GuideInformationBusiness ContinuityIT

Replace a legacy Mac SSO profile without leaving competing payloads

How should a Mac move from a legacy SSO extension profile to Platform SSO?

Paired infrastructure paths converging on a stable recovered service.
DSE visual intelligenceContinuity & recoveryGuide · 2 min read
Executive summary

What you need to know

How should a Mac move from a legacy SSO extension profile to Platform SSO?

Potentially affected

Inventory the existing SSO payloads and enrollment affinity before building the replacement. Check supported macOS and Company Portal requirements against the source, and select the intended authentication method explicitly.

DSE recommendation

Prepare a migration map from each old assignment to the single intended Platform SSO policy.

Source facts

Microsoft directs administrators to remove the old Device Features SSO extension assignment after confirming the Platform SSO settings-catalog policy works; keeping both can cause conflicts. A mixed macOS 13 and 14-or-later population needs the respective authentication settings in one profile. For devices with user affinity, Platform SSO assignments must use users or user groups, without assignment filters. Microsoft Learn.

Applicability

Inventory the existing SSO payloads and enrollment affinity before building the replacement. Check supported macOS and Company Portal requirements against the source, and select the intended authentication method explicitly.

DSE recommendation

Prepare a migration map from each old assignment to the single intended Platform SSO policy. Include the correct version-specific settings in that policy rather than splitting the same population across competing payloads. Pilot the new configuration with a small authorized group and plan the old assignment’s removal as a separate, recorded checkpoint after verification.

Verification

Confirm registration and inspect the delivered Platform SSO profile on the test Mac. Exercise the required sign-in and protected application access with its user, then verify that the obsolete extension profile is no longer assigned. Recheck mixed-version and shared-device cases against their own supported assignment paths. If conflicting payloads or unexpected access failures appear, stop expansion and reconcile the actual delivered profiles before changing unrelated authentication controls.

Official references

Microsoft Learn: Configure Platform SSO for macOS devices.

Primary reference

Review the official source

Configure Platform SSO for macOS devices - Microsoft Intune | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE