Jump to content

Recommended Posts

Posted

Morning All,

 

Has anyone investigated or successfully implemented Platform Single Sign-On (PSSO) for their Mac estate?

 

We have managed to implement this successfully for the most part - but we seem to be experiencing an issue when users change their password via the IdP. Following this, they don't seem to be able to sign back in using their UPN and their new password if they have previously signed into the Mac.

 

Cheers.

Posted
Are you using Jamf Connect or PSSO?

 

We're using PSSO - using Jamf Pro to deploy the necessary Configuration Profile and Company Portal app.

 

Cheers.

Posted
We have tried it again recently with JAMF Pro and macOS Sequoia , don't feel it's ready yet still. Better than it was with Sonoma last year. It's nice we can login from the standard macOS logins screen with Office 365, but the Microsoft apps like OneDrive are still asking for usernames, we don't find the Microsoft Apps are being silent sign on. portal.office.com auto signs in, but we have had that ability for almost a decade. Also found cannot login in again as that user if we delete them and other little annoying things.
Posted
We have tried it again recently with JAMF Pro and macOS Sequoia , don't feel it's ready yet still. Better than it was with Sonoma last year. It's nice we can login from the standard macOS logins screen with Office 365, but the Microsoft apps like OneDrive are still asking for usernames, we don't find the Microsoft Apps are being silent sign on. portal.office.com auto signs in, but we have had that ability for almost a decade. Also found cannot login in again as that user if we delete them and other little annoying things.

Yes we have similar issues. A lot of them aren't deal breakers for us, but the subsequent login issue would cause issues.

 

Currently we're able to sign in with a UPN ([email protected]), but then if the user returns to the Mac after changing their password via the IdP, they won't be able to sign in as their UPN ([email protected]) with their new password.

 

Strangely enough, the user can sign in with "userdomain.co.uk" with the new password, and following this, they can log in with their UPN and the new password.

 

Feels like something to do with the local account user mapping but we've followed the documentation.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...