I've started playing around with the Microsoft Enterprise SSO plugin to compliment Jamf Connect. For end users, this seems like an easy no brainer setup. The problem comes with our IT tiered accounts setup. In our environment, standard users have a mundane account while IT tends to have a Tier 2 account, server admins have a Tier 1, etc. This was done for various security reasons, and generally works well for us.
This setup does not play nicely with the Microsoft Enterprise SSO though. For example, in my testing I effectively get locked out of Jamf because the Microsoft SSO auto applies the mundane account and Jamf doesn't have a built in account switcher I could use to swap to the appropriate tiered account.
Does anyone have any recommendations on how to handle this edge case? The vast majority of our users won't have these tiered accounts, but those that do will be pretty vocal about things not working. I don't see a way to exclude specific sites from the Microsoft SSO configuration without excluding full browsers or applications.