Addigy Identity and Extensible SSO can be leveraged to achieve directory connectivity without needing to bind user accounts to Active Directory.
Requirements
Addigy Identity
Addigy Identity allows end-users to use their Identity Provider (IdP) credentials to create and authenticate into local accounts. To learn more about Addigy Identity, Addigy Identity's End User Experience, and how to configure Addigy Identity with Microsoft Entra view the articles below:
- Addigy Identity Overview
- Addigy Identity End User Experience
- How to configure Addigy Identity with Microsoft Entra
Once Addigy Identity has been configured in the policy you can move on to the step below.
Company Portal App
To use the Microsoft Enterprise SSO plug-in, devices must support and have the Intune Company Portal App installed. The Company Portal App can be added to your policy using Addigy's Prebuilt Apps:
- Select the policy.
- Navigate to Software > Prebuilt Apps.
- Search MS Company Portal.
-
Click the empty box to the left > Actions > Add to policy
- Set App Settings > Assign.
Note: The Company Portal App just needs to be installed on the device and does not need to be accessed by end-users.
Configuring the Extensible SSO Profile
The Extensible SSO profile provides SSO for IdP accounts across all applications/browsers that support the Apple Enterprise SSO feature. The profile extends SSO to applications that don’t yet use IdP libraries and to applications that use OAuth 2, OpenID, Connect, and SAML. To configure and deploy the profile follow the steps below:
- Within Catalog navigate to Device Settings.
- On the upper right hand side of the page click New.
-
Scroll down and select Extensible SSO
- Configure the profile using the values below:
- Payload Name: Give the profile a name
-
Extension Identifier:
com.microsoft.CompanyPortalMac.ssoextension - SSO Type: Redirect
-
Team Identifier:
UBF8T346G9 -
URLs
https://login.microsoftonline.comhttps://login.microsoft.comhttps://sts.windows.nethttps://login.partner.microsoftonline.cnhttps://login.chinacloudapi.cnhttps://login.microsoftonline.dehttps://login.microsoftonline.ushttps://login-us.microsoftonline.com
-
Extension Data: Microsoft
- App Allow List
com.apple.Safaricom.addigy.MacManagecom.microsoft.CompanyPortalMac-
com.google.Chrome(required if Chrome is used)
- App Prefix Allow List
com.apple.com.addigy.com.microsoft.-
com.google.(required if Chrome is used)
- Browser SSO Interaction Enabled
enabled
- App Allow List
- Scroll down to the bottom of the page and click Create Profile.
- Navigate to your policy > Device Settings > locate your Extensible SSO profile > click the empty box on the left > click Add/Remove > Add to policy.
Once Addigy Identity, the Company Portal App, and the Extensible SSO profile have been configured and added to the policy users will be able to authenticate into their devices via their IdP provider with Addigy Identity. After signing into a Microsoft service via SSO, users will also be authenticated into their other Microsoft services.
A Note on Browser Support
- Safari: Safari supports SSOe out of the box on macOS.
- Firefox: Firefox needs to be on v132 or higher for native SSOe support.
- Chrome: Chrome has an extension to support this function and it may need if you are using Chrome under v135 the extension can be found in this article. Starting with Chrome v135+ the SSOe support is native.