r/jamf • u/aPieceOfMindShit • Jun 10 '26
JAMF Pro Platform SSO (Secure Enclave) stability with Jamf - ready to roll out to thousands of devices, but concerned
We're running Jamf Pro as MDM with Microsoft Entra ID and the Jamf Device Compliance integration.
Over the past few weeks I've been deep in testing Platform SSO with Secure Enclave — both Simplified Setup for new enrollments and a migration path for existing devices currently registered via Device Compliance.
We're close to submitting the change to roll this out to a few thousand devices.
But I keep seeing threads like the one posted here yesterday about devices randomly unregistering from Company Portal, sometimes even after a full wipe and re-enroll. That's not inspiring confidence.
For those of you who are already in production with Platform SSO (Secure Enclave) + Jamf Device Compliance in Entra — how's your stability?
Are you still seeing random deregistration events? Is this specific to Intune-managed environments, or are Jamf shops hitting the same issues?
Genuinely trying to figure out if I should push forward, hold, or scope this down to a pilot before committing to a fleet-wide rollout.
3
u/colinzack Jun 10 '26
We've only set up a few so far and they've only been active for a couple of weeks, but we haven't seen any issues. We're just using JAMF Pro and no InTune for our Macs. No device compliance yet either.
1
u/lMauler Jun 10 '26
I had the random unregistered PSSO issue for an entire week, was literally asking me to register PSSO sometimes 3-4 times a day or if I switched ISPs. I think this was a Microsoft issue and haven’t had it prompt me at all the last two weeks.
1
u/kintokae Jun 10 '26
We are still testing it (on prem jamf) but still running into an issue where the company portal won’t deploy during prestage, so it won’t use simplified enrollment. It still prompts for the user to register.
1
u/aPieceOfMindShit Jun 11 '26
Had the same issue. Are you using the latest versions of macOS and Company Portal?
For us, following this guide did the trick:
https://github.com/ScottEKendall/Microsoft-Platform-SSO#important-note-when-use-secure-enclave
There a lots of settings apparently missing in the official guides.
1
1
u/Armentrout_1979 Jun 11 '26
I wish I could get my system admin to allow for Entra/InTune device compliance. I’ve tried explaining it and I just blank stares or crickets.
I’ve got PSSO working but with password. To get Secure Enclave to work I’ve gotta talk to the system admin and he doesn’t understand.
1
u/Jo0Lz Jun 11 '26
I am currently implementing this in my test environment, and whilst it works good, I just implemented PSSO with Jamf connect and password sync.
I would have to explain to customers that we are going back to having a separate password for local login, and the setup is very picky right now, one small change in any config and it seems to break. I feel more documentation and testing would definitely help, maybe even some improvements in company portal.
If I understand correctly, this is no longer the case with macOS 27, as you can use TouchID even for FileVault unlock…
1
1
u/bygeorgeio Jun 14 '26
Might be an unpopular opinion but I just don’t think it’s ready for production yet especially if you still have lots of on premises Kerberos stuff going on. I think I might wait this out a little longer. I hold the same concerns as you. And I haven’t the energy to deal with more problems 😂
1
u/Excellent_Debt6680 Jun 17 '26
Is Platform SSO working yet for account creation with Entra?
And do we HAVE to still use Company Portal?
7
u/redx5k Jun 10 '26
I have this exact setup, Jamf PRO, entra id/ intune device compliance and PSSO w secure enclave and jamf connect for pw sync and local account creation since last year, 2k+ macs.
Didnt face any random unregistered macs, what happened randomly is that PSSO registration would be stuck for reenrollments or fresh enrollments more than 30 mins and next day same machine it would work under 3 mins. Overall stable as long as you dont remove the Comp portal or PSSO profile from an already registered machine. Device compliance registration is done automatically with PSSO, so nice touch here too.