Forum Discussion

almennn's avatar
almennn
Brass Contributor
Mar 25, 2020

iOS Single Sign On Extension

Anybody tried to configure the new Azure AD single sign on extension for iOS?

I get the profile on the device and I have Authenticator but it seems like it’s doing absolutely nothing..

3 Replies

  • almennn's avatar
    almennn
    Brass Contributor

    I now know what some of the limitations are in the first release of the extension. I did write about it if someone is interested: https://almenscorner.io/

  • Moe_Kinani's avatar
    Moe_Kinani
    Bronze Contributor
    I don’t think it works if you refer to IOS profile in article below. I actually opened tickets with MSFT and Apple and no luck!

    I have changed my direction to use Auth app (Setting->Device Registration) and register IOS device, then use Edge to access O365 apps with SSO. It works like charm!

    https://docs.microsoft.com/en-us/mem/intune/configuration/device-features-configure
    • almennn's avatar
      almennn
      Brass Contributor

      This is what I'm trying to use: https://docs.microsoft.com/en-us/mem/intune/configuration/ios-device-features-settings#single-sign-on-app-extension

       

      I don't think this is an issue with Apple but rather with the host app, e.g. Authenticator. I don't know if an update has been released for the Authenticator app to support this as I cannot find any details on that.

       

      That's one way to go but I don't think it's enough since customers have native applications that use webview to do a SAML sign-in from the app. It's better to use these extensions as it supports a wide variety of authentication scenarios on iOS.

       

      I would like to know if Microsoft just released the settings within MEM but has not yet updated Authenticator to support it. Intune_Support_Team