Share via

How to stop Mac Mini from prompting for keychain on SSO login

Adrian Caswell 10 Reputation points
2025-09-30T12:04:32.9866667+00:00

A new Mac Mini has been enrolled into Intune via company portal app, and secured with SSO. The user signs in with their M365 credentials. We have 10 new Mac mini's all working OK this way. However, one user has somehow triggered the Mac to prompt for the creation of a Keychain and it asks for password. There are no smart cards attached to the machine, and smart card is not enabled in our tenant. No other machine or user account prompts for this. Another user can log into the same machine and are not prompted for a keychain. It is only the one user account. When entering a password or cancelling, MacOS just resets the login, rendering the machine unusable for this user only. Bur it's all OK for any other user. We found this user's account in Entra had applications associated with it which we have removed, but the problem persists. Has anyone got any ideas as to how we can resolve this?

Microsoft Security | Intune | Microsoft Intune MacOs

4 answers

Sort by: Most helpful
  1. JP 0 Reputation points
    2025-11-11T05:06:36.2866667+00:00

    I managed to fix the login loop problem with Platform SSO on macOS. The issue was caused by having the authentication method set to Password, which is now deprecated and not recommended by Microsoft. After wiping and re‑enrolling the Mac, I updated the Platform SSO configuration to use Secure Enclave instead. With Secure Enclave enabled, users can now sign in at the login window using their Microsoft Entra ID credentials, and the repeated login prompts are gone.

    Unfortunately, the account created on the Mac is a local account, and its password is not synchronized with the user’s Microsoft Entra ID credentials. The local password is set at the time of first login and remains independent, even if the Entra ID password is later changed.

    0 comments No comments

  2. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more

  3. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more

  4. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.