Not sure if the same applies to JamfSchool, but in JamfPro, you must
deploy the WebClip as a separate config profile and apply it at a user
level instead of at the device level, which is the default.
We've decided to switch to SecureEnclave. During my journey down the
rabbit hole of Platform SSO logs I came up with a few variations on a
predicate that gave some insight into the problem. Silent token refresh
attempt resultslog show --style compact...
¯\_(ツ)_/¯ I had been trying to find a log from Teams that even displayed
the banner's text with a timestamp, to attempt to correlate it with some
other events but, I was unsuccessful.