Deploy the Microsoft Authenticator SSO Payload and Application (iOS/ iPadOS)

Deploy the Microsoft Authenticator SSO payload and required apps to enable seamless sign-in on iOS/iPadOS devices.

Before you begin

Ensure that you have completed the following configuration steps:
  1. Add a Microsoft Authenticator SSO Payload (iOS/iPadOS).
  2. Connect Microsoft Entra ID for Microsoft Authenticator SSO (iOS/ iPadOS).
  3. Configure Conditional Access for Microsoft Authenticator SSO (iOS/iPadOS).
  4. Define Extensible SSO for Microsoft Authenticator SSO (iOS/ iPadOS)

About this task

This is the fifth step in configuring Microsoft Authenticator Single Sign-On (SSO) for your iOS/ iPadOS devices. See Configuring Microsoft Authenticator Single Sign-On (iOS/ iPadOS).

In this step, you assign the configured SSO payload and deploy the Microsoft Authenticator app, along with any Microsoft Authentication Library (MSAL) apps that require SSO support.

Procedure

  1. After configuring the Microsoft Authenticator SSO payload, assign the profile to your target iOS/ iPadOS devices. See Assigning a Profile.
    A prompt appears, asking you to deploy the Microsoft Authenticator application.
    The Microsoft Authenticator prompt appears upon deploying the Microsoft SSO configuration.
  2. Create an iOS/ iPadOS app policy that includes the Microsoft Authenticator app and any MSAL apps that will use SSO. See Using App Policies for instructions.
  3. In the app policy settings for the Microsoft Authenticator application, configure the following:
    • Set the deployment type to Mandatory.
    • Enable Prevent removal of app by device user.
    Making the Microsoft Authenticator application mandatory and preventing users from uninstalling the Microsoft Authenticator application's advanced configuration options.
    Important: You must also deploy the SOTI MobiControl iOS/iPadOS agent as a mandatory application and prevent users from removing it.

Results

The Microsoft Authenticator SSO configuration and the required applications successfully deploy to your iOS/iPadOS devices.

What to do next

Complete the configuration by registering devices with Microsoft Authenticator SSO. See Register Devices for Microsoft Authenticator SSO (iOS/ iPadOS).