Hi all,
Im starting to play with the SSO for Microsoft and the Kerberos Apple pieces. Since we are trying to move away from binding, I'm love to find a solution that allows the user to login using their AD credentials (or office 365 credentials which then just adds our domain name to the end of their login) and then keeps them signed into to anything that can use those credentials. We cant afford Jamf Connect, so thats out...but noMad or something else that isnt expensive would work.
Since we use federated and managed Apple IDs, I found I could tie into the Microsoft SSO during the user sign into to their iCloud accounts on the computer, which then gets them pre-logged into our Zoom accounts and the microsoft office online logins. The Microsoft apps are still currently requesting that they type their user name(email address) into the app, and then it lists their account to click on and doesnt require their password, but I'd love to get it to already be pre-logged into the office apps as well and bypass the need to even type the user name.
I originally misunderstood the Appel Kerberos plug in to assume it could work in place of a bind, but seems like I do need something more like a NoMad to make it work properly. I don't have much experience with NoMAD so hoping its still supported and easy to figure out (but nothing with active directory seems to be easy).
Anyone have any hints to share if they are doing similar setups?