Praveen Balan
Praveen Balan
  • 72
  • 723 353
MacOS Platform SSO (Single Sign On) | Microsoft Intune & Company Portal; Local Account Password Sync
With Platform Single Sign-on (Platform SSO), developers can build SSO extensions that extend to the macOS login window, allowing users to synchronise local account credentials with an identity provider (IdP) and here we sync it with Microsoft Entra ID (AAD). The local account password is automatically kept in sync, so the cloud password and local passwords match. Users can also unlock their Mac with Touch ID and Apple Watch
Platform SSO requires the following:
macOS 13 or later
A mobile device management (MDM), here we use Microsoft Intune, solution that supports the Extensible Single Sign-on payload which includes support for Platform SSO
Support from the IdP, here Microsoft Entra ID, for the Platform SSO authentication protocol
One of two supported authentication methods:
Authentication with a Secure Enclave-backed key: With this method, a user who logs in to their Mac can use a Secure Enclave-backed key to authenticate with the IdP without a password. The Secure Enclave key is set up with the IdP during the user registration process.
Password authentication: With this method, a user authenticates with a local password or an IdP password.
In this video I use Secure Enclave, but the same steps by just changing the selection works for Password Auth as well.
More Read - support.apple.com/en-in/guide/deployment/dep7bbb05313/web
Configure Intune, refer - learn.microsoft.com/en-us/mem/intune/configuration/platform-sso-macos
Intune Config Info: learn.microsoft.com/en-us/mem/intune/configuration/platform-sso-macos#step-2---create-the-platform-sso-policy-in-intune
-Praveen
Переглядів: 935

Відео

New Outlook | Perform Spell (Spelling & Grammar) Check and Attach another email/outlook Item
Переглядів 8 тис.5 місяців тому
Getting started with the new Outlook for Windows. In this video, I have covered two very important feature that most of us use in everyday business. 1. How to Perform Spell Check on New Message Compose window 2. How to attach an email item into a new Outlook message. Both the feature is slightly different in new Outlook, but not too difficult to achieve. I also acknowledge that the new Outlook ...
Mac OS (macOS) Enrollment & Microsoft Intune. Using the Company Portal app
Переглядів 1,2 тис.6 місяців тому
Configure Intune for MacOS Enrollment & Enroll your macOS device using the Company Portal app. This video will help you setup Intune for enrolling your first Mac device. Following are covered. - Configure Intune for Mac MDM capability - Install Company Portal app on MacOS device - Enroll Mac device using company portal app - Verify Intune post the enrollment. Reference Links: Intune Setup: lear...
Avatars for Microsoft Teams, connect with presence without turn on the cameras, engage with fun..
Переглядів 3288 місяців тому
Avatars for Microsoft Teams lets your users connect with presence in Teams without having to turn on their cameras. The video covers the following, Download Avatar App in Microsoft Teams Create and Customize Avatars Use Avatars in Meeting, at the start or during the meeting. Important Notice: Teams users can access this feature if they have one of the following licenses: Teams Essentials, Micro...
Out Of Office from New Teams, Sync with Outlook Automatic Reply, An easy and quick way to set OOO.
Переглядів 78 тис.9 місяців тому
Set Out Of Office message from Microsoft Teams NEW platform now same as Outlook Automatic Reply | New Feature Setting OOO from Teams is faster and simpler in nature. Go to Settings section, and configure "Out Of Office" section with the necessary options. Teams covers same as Outlook Automatic Reply settings, and make it simple. -Praveen
Microsoft New Teams App, Faster, Lighter. How to Switch & Rollback. Fix common transition issues.
Переглядів 6 тис.9 місяців тому
New Teams Launched by Microsoft. Microsoft has made it very simple for users to switch to the new app. This video will help what you can expect when you try to switch to the new Teams from the current classic teams. What I liked the most in this transition is the ability to go back to the classic teams. This means, the new Teams is altogether a new application in your PC and which is more light...
Windows Autopilot, Microsoft Intune Profile to Enroll PC. Configure user driven setup of new Laptops
Переглядів 2 тис.9 місяців тому
Intune Autopilot / Windows Autopilot Windows Autopilot is a collection of technologies used to set up and pre-configure new devices, getting them ready for productive use. When new Windows devices are initially deployed, Windows Autopilot uses the OEM-optimized version of Windows client. This version is preinstalled on the device, so you don't have to maintain custom images and drivers for ever...
Uninstall Win32 apps using the Windows Company Portal | Microsoft Intune Endpoint Manager
Переглядів 3,3 тис.Рік тому
End-users can uninstall Win32 apps and Microsoft store apps using the Windows Company Portal if the apps were assigned as available and were installed on-demand by the end-users. In few simple steps, you can enable the feature of uninstalling application on company portal published Win 32 apps. After you successfully installed the application from company portal. If you want to uninstall the ap...
Intune KIOSK Mode Settings Single-App Windows 10 & 11 | Device Configuration & Edge Browser Profiles
Переглядів 18 тис.Рік тому
Windows 10/11 and newer device settings to run as a kiosk in Intune On Windows 10/11 devices, you can configure these devices to run in single-app kiosk mode. On Windows 10 devices, you can configure these devices to run in multi-app kiosk mode Single app, full-screen kiosk is what we have discussed in this video. You need to create a Device Configuration Profile and and Edge device restriction...
Windows Intune LAPS + Azure Active Directory. Now Available and Easy Steps to Configure
Переглядів 7 тис.Рік тому
Windows LAPS has been revamped to integrate into the Windows platform to securely rotate and backup passwords using Microsoft Entra, Azure Active Directory aka Azure AD. IT admins can use the first-class management experiences built into Intune to configure Windows LAPS and leverage the capabilities that are now available. Pre-requisites - Client level To use Windows LAPS in Intune, ensure you’...
Upgrade Windows 11 Home Edition to Pro and Enterprise Version | Quick & Easy way
Переглядів 11 тис.Рік тому
Upgrade Windows 11 Home Edition to Pro and Enterprise Version. The upgrade of Windows 11 Home edition to Enterprise Edition is quite easy, if you already have a product key. Please note, here in this video I have demonstrated how I upgraded my person laptop which came with Windows 11 Home edition to an Enterprise version with an Enterprise version by entering MAK Product Key. Post the upgrade, ...
Silent BitLocker Encryption Policy Intune, Windows 10 & 11; OS & Fixed Drives | Standard, Admin User
Переглядів 8 тис.2 роки тому
Intune Policy for BitLocker Device OS & Fixed drive Encryption in Windows BitLocker is available on devices that run Windows 10/11. Some settings for BitLocker such as silent encryption which we will be discussing in this video require the device have a supported TPM. What we cover here are, Create and deploy Intune BitLocker policy Silently enable BitLocker on devices Monitor disk encryption B...
Intune Enrollment limit & type restriction policy | Windows iOS Android | Microsoft Endpoint Manager
Переглядів 4,8 тис.2 роки тому
Set enrollment restrictions in Intune Admin Center or Microsoft Endpoint Manager. As an Intune administrator, you can create and manage enrollment restrictions that define 1. Limit number of devices a user can be enrolled. 2. Operating system (OS) types and versions allowed. 3. Type of enrollment (Personal or Corporate) You can create multiple restrictions and apply them to different user group...
Microsoft Intune Endpoint Manager Device Compliance Policy setup | MDM, BYOD | Windows, iOS, Android
Переглядів 5 тис.2 роки тому
Deployment guide: Microsoft Intune Endpoint Manager Device Compliance Policy Creation & Assignment Issue/Requirement Statement: All devices enrolled in Intune (Microsoft Endpoint Manager) must be checked for compliance before allowing access to Cloud Applications How to achieve: 1. Creation Compliance Policies for all type of devices (Windows, Android, Mac and iOS/iPADOS) 2. Assign the complian...
Teams Meeting options, settings & permissions | Disable & Enable Mic, Camera, Chat & Reactions
Переглядів 3,1 тис.2 роки тому
Teams Meeting options, settings; Manage permissions and Change participant settings and more. Although default participant settings are determined by an org's IT admin, the meeting organizer may want to change them for a specific meeting. The organizer can make these changes on the Meeting options web page. What I covered in this vides are listed below. 1. Why the Meeting options are important ...
Microsoft Intune Endpoint Manager MEM | iOS, iPadOS enrollment | MDM | Enroll iPhone | Admin Part-3
Переглядів 4,5 тис.2 роки тому
Microsoft Intune Endpoint Manager MEM | iOS, iPadOS enrollment | MDM | Enroll iPhone | Admin Part-3
Microsoft Intune Endpoint Manager (MEM) | Android Enrollment setup steps | BYOD | MDM | Admin Part-2
Переглядів 13 тис.2 роки тому
Microsoft Intune Endpoint Manager (MEM) | Android Enrollment setup steps | BYOD | MDM | Admin Part-2
Microsoft Intune (MEM) | Windows Enrollment setup for Azure AD joined, AD registered | Admin Part-1
Переглядів 12 тис.3 роки тому
Microsoft Intune (MEM) | Windows Enrollment setup for Azure AD joined, AD registered | Admin Part-1
OneDrive, remove Share permissions of files & folders, review access of OneDrive for Business Shares
Переглядів 18 тис.3 роки тому
OneDrive, remove Share permissions of files & folders, review access of OneDrive for Business Shares
Delete Expired Exchange Server SSL Certificate, "warning: tagged with Send Connector", Exchange|O365
Переглядів 7 тис.3 роки тому
Delete Expired Exchange Server SSL Certificate, "warning: tagged with Send Connector", Exchange|O365
Zoom Breakout Rooms | Enabling, Pre-assigning participants, Features, Recovering | How to Guide
Переглядів 6743 роки тому
Zoom Breakout Rooms | Enabling, Pre-assigning participants, Features, Recovering | How to Guide
Set OneDrive for Business as Teams recording location | Admin PowerShell to update Meeting Policy
Переглядів 2493 роки тому
Set OneDrive for Business as Teams recording location | Admin PowerShell to update Meeting Policy
Refresh Button in Windows 11, Found Missing | Locate Refresh button | Windows 11 Tips
Переглядів 2,3 тис.3 роки тому
Refresh Button in Windows 11, Found Missing | Locate Refresh button | Windows 11 Tips
Windows 11 Upgrade (Preview) | Enroll (link) Windows Insider Program and install updates
Переглядів 3453 роки тому
Windows 11 Upgrade (Preview) | Enroll (link) Windows Insider Program and install updates
Delete & Restore User, Disable, enable & deactivate Accounts |M365, Office 365|Azure AD, PowerShell
Переглядів 9 тис.3 роки тому
Delete & Restore User, Disable, enable & deactivate Accounts |M365, Office 365|Azure AD, PowerShell
Outlook Signatures, how to create use multiple signatures, Professional free Signature templates
Переглядів 3,8 тис.3 роки тому
Outlook Signatures, how to create use multiple signatures, Professional free Signature templates
Microsoft Authenticator, Login without Password to Hotmail, Outlook | Password less | Fast, Secure
Переглядів 23 тис.3 роки тому
Microsoft Authenticator, Login without Password to Hotmail, Outlook | Password less | Fast, Secure
Cropping Sources in OBS Studio, Alt key in Windows or Option in Macbook | How to fast crop
Переглядів 3,9 тис.3 роки тому
Cropping Sources in OBS Studio, Alt key in Windows or Option in Macbook | How to fast crop
Out Of Office status message from Teams, Sync with Outlook Automatic Reply, An easy way to set
Переглядів 81 тис.3 роки тому
Out Of Office status message from Teams, Sync with Outlook Automatic Reply, An easy way to set
Enable Self-service password reset (SSPR), Azure AD Connect Password Writeback | Active Directory
Переглядів 4,4 тис.3 роки тому
Enable Self-service password reset (SSPR), Azure AD Connect Password Writeback | Active Directory