For Azure Files access on macOS with Platform SSO and Microsoft Entra Kerberos, verify these prerequisites first:
- Confirm the Mac meets the macOS requirement.
- For Azure Files with Platform SSO, the device must be running macOS Tahoe 26.5 or later.
- Confirm Company Portal version.
- Microsoft Intune Company Portal 5.2408.0 or later must be installed.
- Confirm device management state.
- The Mac must be enrolled in an MDM solution.
- Confirm Platform SSO is already deployed.
- Platform SSO must already be configured on the device before Azure Files access is expected to work.
- Confirm Azure Files identity prerequisites on the storage account.
- Microsoft Entra Kerberos authentication must be enabled on the storage account.
- Admin consent must be granted to the service principal created for Microsoft Entra Kerberos.
- MFA must be disabled for the Microsoft Entra app representing the storage account.
If the Mac is Intune-registered and the SSO extension is present but access still fails, the most likely gap from the documented prerequisites is on the storage account side rather than device registration alone. Device registration and the SSO extension by themselves are not sufficient.
Also validate the SSO/MDM side on the Mac:
- In System Settings, search for Profiles and open the Profiles panel.
- Verify the SSO configuration profile is actually present.
- Verify the Extension value matches:
- com.microsoft.CompanyPortalMac.ssoextension (UBF8T346G9)
- If the profile is missing, the device or user may be filtered out by MDM targeting.
If the profile exists but SSO still does not function correctly, check for Apple networking issues that can break the SSO extension:
- Ensure these domains are not subject to TLS inspection:
-
app-site-association.cdn-apple.com
-
app-site-association.networking.apple
- On the Mac, run:
sudo sysdiagnose -f ~/Desktop/
Warning: this collects diagnostic data from the device.
- Open the extracted
system_logs.logarchive in Console.
- Search for
com.apple.appsso and filter by SUBSYSTEM.
- Look for associated domain failures, especially involving
login.microsoftonline.com.
If code-signing validation is failing, verify System Integrity Protection (SIP) is enabled. If SIP cannot be re-enabled, check whether sudo nvram boot-args contains amfi_get_out_of_my_way=1; if it does, remove it or set it to 0.
For sign-in tracing, use the SSO extension logs and Microsoft Entra sign-in logs together:
- Capture the Correlation ID from the Browser SSO extension logs.
- Cross-reference that ID in the Microsoft Entra sign-in logs.
- In the sign-in log, check:
- Authentication method detected = Microsoft Entra SSO plug-in
- Device ID present
- Managed status
- Compliant status
- Join Type = Microsoft Entra registered
If all prerequisites are already satisfied and the issue remains, the documented next step is to verify the storage account configuration again, especially Entra Kerberos enablement, admin consent, and MFA disabled on the storage account app.
References: