Entra ID

macOS Platform SSO in ADE Now Generally Available

2 min read

Summary

Microsoft has made Platform SSO during Automated Device Enrollment generally available for macOS. The update lets organizations register devices and enable Platform SSO automatically during setup, reducing user prompts and helping IT teams deliver a more secure, consistent onboarding experience from day one.

Need help with Entra ID?Talk to an Expert

Introduction

Microsoft has announced general availability for Platform SSO (PSSO) during Automated Device Enrollment (ADE) on macOS. For IT teams managing Apple devices with Microsoft Entra ID and Intune, this is an important improvement because it removes extra enrollment steps and builds identity configuration directly into the initial setup experience.

What’s new

With this release, Platform SSO can now be completed automatically during macOS Automated Device Enrollment.

Key changes include:

  • Automatic Entra ID registration during setup for enrolled macOS devices
  • Platform SSO activation as part of enrollment instead of requiring a separate post-setup action
  • Fewer user prompts during first-run device onboarding
  • More consistent identity configuration across newly deployed Macs

This is enabled through the EnableRegistrationDuringSetup capability, which performs Platform SSO registration within the managed ADE workflow.

Why this matters

Previously, users could be asked to finish Platform SSO registration after setup, often through an additional prompt or a manual “Finish” step. That added friction to onboarding and created another point where setup could be delayed or missed.

By integrating PSSO directly into ADE, Microsoft is helping organizations:

  • Reduce deployment complexity
  • Improve first-day productivity for users
  • Strengthen compliance and device trust earlier in the lifecycle
  • Standardize identity-backed access from the first sign-in

This will be especially useful in large-scale deployments, including enterprise rollouts, education environments, and frontline scenarios where speed and consistency matter.

Impact on IT administrators

For admins, this update means identity is now treated as a core part of macOS provisioning rather than a follow-up task. If you already use ADE and Platform SSO, the workflow becomes simpler and easier to standardize.

Benefits for IT teams include:

  • Less reliance on users to complete setup correctly
  • Fewer enrollment support issues
  • Better alignment between MDM provisioning and Entra identity controls
  • Faster delivery of compliant, ready-to-use devices

Next steps

To use Platform SSO during Automated Device Enrollment, organizations should:

  1. Configure Automated Device Enrollment for macOS in their MDM solution.
  2. Ensure Platform SSO is already configured for the organization.
  3. Enable EnableRegistrationDuringSetup in the deployment profile.

If you manage macOS devices in Microsoft Intune, now is a good time to review your ADE profiles and update your onboarding process to take advantage of this GA capability.

Need help with Entra ID?

Our experts can help you implement and optimize your Microsoft solutions.

Talk to an Expert

Stay updated on Microsoft technologies

Entra IDmacOSPlatform SSOAutomated Device EnrollmentIntune

Related Posts

Entra ID

Microsoft Entra ID: Why Active Directory Isn’t Enough

Microsoft says organizations should stop viewing Active Directory as the default identity foundation for modern IT. As cloud apps, external users, and AI agents expand identity needs, Microsoft Entra ID offers stronger security, simpler operations, and a better path for future investments.

Entra ID

Microsoft Entra Zero Trust Across Every Resource

Microsoft has published implementation guidance for enforcing Zero Trust consistently across AI apps, SaaS, on-premises apps, and internet resources using Conditional Access and Global Secure Access. The guidance matters for IT teams because it emphasizes phased rollout, report-only testing, and unified identity-first controls to reduce VPN dependence without disrupting users.

Entra ID

Microsoft Entra August 2026: Identity Feature Updates

Microsoft Entra's August 2026 updates add new admin controls for Windows SSO prompts, Exchange Online attribute writeback, and several Lifecycle Workflows enhancements now generally available. Microsoft also introduced public previews for AD device sync with Cloud Sync, sponsorless guest cleanup automation, and GPO backup and restore in Entra Domain Services, giving identity teams more control, automation, and migration flexibility.

Entra ID

Microsoft Entra Tenant Governance GA for Multi-Tenant Security

Microsoft Entra Tenant Governance is now generally available, giving organizations a built-in way to discover, govern, and monitor multiple Microsoft tenants from a central control plane. The release matters for IT and security teams managing complex tenant estates because it helps reduce shadow tenant risk, enforce consistent baselines, and detect configuration drift across services like Entra, Intune, Defender, Exchange Online, Purview, and Teams.

Entra ID

Microsoft Entra Identity-First Access Replaces VPN Gaps

Microsoft is positioning identity-first access as a better alternative to traditional VPN-centric remote access. By combining Conditional Access with Global Secure Access, organizations can apply Zero Trust policies consistently across SaaS, AI apps, on-premises resources, and internet traffic.

Entra ID

Microsoft Entra July 2026: Backup, BYOD, AI Security

Microsoft Entra's July 2026 updates introduce several identity and access improvements, led by the general availability of Entra Backup and Recovery and new BYOD support for Global Secure Access. Microsoft also previewed stronger Conditional Access controls for AI agents and announced security enhancements in Microsoft Authenticator, giving IT teams more resilience, flexibility, and governance options.