Platform SSO is the feature that closes the biggest gap in Mac management for Microsoft-centric environments. Before it, macOS identity integration with Entra ID was fundamentally weaker than Windows – users had a local account, a separate work account, and an authentication experience that didn’t reflect the identity-bound device model the rest of the environment was built on. Platform SSO changes that.
Understanding what Platform SSO actually does – and what it doesn’t do – is the prerequisite for deciding how to configure it and what to expect from it.
Platform SSO extends Entra ID authentication to the macOS login window. Without Platform SSO, a user logs into their Mac with a local account password that has no relationship to their Entra ID credentials. Their work account lives inside applications – Outlook, Teams, OneDrive – but the OS itself doesn’t know who the user is from an identity perspective. Platform SSO bridges that gap. The user authenticates at the macOS login screen with their Entra ID credentials, and that authentication propagates to Microsoft 365 applications without requiring separate sign-ins.
The practical result is a Mac that behaves more like a Windows device from an identity perspective – the OS authentication is tied to the work identity, the device can participate in Conditional Access evaluation as a compliant managed device, and the user experience of signing into work applications is seamless rather than requiring separate authentication flows for each one.
Platform SSO doesn’t make macOS login identical to Windows login. It makes the identity integration meaningful – the Mac is now an identity-bound device, not just a managed device with a separate identity layer sitting on top.
Platform SSO supports two authentication modes that have different implications for how the Mac login experience works. Password mode synchronizes the Entra ID password with the local account – the user sets their Entra ID password and that password works at the macOS login screen. Secure Enclave mode uses the device’s Secure Enclave chip to create a hardware-bound credential rather than synchronizing a password. Secure Enclave mode is the more secure option – it produces a phishing-resistant credential that can satisfy stronger authentication requirements – but it changes the login experience more significantly and has specific prerequisites around device hardware and macOS version.
Windows Hello for Business is the closest Windows equivalent – a hardware-bound credential in the TPM that authenticates to Entra ID. Platform SSO with Secure Enclave mode is Apple’s implementation of the same concept. The security properties are similar. The user experience differences are real – Windows Hello is deeply integrated into the Windows login experience in a way that Platform SSO with Secure Enclave is still maturing toward on macOS.
Platform SSO requires macOS 13 Ventura or later. It requires the Microsoft Enterprise SSO Extension, which is deployed as an Intune configuration profile. It requires the device to be enrolled in Intune. And for the full Conditional Access integration – where the Mac participates in device compliance evaluation as an identity-bound managed device – it requires the device to be registered in Entra ID, which Platform SSO facilitates as part of the setup flow.
The Conditional Access implication is the most architecturally significant part. A Mac with Platform SSO configured and Entra ID registration completed can be evaluated by Conditional Access as a compliant managed device – the same way a Windows device with Entra join is evaluated. This means your CA policies that require compliant devices can apply meaningfully to Macs, rather than requiring separate CA policies that treat Macs differently because they can’t participate in the same compliance evaluation model. That’s a meaningful step toward a consistent access enforcement model across your fleet regardless of OS.
Platform SSO with Entra ID registration is what makes a Mac a first-class citizen in a Conditional Access-enforced environment. Without it, Macs require special-cased CA policies or weaker enforcement – which is a design compromise worth avoiding.
The implementation of Platform SSO – the specific Intune configuration profile, the Enterprise SSO Extension deployment, and the user experience during the registration flow – is covered in the next article. The architecture here is the decision context: why Platform SSO matters, what it enables, and what mode makes sense for your environment. The implementation follows from those decisions.
Intune Deployment Guide · Phase 11: Mac Management
‹ Previous: [11.1.1] Getting Started with macOS Management: The intune-my-macs Approach
Next: [11.2.1] Implementing Platform SSO on macOS with Intune ›




