Deployment Guide Token Protection Apple
In brief
The deployment guide no longer states that Platform SSO for macOS uses hardware-backed storage by default. The Intune setup link remains unchanged.
What Entra admins need to know
Administrators should use the linked Intune instructions for Platform SSO configuration details.
This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
- Install the Microsoft Company Portal or deploy it via your MDM solution. Company Portal serves as the authentication broker for Microsoft Entra sign-ins.
- Enable hardware-backed registration using one of the following options:
- Option A: Enable the Microsoft Enterprise SSO plug-in for Apple Devices.
- Option B: Configure Platform SSO for macOS.
Platform SSO uses hardware-backed storage by default.For setup instructions, see Configure Platform SSO for macOS devices in Microsoft Intune.
When the Token Protection policy is enabled, users who aren't using a supported application will see the following screen after authenticating:
::\ No newline at end of file
:::image type="content" source="media/deployment-guide-token-protection-apple/token-protection-required-error-message.png" alt-text="Screenshot of the error message when a token protection policy blocks access.":::
\ No newline at end of file
@@ -91,7 +91,7 @@ Complete the following steps for *each* platform you're deploying to. These step 1. Install the Microsoft Company Portal or deploy it via your MDM solution. Company Portal serves as the authentication broker for Microsoft Entra sign-ins. 1. Enable hardware-backed registration using one of the following options: - Option A: Enable the [Microsoft Enterprise SSO plug-in for Apple Devices](../../identity-platform/apple-sso-plugin.md).- - Option B: Configure **Platform SSO for macOS**. Platform SSO uses hardware-backed storage by default. For setup instructions, see [Configure Platform SSO for macOS devices in Microsoft Intune](/intune/intune-service/configuration/platform-sso-macos).+ - Option B: Configure **Platform SSO for macOS**. For setup instructions, see [Configure Platform SSO for macOS devices in Microsoft Intune](/intune/intune-service/configuration/platform-sso-macos). --- @@ -337,4 +337,4 @@ Users on devices that were registered to Microsoft Entra ID before Token Protect When the Token Protection policy is enabled, users who aren't using a supported application will see the following screen after authenticating: -:::image type="content" source="media/deployment-guide-token-protection-apple/token-protection-required-error-message.png" alt-text="Screenshot of the error message when a token protection policy blocks access.":::\ No newline at end of file+:::image type="content" source="media/deployment-guide-token-protection-apple/token-protection-required-error-message.png" alt-text="Screenshot of the error message when a token protection policy blocks access."::: 