My MacBook is registered in Intune, and the SSO extension is also registered on the MacBook, but still ot able to access my file share

rapidit 0 Reputation points
2026-09-22T16:17:19.46+00:00

I believe the description box is too short for my query. If I include the complete ticket history, the Microsoft support team will take ages to read through it. I have been experiencing a basic file share connection issue on my MacBook for the last four days. I attempted to connect to my file share with my registered device in Intune, and I have also installed the Entra Kerberos profile and extension on my MacBook. Despite this, I still cannot access the Azure file share. For the past four days, Microsoft has been passing this ticket from one team to another, which I find completely unprofessional.

Azure Files
Azure Files

An Azure service that offers file shares in the cloud.

0 comments No comments

2 answers

Sort by: Newest
  1. kagiyama yutaka 5,575 Reputation points
    2026-09-23T01:50:47.9466667+00:00

    I think this is worth checking if it’s an existing file share. Look at the identifier URI under App registrations > Manifest. If it still starts with CIFS/, change it to lowercase cifs/. Uppercase CIFS/ prevents macOS from authenticating and mounting the share.

    Was this answer helpful?

    0 comments No comments

  2. AI answer

    2026-09-22T16:17:40.98+00:00

    For Azure Files access on macOS with Platform SSO and Microsoft Entra Kerberos, verify these prerequisites first:

    1. Confirm the Mac meets the macOS requirement.
      • For Azure Files with Platform SSO, the device must be running macOS Tahoe 26.5 or later.
    2. Confirm Company Portal version.
      • Microsoft Intune Company Portal 5.2408.0 or later must be installed.
    3. Confirm device management state.
      • The Mac must be enrolled in an MDM solution.
    4. Confirm Platform SSO is already deployed.
      • Platform SSO must already be configured on the device before Azure Files access is expected to work.
    5. Confirm Azure Files identity prerequisites on the storage account.
      • Microsoft Entra Kerberos authentication must be enabled on the storage account.
      • Admin consent must be granted to the service principal created for Microsoft Entra Kerberos.
      • MFA must be disabled for the Microsoft Entra app representing the storage account.

    If the Mac is Intune-registered and the SSO extension is present but access still fails, the most likely gap from the documented prerequisites is on the storage account side rather than device registration alone. Device registration and the SSO extension by themselves are not sufficient.

    Also validate the SSO/MDM side on the Mac:

    1. In System Settings, search for Profiles and open the Profiles panel.
    2. Verify the SSO configuration profile is actually present.
    3. Verify the Extension value matches:
      • com.microsoft.CompanyPortalMac.ssoextension (UBF8T346G9)
    4. If the profile is missing, the device or user may be filtered out by MDM targeting.

    If the profile exists but SSO still does not function correctly, check for Apple networking issues that can break the SSO extension:

    1. Ensure these domains are not subject to TLS inspection:
      • app-site-association.cdn-apple.com
      • app-site-association.networking.apple
    2. On the Mac, run:
         sudo sysdiagnose -f ~/Desktop/
      
      Warning: this collects diagnostic data from the device.
    3. Open the extracted system_logs.logarchive in Console.
    4. Search for com.apple.appsso and filter by SUBSYSTEM.
    5. Look for associated domain failures, especially involving login.microsoftonline.com.

    If code-signing validation is failing, verify System Integrity Protection (SIP) is enabled. If SIP cannot be re-enabled, check whether sudo nvram boot-args contains amfi_get_out_of_my_way=1; if it does, remove it or set it to 0.

    For sign-in tracing, use the SSO extension logs and Microsoft Entra sign-in logs together:

    1. Capture the Correlation ID from the Browser SSO extension logs.
    2. Cross-reference that ID in the Microsoft Entra sign-in logs.
    3. In the sign-in log, check:
      • Authentication method detected = Microsoft Entra SSO plug-in
      • Device ID present
      • Managed status
      • Compliant status
      • Join Type = Microsoft Entra registered

    If all prerequisites are already satisfied and the issue remains, the documented next step is to verify the storage account configuration again, especially Entra Kerberos enablement, admin consent, and MFA disabled on the storage account app.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.