Intune support for macOS 26 unattended Platform SSO with ADE without User Affinity?

Yannik Piwowarski 0 Zuverlässigkeitspunkte
2026-08-16T11:50:53.9066667+00:00

Hi,

I’m currently testing Microsoft Intune Automated Device Enrollment and Platform SSO on macOS 26 and would like to understand Microsoft’s support status for Apple’s new unattended Platform SSO enrollment flow.

Apple now documents an unattended ADE scenario for macOS 26 where the MDM can:

  • enroll the Mac through ADE without an end user,
  • use Auto Advance and Await Device Configured,
  • create a managed local administrator,
  • skip creation of the primary local user during Setup Assistant,
  • deploy the Platform SSO extension and configuration,
  • perform silent Platform SSO device registration,
  • finish Setup Assistant without a normal local user account,
  • and then create the first local user on demand when that user signs in at the macOS login window using IdP credentials.

In our case, the IdP is Microsoft Entra ID, the MDM is Microsoft Intune, and we use the Microsoft Enterprise SSO plug-in / Company Portal.

The desired user experience is:

  1. Mac starts and performs ADE.
  2. Intune enrolls the device without User Affinity.
  3. Intune creates a hidden managed/LAPS administrator.
  4. No normal user account is created during Setup Assistant.
  5. Company Portal / Microsoft Enterprise SSO plug-in and the Platform SSO configuration are installed.
  6. Platform SSO performs silent device registration with Microsoft Entra ID.
  7. Setup Assistant finishes and macOS displays the login window.
  8. The first employee enters their Entra ID UPN and password.
  9. Platform SSO creates the local standard user on demand.
  10. With Password authentication, the local password remains synchronized with the Entra ID password.

This appears to match Apple’s documentation titled “Implementing Platform SSO for unattended device enrollment.”

However, Microsoft’s current documentation for “Configure Platform Single Sign-On (PSSO) during Automated Device Enrollment for macOS devices” requires:

  • Enroll with User Affinity
  • Setup Assistant with modern authentication
  • static user-group assignments

So currently the documented Intune implementation appears to cover the interactive/user-affinity Platform SSO enrollment flow, but not Apple’s new unattended/userless flow.

Interestingly, the Microsoft Graph beta depMacOSEnrollmentProfile already exposes properties such as:

usePlatformSSODuringSetupAssistant

and Intune/macOS already has building blocks for managed admin account creation, skipping primary account creation, Await Final Configuration and Platform SSO configuration.

Could Microsoft please clarify:

  1. Does Microsoft Intune currently support Apple’s macOS 26 unattended Platform SSO enrollment flow without User Affinity?
  2. Does the Microsoft Enterprise SSO plug-in currently support the silent Platform SSO device registration required by Apple for this scenario?
  3. Is there a supported configuration using a combination of userless ADE, Skip Primary Setup Account Creation, a managed/LAPS admin, and Platform SSO during Setup Assistant?
  4. If this isn't currently supported, is support planned or currently in development?
  5. Is there a private preview, feature flag, or roadmap item for this scenario?
  6. What is the intended Microsoft equivalent of a Jamf Connect-style deployment where the first real user is created directly from their Entra ID credentials at the macOS login window, without manually creating a local user during Setup Assistant?
  7. If this scenario is planned, will userless/shared macOS devices also support Intune compliance evaluation and device-based Conditional Access?

The goal is not necessarily a traditional shared Mac. We mainly want device-centric zero-touch provisioning, where the Mac itself is enrolled and managed first, while the first organizational user account is created later from Entra ID at the macOS login window.

Any clarification from the Intune macOS / Microsoft Entra Platform SSO product team would be greatly appreciated.

Microsoft Security | Intune | Andere
0 Kommentare Keine Kommentare

Ihre Antwort

Antworten können von Fragestellenden als „Angenommen“ und von Moderierenden als „Empfohlen“ gekennzeichnet werden, wodurch Benutzende wissen, dass diese Antwort das Problem des Fragestellenden gelöst hat.