TL;DR: Okta Platform SSO enrollment with Jamf works on an existing account, but the Identity First (Simplified Setup) PreStage flow fails with "Registration failed" before any credentials are entered. Looking for the full list of PreStage requirements, plus best practices for recovery when the Okta and local passwords diverge.
ENVIRONMENT
- Jamf Pro (cloud), macOS Tahoe 26.x, Apple silicon, ADE through ABM
- Okta Verify 9.59.0 (enrollment package), Okta Platform SSO with password authentication
- Fleet currently uses Jamf Connect Login/AuthChanger; my test Macs are excluded from both
- Local admin account created by Jamf's managed local administrator (LAPS-style) setting
GOAL
Zero-touch onboarding: ship a Mac, the user signs in with Okta during setup, the local account is created and linked to Okta, and IT has a dependable recovery path if the user gets locked out.
TARGET WORKFLOW
1. New Mac is added to ABM, auto-assigned to Jamf, and lands in a dedicated PreStage.
2. During Setup Assistant, the PreStage installs Okta Verify (enrollment package) and the PSSO profile (plus SCEP profile), using Identity First so the user signs in with Okta before any local account exists.
3. The local account is created by PSSO already linked to Okta (PreStage set to Skip Account Creation, no separate local account step).
4. Jamf's managed local admin (rotating password) is created automatically as the IT recovery account. The bootstrap token is escrowed so Secure Token is granted automatically at first graphical login.
5. No Jamf Connect Login on these Macs.
6. Recovery: if a user is locked out, IT signs in with the managed local admin (retrieving the rotating password from Jamf), resets the local password, and aligns it with the Okta password.
Steps 2-3 are where I'm stuck. Step 4's automatic Secure Token grant worked in my testing. Step 6 is the part I'm least sure is realistic.
WHAT WORKS
On an existing local account, registration completes with the PSSO profile + Associated Domains + two custom settings payloads (registrationCompleted: true, SSO token issued, password sync prompt appears). Things that tripped me up, in case they help someone else:
- The Associated Domains payload wasn't offered when I built the profile from scratch, but appeared after I cloned an existing profile.
- com.okta.mobile and com.okta.mobile.auth-service-extension each needed their own Upload payload (OrgUrl, UserPrincipalName, PasswordSyncClientID), with PlatformSSO.ProtocolVersion = 2.0 only in the extension domain.
- app-sso platform -s still reports protocolVersion 1 even though I set 2.0. Is that expected?
WHAT FAILS
New PreStage with "Enable Simplified Setup for Platform SSO", workflow Identity First, PSSO app bundle ID com.okta.mobile, my PSSO profile selected, and Skip Account Creation. The Mac shows the "Single Sign-On for Mac" screen, and when I click Continue it immediately shows "Unable to Sign-In: Registration failed. Please contact an administrator for assistance." I never get a username/password prompt. Same result after deleting the computer record and re-enrolling, so it's not leftover state, and the network is fine.
At the time of the failure, the PreStage had only the PSSO profile attached (no SCEP profile) and no Okta Verify enrollment package. Since then I've added the Okta Verify enrollment package. I haven't retested yet and will update this thread with the result.
QUESTIONS
1. Has anyone gotten Identity First (Simplified Setup) working with Okta and Jamf? What is the complete list of what the PreStage needs (profiles, packages, Setup Assistant panes that must stay visible)?
2. "Registration failed" gives no detail. Which logs are most useful for debugging PSSO registration during Setup Assistant, and how do you get a terminal at that stage?
3. If an admin resets the Okta password, PSSO asks for the old local password to sync. If the user doesn't remember it, they're stuck. What's your recovery workflow (bootstrap token, LAPS admin reset, something else)?
4. Does a LAPS-managed local admin work at the PSSO login window? In my testing with Jamf Connect Login, the local admin couldn't sign in because logins route through Okta. How do you keep a local recovery account usable?
5. A CIS Level 1 password policy profile appeared to block password resets and Secure Token operations. Has anyone seen that, and which keys did you relax?
6. For Okta shops today, is native PSSO ready to replace Jamf Connect Login, or are you still running Connect?
