Platform SSO with Entra on Tahoe - Is it working in Beta 1

This test setup is Jamf Pro as the MDM with Entra as the IdP. PSSO is working on Sequoia devices.

Prior to Tahoe, PSSO required the following three items: An existing local account, the delivery of Company Portal, and a profile containing PSSO payload.

Based on the Tahoe announcement, it looks like PSSO is now available during Setup Assistant, removing the requirement of first creating a local account. I assume this means that the requirements now as easy as deploying Company Portal and the PSSO profile during the Pre-Stage policy.

I attempted this on the macOS 26 beta 1 and during Setup Assistant, with the PSSO profile delivered, Setup Assistant prompts me to login to my IdP. However, pressing Continue will result in a failure, notifying me that the application required is not available. The continue button is now inactive but a "try again" button is available. This results in the loop of trying and then failing, stating that the required application is not available. I eventually must quit Setup Assistant which exits it and drops me at the login window. The only account that is visible is the management account. A trip into DFU and an IPSW restore then follows.

Am I trying this too soon? Is PSSO at Setup Assistant not yet fully supported? Is there another requirement other than delivering Company App in the prestige alongside the profile?

I've enabled the beta channel in MAU but there is no newer Company Portal being offered.

Any guidance here would be appreciated as this is the PSSO announcement I've been waiting for since the deprecation of Apple Enterprise Connect.

Interesting. I haven't been able to get the SSO to prompt during setup at all. Entra asks after setup is done but nothing during enrollment/setup.

Trying with Beta 8 now.

Updated to Beta 8 and SSO still did not show up. I got it to appear by backing out of the first user account creation step.

However once SSO initiated I got this error:

The single sign on extension could not validate the domain

Since this same profile works as expected with a logged in local user account, I suspect this error message is in error.

Platform SSO with Entra on Tahoe - Is it working in Beta 1
 
 
Q