Posted on 12-12-2023 08:00 AM
Hello,
I am currently working on integrating macOS local accounts with Azure AD accounts. Is this feasible?
I'm having difficulty locating the appropriate documentation to guide me through the setup process.
Additionally, we are exploring Jamf Pro as part of our trial phase. We require the capability to enable users to reset their Microsoft account password, ensuring it synchronizes with the local macOS account.
Any help would be much appreciated.
Posted on 12-12-2023 08:55 AM
MacOS and Windows have massively different concepts of identity management. I would suggest forgetting everything you understand about how Windows identity management works.
Without any 3rd party tools, Apple has two solutions and JAMF has a 3rd party solution.
JAMF Pro is a MDM platform, it will configure all the stuff mentioned above. However, JAMF Pro itself will not enable any IDP integrations. Platform SSO is the function that would be closest to what you are asking for, not counting JAMF Connect which is what we use. Depending on your Licensing level with Microsoft, Platform SSO is likely an additional cost. JAMF Connect is an add on item to JAMF Pro, but we find it worth it.
https://www.apple.com/za/business/docs/site/Kerberos_Single_Sign_on_Extension_User_Guide.pdf
https://support.apple.com/guide/deployment/platform-sso-for-macos-dep7bbb05313/web
Posted on 12-12-2023 10:23 PM
Ideal way would be using jamf connect and migrate account option.
"Allows existing local accounts to be connected to a network account.
This setting is typically used when you want a user's existing local account to have the same username and password as the user's network account."