Share via

I would like to clarify the behavior of Platform SSO (PSSO) registration on macOS devices.

Mian Mudasir Bari 0 Reputation points
2026-03-27T16:48:16.5266667+00:00

We currently have Macs enrolled using Automated Device Enrollment (ADE) with Platform SSO and LAPS for Mac configured via Intune.

 

In our scenario:

  • A first user (e.g., admin account) signs in to the device and completes PSSO registration successfully.
  • When a second user signs in to the same device (in our scenario Mac local admin account), they are prompted to complete PSSO registration again.

We would like to confirm whether this behavior is expected, specifically:

  • Is PSSO registration designed to be per-user rather than per-device?
  • Is it expected that each new user signing into the same Mac must complete PSSO registration, even if another user has already registered?

 

Additionally, is there any configuration available to streamline or avoid repeated registration prompts for multiple users?We currently have Macs enrolled using Automated Device Enrollment (ADE) with Platform SSO and LAPS for Mac configured via Intune.

 

In our scenario:

  • A first user (e.g., admin account) signs in to the device and completes PSSO registration successfully.
  • When a second user signs in to the same device (in our scenario Mac local admin account), they are prompted to complete PSSO registration again.

We would like to confirm whether this behavior is expected, specifically:

  • Is PSSO registration designed to be per-user rather than per-device?
  • Is it expected that each new user signing into the same Mac must complete PSSO registration, even if another user has already registered?

 

Additionally, is there any configuration available to streamline or avoid repeated registration prompts for multiple users?

Microsoft Security | Intune | Microsoft Intune MacOs
0 comments No comments

1 answer

Sort by: Most helpful
  1. Q&A Assist
    2026-03-27T16:48:40.23+00:00
    AI generated content. This question contains an answer created with AI from Q&A Assist. Learn more

    Platform SSO (PSSO) registration on macOS is tied to the user account, not only to the device.

    From the documented behavior:

    • Each user who signs in and uses Platform SSO must complete a registration flow where they authenticate to Microsoft Entra ID and (if required) perform MFA. This process joins the device to Microsoft Entra ID and binds the workplace join (WPJ) certificate and SSO tokens to that user context.
    • After registration, the status is visible under Settings > Users & Groups > Network Account Server > Edit, where Platform SSO is shown as Registered, and the authentication method (Secure enclave, Smart Card, or Password) is associated with the signed‑in user.
    • The guidance for shared-device scenarios explicitly instructs testing with a second user by logging out, choosing Other… at the login screen, and having the new user sign in with their Microsoft Entra ID UPN and password. That second user is expected to go through the setup/registration experience and then land on the desktop.

    This confirms the following for the scenario described:

    • PSSO registration is effectively per user: each user account that will use Platform SSO must complete its own registration so that SSO tokens and authentication method are correctly associated with that user.
    • It is expected that a second user signing into the same Mac (including a local admin account that is being brought under PSSO) will be prompted to complete PSSO registration, even if another user has already registered on that device.

    Regarding configuration to avoid repeated prompts for multiple users:

    • Current guidance focuses on ensuring the Platform SSO profile is correctly deployed (via Intune), that the Registration required notification is completed, and that each user who needs SSO completes their own registration.
    • The documentation does not describe any configuration that would suppress or “reuse” an existing PSSO registration from one user for another user on the same device, nor a setting to globally bypass registration prompts for additional users. Instead, it provides troubleshooting and repair options (for example, Settings > Users & Groups > Network Account Server > Edit > Repair on macOS 14+) when registration fails or needs to be retriggered.

    Therefore, the behavior observed—each new user on the same ADE‑enrolled, Intune‑managed Mac being prompted to complete PSSO registration—is expected and aligned with the per‑user registration model. No supported configuration is documented to eliminate those per‑user registration prompts; the available controls are around deploying the PSSO profile, ensuring prerequisites are met, and repairing or retriggering registration when needed.


    References:

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.