Microsoft Entra ID
Conditional Access

Token Protection Deployment Guide - Apple Platforms

In brief

The guide removes the Preview designation, adds Microsoft Scout to the support matrix, and replaces detailed storage-flag instructions with updated Apple SSO plugin and Platform SSO guidance.

What Entra admins need to know

Review the updated deployment steps and supported-client information when deploying Token Protection on Apple platforms.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Token Protection Deployment Guide - Apple Platforms (Preview)

Overview

This guide covers the steps required to deploy and enforce Token Protection for sign-in session tokens on Apple platforms (iOS, iPadOS, and macOS). Token Protection on Apple platforms is currently in Preview.

Before using this deployment guide, review Token Protection in Microsoft Entra Conditional Access for an overview of the feature and supported platforms.

|---|---|---| | Intune Company Portal | ✅ | ✅ | | Microsoft Authenticator | ✅ | | | Microsoft Edge (support for sign-in to Edge profile only)* | ✅ | ✅ | | Microsoft Loop | ✅ | | | Microsoft OneNote | ✅ | ✅ | | Microsoft Scout | | ✅ | | Microsoft SharePoint | ✅ | | | Microsoft Teams | ✅ | ✅ | | Microsoft To Do | ✅ | ✅ | | Visual Studio Code | | ✅ | | Word, Excel, PowerPoint | ✅ | ✅ |

*Token Protection currently supports native applications only. Browser-based applications are not supported.

Supported Resources

Token Protection on Apple platforms can be used to protect the following resources:

  1. Install Microsoft Authenticator from the Apple App Store, or deploy it via your MDM solution. Authenticator serves as the authentication broker for Microsoft Entra sign-ins.
  2. Enable hardware-backed registration using the Microsoft Enterprise SSO plug-in for Apple Devices.
  3. Set the use_most_secure_storage flag.
    • The flag applies only to new device registrations made after the flag is configured.
    • For Intune-enrolled devices, the flag also applies to registrations made through the Intune Company Portal app, even before the device becomes MDM-managed.
    • For all other registrations, the flag takes effect only after the device is MDM-managed and the Microsoft Enterprise SSO plug-in profile is active.

macOS

  1. Install the Microsoft Company Portal or deploy it via your MDM solution. Company Portal serves as the authentication broker for Microsoft Entra sign-ins.
  2. Enable hardware-backed registration using one of the following options:
    • Option A: Enable the Microsoft Enterprise SSO plug-in with the use_most_secure_storage flag.
      • The flag applies only to new device registrations made after the flag is configured.
      • For Intune-enrolled devices, the flag also applies to registrations made through the Intune Company Portal app, even before the device becomes MDM-managed.
      • For all other registrations, the flag takes effect only after the device is MDM-managed and the Microsoft Enterprise SSO plug-in profile is active.
      Microsoft Enterprise SSO plug-in for Apple Devices.
    • Option B: Configure Platform SSO for macOS. Platform SSO uses hardware-backed storage by default and requires no extra flag configuration.default. For setup instructions, see Configure Platform SSO for macOS devices in Microsoft Intune.

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…