macOS Big Sur + Azure AD auth

Sessions wwdc20-10639 references using Azure AD for authentication. Does this mean users can authenticate at the macOS login screen with Azure instead of on-prem AD? This there more documentation on this?

Replies

This was mentioned in the context of Enrollment Customization introduced last year with macOS Catalina and iOS 13, as well as later in the session in the context of federating Apple Business Manager to more easily be able to create Managed Apple IDs.

The Enrollment Customization feature allows an MDM vendor to display a custom webpage during the initial enrollment process of a device. On macOS, the information the user enters during the enrollment process can then (optionally) be used to pre-populate the user's Full Name and Account Name on the local user account creation screen during the macOS Setup Assistant (optionally locking them into place). That helps with making a local account; there is no direct ability to sign in with an Azure Active Directory account at the macOS Login Window. However, 3rd party tools, often provided by MDM vendors, can allow that to be possible if desired.