{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-151-replace-a-legacy-mac-sso-profile-without-leaving-competing-payloads/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-151-replace-a-legacy-mac-sso-profile-without-leaving-competing-payloads/",
        "slug": "dse-20260909-151-replace-a-legacy-mac-sso-profile-without-leaving-competing-payloads",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-151-replace-a-legacy-mac-sso-profile-without-leaving-competing-payloads/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-151-replace-a-legacy-mac-sso-profile-without-leaving-competing-payloads.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-151-replace-a-legacy-mac-sso-profile-without-leaving-competing-payloads/"
        },
        "title": "Replace a legacy Mac SSO profile without leaving competing payloads",
        "summary": "How should a Mac move from a legacy SSO extension profile to Platform SSO?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "continuity-recovery",
            "label": "Continuity & recovery",
            "alt": "Paired infrastructure paths converging on a stable recovered service.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:29:25+00:00",
        "modified_at": "2026-09-10T00:55:35+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 225,
        "potentially_affected": "Inventory the existing SSO payloads and enrollment affinity before building the replacement. Check supported macOS and Company Portal requirements against the source, and select the intended authentication method explicitly.",
        "dse_recommendation": "Prepare a migration map from each old assignment to the single intended Platform SSO policy.",
        "primary_source": {
            "name": "Configure Platform SSO for macOS devices - Microsoft Intune | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/intune/device-configuration/settings-catalog/configure-platform-sso-macos",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Microsoft directs administrators to remove the old Device Features SSO extension assignment after confirming the Platform SSO settings-catalog policy works; keeping both can cause conflicts. A mixed macOS 13 and 14-or-later population needs the respective authentication settings in one profile. For devices with user affinity, Platform SSO assignments must use users or user groups, without assignment filters. <a href=\"https://learn.microsoft.com/en-us/intune/device-configuration/settings-catalog/configure-platform-sso-macos\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Inventory the existing SSO payloads and enrollment affinity before building the replacement. Check supported macOS and Company Portal requirements against the source, and select the intended authentication method explicitly.</p>\n<h2>DSE recommendation</h2>\n<p>Prepare a migration map from each old assignment to the single intended Platform SSO policy. Include the correct version-specific settings in that policy rather than splitting the same population across competing payloads. Pilot the new configuration with a small authorized group and plan the old assignment’s removal as a separate, recorded checkpoint after verification.</p>\n<h2>Verification</h2>\n<p>Confirm registration and inspect the delivered Platform SSO profile on the test Mac. Exercise the required sign-in and protected application access with its user, then verify that the obsolete extension profile is no longer assigned. Recheck mixed-version and shared-device cases against their own supported assignment paths. If conflicting payloads or unexpected access failures appear, stop expansion and reconcile the actual delivered profiles before changing unrelated authentication controls.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/intune/device-configuration/settings-catalog/configure-platform-sso-macos\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Configure Platform SSO for macOS devices</a>.</p>",
        "content_text": "Source facts\nMicrosoft directs administrators to remove the old Device Features SSO extension assignment after confirming the Platform SSO settings-catalog policy works; keeping both can cause conflicts. A mixed macOS 13 and 14-or-later population needs the respective authentication settings in one profile. For devices with user affinity, Platform SSO assignments must use users or user groups, without assignment filters. Microsoft Learn.\nApplicability\nInventory the existing SSO payloads and enrollment affinity before building the replacement. Check supported macOS and Company Portal requirements against the source, and select the intended authentication method explicitly.\nDSE recommendation\nPrepare a migration map from each old assignment to the single intended Platform SSO policy. Include the correct version-specific settings in that policy rather than splitting the same population across competing payloads. Pilot the new configuration with a small authorized group and plan the old assignment’s removal as a separate, recorded checkpoint after verification.\nVerification\nConfirm registration and inspect the delivered Platform SSO profile on the test Mac. Exercise the required sign-in and protected application access with its user, then verify that the obsolete extension profile is no longer assigned. Recheck mixed-version and shared-device cases against their own supported assignment paths. If conflicting payloads or unexpected access failures appear, stop expansion and reconcile the actual delivered profiles before changing unrelated authentication controls.\nOfficial references\nMicrosoft Learn: Configure Platform SSO for macOS devices.",
        "content_markdown": "## Source facts\n\nMicrosoft directs administrators to remove the old Device Features SSO extension assignment after confirming the Platform SSO settings-catalog policy works; keeping both can cause conflicts. A mixed macOS 13 and 14-or-later population needs the respective authentication settings in one profile. For devices with user affinity, Platform SSO assignments must use users or user groups, without assignment filters. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/device-configuration/settings-catalog/configure-platform-sso-macos).\n\n## Applicability\n\nInventory the existing SSO payloads and enrollment affinity before building the replacement. Check supported macOS and Company Portal requirements against the source, and select the intended authentication method explicitly.\n\n## DSE recommendation\n\nPrepare a migration map from each old assignment to the single intended Platform SSO policy. Include the correct version-specific settings in that policy rather than splitting the same population across competing payloads. Pilot the new configuration with a small authorized group and plan the old assignment’s removal as a separate, recorded checkpoint after verification.\n\n## Verification\n\nConfirm registration and inspect the delivered Platform SSO profile on the test Mac. Exercise the required sign-in and protected application access with its user, then verify that the obsolete extension profile is no longer assigned. Recheck mixed-version and shared-device cases against their own supported assignment paths. If conflicting payloads or unexpected access failures appear, stop expansion and reconcile the actual delivered profiles before changing unrelated authentication controls.\n\n## Official references\n\n[Microsoft Learn: Configure Platform SSO for macOS devices](https://learn.microsoft.com/en-us/intune/device-configuration/settings-catalog/configure-platform-sso-macos)."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-151-replace-a-legacy-mac-sso-profile-without-leaving-competing-payloads/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-151-replace-a-legacy-mac-sso-profile-without-leaving-competing-payloads/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-151-replace-a-legacy-mac-sso-profile-without-leaving-competing-payloads/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Replace a legacy Mac SSO profile without leaving competing payloads",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-151-replace-a-legacy-mac-sso-profile-without-leaving-competing-payloads/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-151-replace-a-legacy-mac-sso-profile-without-leaving-competing-payloads/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-151-replace-a-legacy-mac-sso-profile-without-leaving-competing-payloads/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-151-replace-a-legacy-mac-sso-profile-without-leaving-competing-payloads/",
                "headline": "Replace a legacy Mac SSO profile without leaving competing payloads",
                "description": "How should a Mac move from a legacy SSO extension profile to Platform SSO?",
                "abstract": "How should a Mac move from a legacy SSO extension profile to Platform SSO?",
                "articleBody": "Source facts\nMicrosoft directs administrators to remove the old Device Features SSO extension assignment after confirming the Platform SSO settings-catalog policy works; keeping both can cause conflicts. A mixed macOS 13 and 14-or-later population needs the respective authentication settings in one profile. For devices with user affinity, Platform SSO assignments must use users or user groups, without assignment filters. Microsoft Learn.\nApplicability\nInventory the existing SSO payloads and enrollment affinity before building the replacement. Check supported macOS and Company Portal requirements against the source, and select the intended authentication method explicitly.\nDSE recommendation\nPrepare a migration map from each old assignment to the single intended Platform SSO policy. Include the correct version-specific settings in that policy rather than splitting the same population across competing payloads. Pilot the new configuration with a small authorized group and plan the old assignment’s removal as a separate, recorded checkpoint after verification.\nVerification\nConfirm registration and inspect the delivered Platform SSO profile on the test Mac. Exercise the required sign-in and protected application access with its user, then verify that the obsolete extension profile is no longer assigned. Recheck mixed-version and shared-device cases against their own supported assignment paths. If conflicting payloads or unexpected access failures appear, stop expansion and reconcile the actual delivered profiles before changing unrelated authentication controls.\nOfficial references\nMicrosoft Learn: Configure Platform SSO for macOS devices.",
                "datePublished": "2026-09-10T00:29:25+00:00",
                "dateModified": "2026-09-10T00:55:35+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-151-replace-a-legacy-mac-sso-profile-without-leaving-competing-payloads/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-151-replace-a-legacy-mac-sso-profile-without-leaving-competing-payloads/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Replace a legacy Mac SSO profile without leaving competing payloads"
                },
                "articleSection": [
                    "Business Continuity",
                    "IT"
                ],
                "keywords": [
                    "Business Continuity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 225,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Configure Platform SSO for macOS devices - Microsoft Intune | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/intune/device-configuration/settings-catalog/configure-platform-sso-macos"
                }
            }
        ]
    }
}