Skip to main content
Question

Configure Platform Single Sign-On (PSSOe) for Microsoft Entra ID with Jamf Pro

  • July 16, 2024
  • 58 replies
  • 3116 views

Show first post

58 replies

Forum|alt.badge.img+3
  • New Contributor
  • February 24, 2025

@rabbitt - I'm going to go ahead and get this out of the way - We still AD Bind.   (hangs head in shame).

But, I've been looking to convince management to get away from this for a while.  After JNUC and hearing your session (awesome session BTW), management decided to get some Jamf Connect licenses and start looking at PSSOe.  The problem I'm running into is that we seem dead set on not allowing just anyone the capability to register in Entra.  We have it restricted to a small group of employees.  That means I'll have to touch every single machine.
Do you have any advice on how I can accomplish this easily or how to convince management to open it up?  Their concern is that we've had a bunch of personal devices register in our tenant and this was presented as the way to stop that.

Thanks!


Did you ever find a way around this? We are absolutely not budging on blocking end users from Entra Join for the same reason, people kept binding their personal devices to Entra ID when trying to sign into Office on their computers, and then when they leave the company, and their email gets de-activated, they lose access to their personal computer, and if they have bitlocker, all their files too. I've been touching every single machine to get this working, but it's the only thing I haven't automated, so it's a little bit painful that this is the hangup preventing zero touch deployment, given that on-prem AD binding allows me to do this without having to interact with the computer. 


Forum|alt.badge.img+13
  • Valued Contributor
  • February 24, 2025

Did you ever find a way around this? We are absolutely not budging on blocking end users from Entra Join for the same reason, people kept binding their personal devices to Entra ID when trying to sign into Office on their computers, and then when they leave the company, and their email gets de-activated, they lose access to their personal computer, and if they have bitlocker, all their files too. I've been touching every single machine to get this working, but it's the only thing I haven't automated, so it's a little bit painful that this is the hangup preventing zero touch deployment, given that on-prem AD binding allows me to do this without having to interact with the computer. 


Unfortunately no.  We're in the same situation with end users.  Our Entra transition is in coordination with a 3rd party professional services.  We have brought this up to their team as a need for PSSOe, but so far, they don't have a workable solution either with our requirement to not allow just anyone to do a join.

So, no.  We're still just as stuck as you are.


howie_isaacks
Forum|alt.badge.img+23
  • Esteemed Contributor
  • February 24, 2025

With our current SSO profile setup, users are notified that their password is due to expire, and they can change their password using the key icon in the menubar. With this configuration usign the company portal app, how are users notified that their password will expire, and what is the process for the password change? I am working on creating a guide for users to go through the process of registering. At some point, everyone will need to reset their password.


Forum|alt.badge.img+5
  • Contributor
  • May 27, 2025

Hi All,

I am able to setup pSSO exactly like this guide, only issue is we are getting lots of sign in pop up like below and when trying to authenticate its getting stuck in between. The sign in pop ups comes with Error code 16000


Mowmow003
Forum|alt.badge.img+2
  • Jamf Heroes
  • November 27, 2025

Hi ​@rabbitt , I just want to ask, before we deploy PSSO for better MFA authentication, does Device Compliance need to be enabled in Jamf and does the device need to be registered in Entra? Is that correct? Because I thought we could deploy the company portal and then the configuration profile based on the Jamf documentation.


rabbitt
Forum|alt.badge.img+17
  • Author
  • Valued Contributor
  • November 29, 2025

Hi ​@rabbitt , I just want to ask, before we deploy PSSO for better MFA authentication, does Device Compliance need to be enabled in Jamf and does the device need to be registered in Entra? Is that correct? Because I thought we could deploy the company portal and then the configuration profile based on the Jamf documentation.


No. PSSO does not require Device Compliance. IF you are using device compliance, PSSO makes the registration much easier by combining the PSSO and device registration in one step. But it is not mandatory. 


Mowmow003
Forum|alt.badge.img+2
  • Jamf Heroes
  • November 30, 2025

Hi ​@rabbitt , I just want to ask, before we deploy PSSO for better MFA authentication, does Device Compliance need to be enabled in Jamf and does the device need to be registered in Entra? Is that correct? Because I thought we could deploy the company portal and then the configuration profile based on the Jamf documentation.


No. PSSO does not require Device Compliance. IF you are using device compliance, PSSO makes the registration much easier by combining the PSSO and device registration in one step. But it is not mandatory. 

Thank you, ​@rabbitt , for your prompt response. We want to enable this so we can reduce MFA prompts and have a more unified experience. However, when we enable Secure Enclave and require device registration, it fails. So is it okay for us to ignore that requirement? And we can ignore Company Portal registration and it will server as broker only? Is that correct? Sorry this is our first time going to implement this and we followed the instruction it seems it doesn’t work.


rabbitt
Forum|alt.badge.img+17
  • Author
  • Valued Contributor
  • December 2, 2025

 

However, when we enable Secure Enclave and require device registration, it fails. So is it okay for us to ignore that requirement? And we can ignore Company Portal registration and it will server as broker only? Is that correct? Sorry this is our first time going to implement this and we followed the instruction it seems it doesn’t work.

When you enroll a computer in PSSO with the secure enclave method, Entra creates a device record and it appears in the device registration in Entra as “Microsoft Entra Joined.”  You should not need to take any additional steps to enroll the device via Company Portal.  You shouldn’t even need to ever open the Company Portal app.

IF you are also using Device Compliance, this enrollment in PSSO will also enroll the device for Jamf to report device compliance with no extra steps or Self Service policy needed.

I would not require an authentication strength of PSSO and simultaneously require a device be joined.  Using the PSSO credential implies the device has been enrolled in a management system.

You _may_ want to deploy Device Compliance to check the state of the device (up to date OS, FileVault enabled, etc.)  That will depend on your organization’s risk policies.  But using PSSO on its own means you’re on a managed machine, using a non-exportable, non-replayable, non-phishable credential which is far better than relying on a password.