Microsoft Entra ID
Authentication

Deployment Guide Token Protection Apple

In brief

The deployment guide no longer states that Platform SSO for macOS uses hardware-backed storage by default. The Intune setup link remains unchanged.

What Entra admins need to know

Administrators should use the linked Intune instructions for Platform SSO configuration details.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

  1. Install the Microsoft Company Portal or deploy it via your MDM solution. Company Portal serves as the authentication broker for Microsoft Entra sign-ins.
  2. Enable hardware-backed registration using one of the following options:

When the Token Protection policy is enabled, users who aren't using a supported application will see the following screen after authenticating:

::\ No newline at end of file :::image type="content" source="media/deployment-guide-token-protection-apple/token-protection-required-error-message.png" alt-text="Screenshot of the error message when a token protection policy blocks access."::: \ No newline at end of file

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…