Thank you ncworster! This was exactly the fix we needed for our company.
we changed the keys to "allowlist" and now sso is working properly for
Google Chrome.
Our company also experienced device signature errors while re-enrolling
Macs with DEP and UIE. We worked with Jamf Support and it turns out that
one of the VPP Mac apps was preventing the device certificate from
installing. We excluded the VPP app fr...