# Replace a legacy Mac SSO profile without leaving competing payloads

> How should a Mac move from a legacy SSO extension profile to Platform SSO?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-151-replace-a-legacy-mac-sso-profile-without-leaving-competing-payloads/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:29:25+00:00
- Modified: 2026-09-10T00:55:35+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 2 minutes

## What you need to know

How should a Mac move from a legacy SSO extension profile to Platform SSO?

## Potentially affected

Inventory the existing SSO payloads and enrollment affinity before building the replacement. Check supported macOS and Company Portal requirements against the source, and select the intended authentication method explicitly.

## DSE recommendation

Prepare a migration map from each old assignment to the single intended Platform SSO policy.

## Article

## Source facts

Microsoft directs administrators to remove the old Device Features SSO extension assignment after confirming the Platform SSO settings-catalog policy works; keeping both can cause conflicts. A mixed macOS 13 and 14-or-later population needs the respective authentication settings in one profile. For devices with user affinity, Platform SSO assignments must use users or user groups, without assignment filters. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/device-configuration/settings-catalog/configure-platform-sso-macos).

## Applicability

Inventory the existing SSO payloads and enrollment affinity before building the replacement. Check supported macOS and Company Portal requirements against the source, and select the intended authentication method explicitly.

## DSE recommendation

Prepare a migration map from each old assignment to the single intended Platform SSO policy. Include the correct version-specific settings in that policy rather than splitting the same population across competing payloads. Pilot the new configuration with a small authorized group and plan the old assignment’s removal as a separate, recorded checkpoint after verification.

## Verification

Confirm registration and inspect the delivered Platform SSO profile on the test Mac. Exercise the required sign-in and protected application access with its user, then verify that the obsolete extension profile is no longer assigned. Recheck mixed-version and shared-device cases against their own supported assignment paths. If conflicting payloads or unexpected access failures appear, stop expansion and reconcile the actual delivered profiles before changing unrelated authentication controls.

## Official references

[Microsoft Learn: Configure Platform SSO for macOS devices](https://learn.microsoft.com/en-us/intune/device-configuration/settings-catalog/configure-platform-sso-macos).

## Primary reference

- Name: Configure Platform SSO for macOS devices - Microsoft Intune | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/intune/device-configuration/settings-catalog/configure-platform-sso-macos
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Replace a legacy Mac SSO profile without leaving competing payloads,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-151-replace-a-legacy-mac-sso-profile-without-leaving-competing-payloads/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
