the Class Link launcher not anywhere else on the iPad and there are no MS apps in fact there is only 1 x third party app in there. Yes you are correct, everything is accessed through the Launchpad. We use CL in our schools and we access the office365 suite through the launchpad. It may be something worth looking at.
CHiLL Posted November 13, 2024 Posted November 13, 2024 Sorry for the necro thread bump, but I was just wondering if anyone had any success with this? I'm testing a shared iPad that requires users to sign in with their Microsoft Entra credentials and would like apps such as Word, Excel, PowerPoint, Outlook, etc to automatically sign them in via SSO using the credentials they authenticated on the iPad with.
Brimstone Posted November 15, 2024 Posted November 15, 2024 Here should tell you...but in essence you have to use an Authentication process on the iPad using MS Authenticator https://learn.microsoft.com/en-us/mem/intune/configuration/use-enterprise-sso-plug-in-ios-ipados-macos?pivots=macos#sso-app-extension 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now