惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

有赞技术团队
有赞技术团队
美团技术团队
博客园 - 司徒正美
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
阮一峰的网络日志
阮一峰的网络日志
S
SegmentFault 最新的问题
博客园_首页
雷峰网
雷峰网
V
V2EX
The Cloudflare Blog
博客园 - 三生石上(FineUI控件)
量子位
Last Week in AI
Last Week in AI
人人都是产品经理
人人都是产品经理
爱范儿
爱范儿
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
博客园 - 聂微东
V
Visual Studio Blog
Hugging Face - Blog
Hugging Face - Blog
博客园 - 【当耐特】
Jina AI
Jina AI
月光博客
月光博客
L
LangChain Blog

Omnissa

Discover which solution is best for you: VDI, DaaS, or RDSH From on-prem to cloud: how Horizon licensing adapts to you Inside the Forrester TEI findings: Workspace ONE UEM delivered 170% ROI As security continues to evolve, has your mobile strategy? Introducing automated enrollment for Horizon Cloud desktops with Workspace ONE UEM Omnissa and GEMA partner to empower organizations with a modern digital sovereignty solution Attention Omnissa Intelligence users: Show off your dashboard! How P&O Cruises and Cunard manage devices & IT support at sea Omnissa Solution Exchange: Discover additional ways to maximize your Omnissa investments Horizon Cloud on vSphere: Hybrid DaaS made easy 10 challenges that hold back Horizon success Omnissa named a Leader in the 2025 Gartner® Magic Quadrant™ for Desktop as a Service Omnissa scores highest in 4 out of 4 Use Cases in 2026 Gartner® Critical Capabilities for Endpoint Management Tools Enabling the Modern Workforce with Omnissa Workspace ONE and Samsung Knox Suite Point of view: The autonomous workspace will reshape the role of enterprise IT Introducing Workspace ONE UEM 2602: A feature packed release with updates across the board Why security fundamentals matter more than ever Android XR Management with Workspace ONE What's new with DEX for Horizon: expanding partner ecosystems and integrations Customer adoption grows for Omnissa Horizon deployments on Nutanix AHV Optimize secure, seamless workspaces with IGEL and Omnissa Omnissa Secure Access Suite delivers secure browser functionality with the Omnissa platform ICYMI: Highlights from our “App Management Reimagined” event Omnissa Pass: Native MFA for stronger, simpler security Modern education—any device, everywhere learning with smarter IT DEX is a value strategy: How Omnissa helps turn IT from cost center to value engine From fragmentation to fruition: Why a platform approach wins Mod Stack architecture: Rebuilding for flexibility, scalability, and resilience New Omnissa 2026 study finds shadow AI, security gaps, and device instability expose need for end-to-end IT observability Omnissa accelerates global market momentum with strategic board expansion and executive leadership appointment
Workspace ONE supports Platform SSO with Entra ID via Sec...
Samidha Suhas Rege · 2025-12-16 · via Omnissa

Workspace ONE Intelligent Hub is expanding its Apple platform capabilities with support for Platform Single Sign-On (PSSO) on macOS, integrated with Microsoft Entra ID and secured by Apple's Secure Enclave.  This integration marks a major step forward in enabling modern authentication workflow on macOS for organizations leveraging Microsoft 365, Conditional Access, and device compliance policies via Entra ID. 

What Is Secure Enclave-based device identity? 

Secure Enclave is Apple’s hardware-based security coprocessor that stores cryptographic keys in an isolated environment. By leveraging Secure Enclave, Workspace ONE Intelligent Hub ensures tamper-resistant credential storage and alignment with Apple’s latest security standards. 

Why leverage Secure Enclave? 

To support PSSO with Microsoft Entra ID 

Apple introduced PSSO   framework to enables users to sign in once at the macOS login screen and automatically gain access to Entra ID–protected apps and services.  Secure Enclave securely stores the macOS device identity, allowing Microsoft’s Enterprise SSO plug-in to seamlessly single sign-on into Microsoft 365 and custom MSAL-based apps and silently authenticate with device trust included. 

Full Conditional Access enforcement 

While Workspace ONE has long participated in Microsoft's Partner Compliance Program to support Conditional Access for macOS, the existing Keychain-based integration has limitations, especially in device identity and compliance scenarios. This is primarily because Microsoft Conditional Access evaluates device trust using the Microsoft identity platform, not the underlying Apple Keychain - a secure local storage for credentials, that Apple devices traditionally used to store device identity keys for Entra AD.  

In 2025, Microsoft began transitioning away from storing device credentials in the macOS Keychain.  New device registrations will require Secure Enclave–based identity keys, slowly phasing out the Keychain approach. This transition provides stronger, hardware-backed security and aligns with the latest Entra ID architecture. 

Refer Microsoft Enterprise SSO plug-in for Apple devices  for more details. 

Why are we updating Intelligent Hub for macOS? 

For Workspace ONE to maintain full compatibility with Microsoft Conditional Access, ensure seamless policy enforcement like device compliance and app-based restrictions, and future-proof its compliance posture, it is critical to adopt Secure Enclave–based device identity.  To do this we have updated Intelligent Hub for macOS 25.11 version to support Secure Enclave-based identity keys. To support this capability, Microsoft requires the Microsoft Enterprise SSO Plug-in application (Company Portal App) to be installed on the device – as this is used to register devices with Entra ID and store the identity in the Secure Enclave. 

 How does this impact you? 
  • Stronger security posture - Secure Enclave isolates credentials in hardware, reducing risk of tampering or extraction.
  • Conditional Access compliance - Ensures consistent policy enforcement using both user and device identity — enabling full support for Conditional Access scenarios.
  • Seamless user experience - Users sign in once at login and gain SSO across all Microsoft-authenticated apps and browsers. 

Summary 

Workspace ONE’s support for Secure Enclave–based Platform SSO with Microsoft Entra ID ensures secure, seamless access to enterprise apps — while meeting Microsoft’s latest identity standards and Conditional Access requirements. This essential update empowers macOS environments using Microsoft 365 and Entra ID to transition from Keychain-based identity to a modern, hardware-backed authentication model. 

Back to insights