Skip to main content
Question

NoMad replacement

  • April 15, 2026
  • 10 replies
  • 201 views

shikhartodaria
Forum|alt.badge.img+4

Since NoMad has stopped working with the new macOS 26, we are looking for its replacement.

We tried implementing JAMF Connect, but since we use ADFS, JAMF Connect is not compatible.

Can anyone suggest any other replacement for NoMad, which can work as a password sync between Mac devices and our Entra environment.

Thanks

10 replies

MusicCityMac
Forum|alt.badge.img+15
  • Jamf Heroes
  • April 15, 2026

I’d look at XCreds to see if it would meet your needs. 


shikhartodaria
Forum|alt.badge.img+4
  • Author
  • Contributor
  • April 15, 2026

I’d look at XCreds to see if it would meet your needs. 

Thanks, I will give it a go.


Chubs
Forum|alt.badge.img+25
  • Jamf Heroes
  • April 15, 2026

Wait, we use ADFS and have JAMF Connect - where is the hold up? Care to post your cleansed JC config? Are you also leveraging ADDS?

The integration isn’t with ADFS, it’s with purely Entra. Where are you stuck?  

https://learn.jamf.com/r/en-US/jamf-connect-documentation-current/Federated_Integrations

xCreds operates in the same capacity (albeit a little bit more clunky) as JAMF Connect. 


Jason33
Forum|alt.badge.img+13
  • Honored Contributor
  • April 15, 2026

Have you considered Apple’s built-in Kerberos SSO extension?


ktrojano
Forum|alt.badge.img+21
  • Jamf Heroes
  • April 15, 2026

When we were testing JAMF Connect we used ADFS as well. We did’t see any issues with it. 


mvu
Forum|alt.badge.img+22
  • Jamf Heroes
  • April 15, 2026

We use Apple’s Kerberos SSO Extenstion. We are ADFS/Entra Hybrid.

I thought there was a more updated setup guide, but here is a user guide:
• https://www.apple.com/business/docs/site/Kerberos_Single_Sign_on_Extension_User_Guide.pdf


mark_mahabir
Forum|alt.badge.img+16
  • Jamf Heroes
  • April 17, 2026

Platform SSO is the direction of travel now, have you investigated that?

We currently use NoMAD, but planning on going down the PSSO route once we have some infrastructure upgrades worked out (SCEP proxies etc.).


mvu
Forum|alt.badge.img+22
  • Jamf Heroes
  • April 17, 2026

We are using Platfrom SSO with Kerberos SSO Extenstion. Until Microsoft Entra is ready for Simplified Setup for Platform SSO, we’ll still be levaraging other tech. But our organization is still legacy on some things, so Kerberos SSO extenstion will probably stick around for a bit.


Tbaker63
Forum|alt.badge.img+5
  • Contributor
  • April 17, 2026

In my Org, we were in the same boat. We implemented XCreds and it’s working great. We will eventually move to Jamf Connect or Platform SSO when our Entra is set up completely. 


AJPinto
Forum|alt.badge.img+26
  • Legendary Contributor
  • April 19, 2026

Seeing NoMAD mentioned in 2026 still blows my mind. It has been end of life for years, and anyone relying on it today is essentially brokering credentials over unpatched and deprecated channels.

ADFS is not the blocker here. Jamf Connect does not talk to ADFS at all. It talks to Entra through OIDC. If your Connect deployment failed, the issue is almost always in the Entra app registration or the redirect URI configuration, not ADFS.

XCreds and Kerberos SSO are valid options, and Platform SSO is the long term direction, but Connect should work with Entra even in hybrid ADFS environments.