Apple now supports Platform SSO during Automated Device Enrollment (ADE) in macOS 26. This allows users to authenticate with Entra ID directly in the Setup Assistant, create a local macOS account, and gain immediate SSO access to apps and websites.
Currently, the Microsoft Platform SSO plug-in does not support this flow, and Microsoft has not announced full support.
Could this serve as a workaround for first-time login on a JAMF-managed Mac?
A possible setup using Entra ID:
1. Start the Mac → Setup Assistant
2. Sign in with Managed Apple ID (federated with Entra ID)
3. Redirect to Entra ID → authenticate
4. Create a local macOS user
5. Enroll the device in MDM
6. Configure Platform SSO later using the Entra ID user
This approach enables initial device setup while allowing Platform SSO to be activated once the local user account is established.
