Platform SSO Setup & troubleshooting

Body

Setup Process

Changes​​​​​

  • Beginning August 2026, JAMF connect will no longer be installed .
  • Company Portal will be installed (PSSO).
  • New device set up will include new screens prompting for user sign-in
    • Prompts for MFA.
    • Microsoft SSO authentication screens. This helps create the user account and sync password.

Workflow

  1. Turn on the Mac and proceed through the initial Setup Assistant screens until the Remote Management screen appears.
  2. Enroll the Mac by selecting Continue on the Remote Management screen so Automated Device Enrollment can apply the correct MDM configuration.
  3. When prompted to create a computer account, enter the user’s Entra ID username (UPN) exactly as provided.
  4. When Setup Assistant redirects to the Platform SSO sign‑in window, have the user authenticate with their Entra ID password.
  5. After successful authentication, allow Platform SSO to create the local macOS account automatically using the user’s Entra identity.
  6. When prompted to set a local password, have the user enter the local macOS password that Platform SSO requires (this may differ from the Entra password if password separation is enabled).
  7. Complete the remaining Setup Assistant screens until the Mac reaches the desktop.Uploaded Image (Thumbnail)

Troubleshooting

Open System Setting 

Uploaded Image (Thumbnail)

Navigate to "Users & Groups" And Click the "i" next to account name

Uploaded Image (Thumbnail)

On the Window that opens, click "repair"
 

Uploaded Image (Thumbnail)

This will begin the steps to re-register and sync your device with your SJU credentials

Password not being accepted?

Randomly, the Platform SSO (PSSO) application appears in the top right corner of your Mac, asking the user to register (even though this may have previously been completed, or maybe they have yet to register).  When the user attempts to enter their password in order to register, it will repeatedly reject the password over and over again.

In addition to this behavior, if a user upgraded their SJU-issued macOS device to Golden Gate from a previous version, they may experience an issue where their password does not seem to be accepted when logging in for the first time post-upgrade.  If this scenario takes place, the user should reboot their computer and confirm they are connected to the internet (wifi or hardwired). 

These steps can be done to correct this issue for when the registration prompt is repeatedly shown and rejecting the correct password:

  1. Open the Company Portal App location within the Applications folder on the affected Mac.

    Uploaded image

  2. Sign in to the Company Portal using your SJU email address and password.

    Uploaded image

  3. Click 'Postpone'

    Uploaded image

  4. Click user account in the upper right hand corner of the window

    Uploaded image

  5. Click remove account from device.

    Uploaded image

  6. Proceed with the repair process outlined above in the Troubleshooting section.

Additional Notes

  • Single-User devices ONLY.
  • A network connection must be available when registering. 
  • MFA is required.
  • Devices are registered within our Azure/Entra portal.   At the time of writing this article, we are not leveraging any of the management abilities within Azure/Entra.  The registration, however, is a requirement for PSSO to work. 

Details

Details

Article ID: 163636
Created
Mon 7/20/26 3:56 PM
Modified
Sun 10/4/26 3:16 PM

Related Articles

Related Articles (1)