Posted on 11-02-2023 03:43 AM
Hello everyone,
Where digging for a good technic/solution for us to use or Macs with AD environment. What is important to us is Azure (Entra) login on our Mac computers, that you get access to a home directory in the AD environment, that it provides good and functioning SSO for Mac and that it is easy and convenient to change passwords when needed , so that it syncs with the AD environment.
Plus (** not a must)
Jamf Connect is one option, but can it do all above? Or does it exist any other alternative that fulfils this wishes?
Hope to find good solutions and users with good knowledge about this in this forum. :)
Is MS SSO plug-in for the Mac a possible alternative? What about the built in AD function in macOS?
11-02-2023 05:43 AM - edited 11-02-2023 05:45 AM
As far as apple is concerned on prem AD is dead. There is no real modern way to integrate a Mac with an AD environment. You can use scripts to map users' network Home Drives and use JAMF Connects Kerberos ticket to SSO the drive. However, macOS itself gives no respect or regard to this network drive. It's just another share drive. Even Microsoft is pushing hard at using OneDrive over Home Drives, though not every organization is ready for that shift.
JAMF Connect can do all of your bullet points. Though finder has nothing to do with passwords, passwords are handled by keychain access.app.
JAMF Connect does generate Kerberos tickets. However, ADFS will not use them. To get SSO with Microsoft Products you need to install the Microsoft Company Portal app as that has Microsoft's SSO Broker in it. Once a user logs in to the company portal app (or any other Microsoft tool like Outlook) that will enable the SSO Broker in the Company portal to handle authentication.
As far as competitors to JAMF Connect. I have not found any that come close to doing as much as JAMF Connect does. Tools like the Company Portal app, or Okta Verify have PW sync options to the SSO Broker but they do not update macOS's local password. Platform SSO has a bunch of offerings but I cannot test it in my organization so I cannot really speak much on it.
Posted on 11-02-2023 07:25 AM
Thanks a lot for very detailed information.