Skip to main content
Question

Apple SSO Extension without MDM

  • July 8, 2020
  • 5 replies
  • 65 views

Forum|alt.badge.img+5

The Apple Kerberos SSO extension (the one that replaces Enterprise Connect in Catalina and Big Sur) is configured via config profile that must be applied by MDM.

Since the pandemic turned me into a full-time work-from-home admin, I've been using my personal Mac to do most of my work. I would love to leverage the SSO extension, but I don't want to put my personal Mac in management. Is anyone aware of a way to enable the extension via terminal or some other method?

5 replies

Forum|alt.badge.img+9
  • Valued Contributor
  • July 8, 2020

Have you tried creating a Profile in your MDM, exporting it and installing in your Mac. I'm pretty sure you need your Mac to be at least UAMDM to active SSO Extension but you could give this a try.


Forum|alt.badge.img+5
  • Author
  • Contributor
  • July 8, 2020

@f.deis yeah I tried that. It rejects this profile since its not coming from an MDM authority.


boberito
Forum|alt.badge.img+22
  • Jamf Heroes
  • July 8, 2020

Like kernel extensions, privacy protection configurations, the SSO config profile must originate from an MDM server.


Forum|alt.badge.img+5
  • Author
  • Contributor
  • July 8, 2020

Thanks, @boberito but I was wondering if there is another way, like using defaults to import a plist. I exported plists for com.apple.kerberos and com.apple.AppSSOKerberos.KerberosExtension on one Mac that was configured by MDM, then imported them on an unmanaged Mac, but the menu item hasn't shown up yet. I must still be missing something.


dan-snelson
Forum|alt.badge.img+28
  • Honored Contributor
  • July 9, 2020

@KMerendaTFMC Perhaps a VM with a serial number enrolled in Apple Business Manager / Apple School Manager would meet your needs.

If so, adapt @cainehorr's Automate Building Jamf Compatible macOS 10.13+ Virtual Machines.