_techie_ Posted March 17, 2025 Posted March 17, 2025 Hi. Does SSO on Intune managed shared iPads ever work? I am trying to improve experience with SSO on Apple's version of Shared iPads: The iPads are setup using an enrollment profile that is declared as shared with: 1) No User Affinity 2) Users must login to the device using a UPN/email address and password for the first time, then can setup a 6 digit iPad pass code thats tied to their school apple ID. 3) Our Apple School Tenant is federated against our M365 Tenant. Apparently according to Microsoft's documentation, just the Microsoft Authenticator App is required to achieve SSO, and their M365 Apps such as Outlook, Powerpoint, OneDrive and Teams etc (VPP versions) should just work, due to them being MSAL apps. So far, this doesn't seem to work! Users are prompted again, to enter their email address when opening any of the above apps. I have also enabled the attached policy, following the Microsoft documentation, but even with or without this, it doesn't seem to work. Any ideas? Thanks
CHiLL Posted March 18, 2025 Posted March 18, 2025 (edited) I am in the testing phase of shared iPads and I have found the same behaviour. We are deploying the Smoothwall Browser to replace Safari and that does pick up the SSO and is signed in automatically (bar a 30 second delay after sign-in is complete), however the Microsoft apps will not use SSO from the device sign-in. However, if you sign into one Microsoft app, it signs you into them all via the Authenticator app. My Intune configuration appears to be the same as yours, though my SSO sign-on app extension has a few apps defined: Edited March 18, 2025 by CHiLL 1
_techie_ Posted March 18, 2025 Author Posted March 18, 2025 We are deploying the Smoothwall Browser to replace Safari and that does pick up the SSO and is signed in automatically (bar a 30 second delay after sign-in is complete) Do you mean that Safari picks up the SSO, or Smoothwall browser? What is your App Config looking like on the Smoothwall browser end? Are you installing the company portal on Shared devices? The company portal doesn't seem to work as when prompted to install a management profile, it fails. Is this even necessary? Since we had enrolled them as supervised, why the additional layer of management? Thanks
CHiLL Posted March 18, 2025 Posted March 18, 2025 Do you mean that Safari picks up the SSO, or Smoothwall browser? What is your App Config looking like on the Smoothwall browser end? Are you installing the company portal on Shared devices? The company portal doesn't seem to work as when prompted to install a management profile, it fails. Is this even necessary? Since we had enrolled them as supervised, why the additional layer of management? Thanks We've disabled Safari and only deploy Smoothwall Browser to the iPads (so it's the only browser option), as we are subscribed to Smoothwall Cloud Filter and Smoothwall Monitor and it allows us to monitor and log usage. The app configuration was a bit of a nightmare with a lot of back and forth between their support departments. I can provide the PLIST of my Smoothwall app configuration, though it's only worthwhile if you're subscribed to either Smoothwall Cloud Filter or Monitor. Company Portal doesn't work in a shared environment from what I can gather, it's only really useful for one-to-one devices, such as an iPad assigned to a specific individual and they self-enroll the device. I have only deployed the Microsoft apps (including Authenticator), Smoothwall Browser and some other education apps, such as PiXL.
_techie_ Posted March 18, 2025 Author Posted March 18, 2025 I can provide the PLIST of my Smoothwall app configuration, though it's only worthwhile if you're subscribed to either Smoothwall Cloud Filter or Monitor. Yes please! I will try your version of the Smoothwall Browser config if you can provide it!
CHiLL Posted March 18, 2025 Posted March 18, 2025 _techie_ said: Yes please! I will try your version of the Smoothwall Browser config if you can provide it! Intune > Apps > App Configuration Policies > Create a new managed device policy and target it against the Smoothwall app > Enter XML data SmoothwallSerialNumber REPLACE WITH YOUR SERIAL NUMBER SmoothwallLegacyOrgID REPLACE WITH YOUR ORG ID UserID {{devicename}} UniqueDeviceID {{devicename}} HomePageURL https://www.{schoolname.council.sch.uk} SSOProvider Microsoft UsersIDsAllowedToSSOSignIn @REPLACE WITH YOUR EMAIL DOMAIN - E.G: @schoolname.council.sch.uk - Include the @ sign CanStoreSSOUserIDInCloud Deploy that configuration the the device group that contains your iPad(s). I've found that once the user logs in and is on the home screen, the Smoothwall browser will take approximately 30 seconds to work with SSO. If the user tries to use it before that, you will see the SSO login screen. It's been a bit of a nightmare getting the iPads to the stage that they're at at the moment.
_techie_ Posted March 18, 2025 Author Posted March 18, 2025 Interesting you mention a 30 second delay - we had this with the latest version of the extension on Windows. They did give us a workaround however, which seems to work. With the SSO, are you expecting the Smoothwall browser app to just sign in without prompts - and identifying the user correctly? We are getting a prompt when launching Smoothwall browser, to open authenticator app which prompts to sign into entra (not proper SSO IMHO). Whilst not terrible - it doesn't really perform as proper SSO - like the extension in Edge on Windows. I guess I am just impatient perhaps. Your plist file is close to my working version so thats good news.
CHiLL Posted March 18, 2025 Posted March 18, 2025 Interesting you mention a 30 second delay - we had this with the latest version of the extension on Windows. They did give us a workaround however, which seems to work. With the SSO, are you expecting the Smoothwall browser app to just sign in without prompts - and identifying the user correctly? We are getting a prompt when launching Smoothwall browser, to open authenticator app which prompts to sign into entra (not proper SSO IMHO). Whilst not terrible - it doesn't really perform as proper SSO - like the extension in Edge on Windows. I guess I am just impatient perhaps. Your plist file is close to my working version so thats good news. After the 30 second delay, it does automatically log the user in without any further prompts (aside from the necessary Apple privacy disclaimer that just needs dismissing). I can confirm this in the diagnostics page where it shows the user's UPN. I have another app configuration for managed devices deployed, specifically targeting Microsoft Authenticator that has the following configuration: Configuration key: sharedDeviceMode Value type: Boolean Configuration value: true I don't know what would happen if I remove that, since I'm not actually using Shared Device Mode, but Shared iPad instead. However it appears to be working correctly, so I think I'll leave it alone for the moment.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now