Jump to content

Recommended Posts

Posted

Hi.

 

Does SSO on Intune managed shared iPads ever work?

 

I am trying to improve experience with SSO on Apple's version of Shared iPads:

 

The iPads are setup using an enrollment profile that is declared as shared with:

1) No User Affinity

2) Users must login to the device using a UPN/email address and password for the first time, then can setup a 6 digit iPad pass code thats tied to their school apple ID.

3) Our Apple School Tenant is federated against our M365 Tenant.

 

Apparently according to Microsoft's documentation, just the Microsoft Authenticator App is required to achieve SSO, and their M365 Apps such as Outlook, Powerpoint, OneDrive and Teams etc (VPP versions) should just work, due to them being MSAL apps.

So far, this doesn't seem to work! Users are prompted again, to enter their email address when opening any of the above apps.

 

I have also enabled the attached sso.png policy, following the Microsoft documentation, but even with or without this, it doesn't seem to work.

 

Any ideas?

 

Thanks

Posted (edited)

I am in the testing phase of shared iPads and I have found the same behaviour. We are deploying the Smoothwall Browser to replace Safari and that does pick up the SSO and is signed in automatically (bar a 30 second delay after sign-in is complete), however the Microsoft apps will not use SSO from the device sign-in. However, if you sign into one Microsoft app, it signs you into them all via the Authenticator app. My Intune configuration appears to be the same as yours, though my SSO sign-on app extension has a few apps defined:

 

Screenshot 2025-03-18 142035.png

Edited by CHiLL
  • Thanks 1
Posted
We are deploying the Smoothwall Browser to replace Safari and that does pick up the SSO and is signed in automatically (bar a 30 second delay after sign-in is complete)

Do you mean that Safari picks up the SSO, or Smoothwall browser?

What is your App Config looking like on the Smoothwall browser end?

 

Are you installing the company portal on Shared devices?

The company portal doesn't seem to work as when prompted to install a management profile, it fails. Is this even necessary? Since we had enrolled them as supervised, why the additional layer of management?

 

Thanks

Posted
Do you mean that Safari picks up the SSO, or Smoothwall browser?

What is your App Config looking like on the Smoothwall browser end?

 

Are you installing the company portal on Shared devices?

The company portal doesn't seem to work as when prompted to install a management profile, it fails. Is this even necessary? Since we had enrolled them as supervised, why the additional layer of management?

 

Thanks

We've disabled Safari and only deploy Smoothwall Browser to the iPads (so it's the only browser option), as we are subscribed to Smoothwall Cloud Filter and Smoothwall Monitor and it allows us to monitor and log usage. The app configuration was a bit of a nightmare with a lot of back and forth between their support departments. I can provide the PLIST of my Smoothwall app configuration, though it's only worthwhile if you're subscribed to either Smoothwall Cloud Filter or Monitor.

 

Company Portal doesn't work in a shared environment from what I can gather, it's only really useful for one-to-one devices, such as an iPad assigned to a specific individual and they self-enroll the device. I have only deployed the Microsoft apps (including Authenticator), Smoothwall Browser and some other education apps, such as PiXL.

Posted
I can provide the PLIST of my Smoothwall app configuration, though it's only worthwhile if you're subscribed to either Smoothwall Cloud Filter or Monitor.

 

Yes please!

I will try your version of the Smoothwall Browser config if you can provide it!

Posted
_techie_ said:
Yes please!

I will try your version of the Smoothwall Browser config if you can provide it!

Intune > Apps > App Configuration Policies > Create a new managed device policy and target it against the Smoothwall app > Enter XML data

 

SmoothwallSerialNumber
REPLACE WITH YOUR SERIAL NUMBER
SmoothwallLegacyOrgID
REPLACE WITH YOUR ORG ID
UserID
{{devicename}}
UniqueDeviceID
{{devicename}}
HomePageURL
https://www.{schoolname.council.sch.uk}
SSOProvider
Microsoft
UsersIDsAllowedToSSOSignIn

@REPLACE WITH YOUR EMAIL DOMAIN - E.G: @schoolname.council.sch.uk - Include the @ sign

CanStoreSSOUserIDInCloud


 

 

Deploy that configuration the the device group that contains your iPad(s). I've found that once the user logs in and is on the home screen, the Smoothwall browser will take approximately 30 seconds to work with SSO. If the user tries to use it before that, you will see the SSO login screen.

 

It's been a bit of a nightmare getting the iPads to the stage that they're at at the moment.

Posted

Interesting you mention a 30 second delay - we had this with the latest version of the extension on Windows. They did give us a workaround however, which seems to work.

 

With the SSO, are you expecting the Smoothwall browser app to just sign in without prompts - and identifying the user correctly? We are getting a prompt when launching Smoothwall browser, to open authenticator app which prompts to sign into entra (not proper SSO IMHO). Whilst not terrible - it doesn't really perform as proper SSO - like the extension in Edge on Windows.

I guess I am just impatient perhaps.

 

Your plist file is close to my working version so thats good news.

Posted
Interesting you mention a 30 second delay - we had this with the latest version of the extension on Windows. They did give us a workaround however, which seems to work.

 

With the SSO, are you expecting the Smoothwall browser app to just sign in without prompts - and identifying the user correctly? We are getting a prompt when launching Smoothwall browser, to open authenticator app which prompts to sign into entra (not proper SSO IMHO). Whilst not terrible - it doesn't really perform as proper SSO - like the extension in Edge on Windows.

I guess I am just impatient perhaps.

 

Your plist file is close to my working version so thats good news.

After the 30 second delay, it does automatically log the user in without any further prompts (aside from the necessary Apple privacy disclaimer that just needs dismissing). I can confirm this in the diagnostics page where it shows the user's UPN.

 

I have another app configuration for managed devices deployed, specifically targeting Microsoft Authenticator that has the following configuration:

Configuration key: sharedDeviceMode

Value type: Boolean

Configuration value: true

 

I don't know what would happen if I remove that, since I'm not actually using Shared Device Mode, but Shared iPad instead. However it appears to be working correctly, so I think I'll leave it alone for the moment.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...