Configuring Microsoft Authenticator Single Sign-On (iOS/ iPadOS)

Set up Microsoft Authenticator SSO on iOS or iPadOS devices to streamline sign-in across Microsoft Authentication Library (MSAL) apps, such as Microsoft Teams or Outlook.

The Microsoft Authenticator SSO payload for iOS enables seamless Single Sign-On (SSO) and sign-out across Microsoft Authentication Library (MSAL)-integrated apps using the SOTI MobiControl iOS agent. This feature simplifies deployment by allowing administrators to configure all required prerequisites from a single, intelligent interface.

Prerequisites

  • Manage Profile permissions. See General Permissions.
  • Target devices are running iOS/ iPadOS 14 or later.
    Restriction: This feature is incompatible with Shared iPads.
  • Microsoft Entra ID (formerly Azure AD) Premium 1 or higher licenses with Microsoft Conditional Access enabled.
  • A supported Microsoft license plan ( See Microsoft license plans), such as:
    • Microsoft 365 E3, E5, F1, or F3

    • Enterprise Mobility + Security (EMS) E3 or E5

      See Assigning User Licenses In Microsoft Entra ID/Azure AD for instructions on assigning these licenses.
      Note: When adding a license for a user, select all services. Services may differ based on the subscription type.
  • iOS/ iPadOS devices enrolled using a policy that has Enable Microsoft Shared Device Mode Registration enabled.
    Toggling on the Enable Microsoft Shared Device Mode registration option in an iOS enrollment policy.
    Tip: You can enable or disable Shared Device Mode after enrollment using a device action.
    Sending the Enable Microsoft Shared Device Mode device action to an iOS device.

Workflow

  1. Add a Microsoft Authenticator SSO Payload (iOS/iPadOS)
  2. Connect Microsoft Entra ID for Microsoft Authenticator SSO (iOS/ iPadOS)
  3. Configure Conditional Access for Microsoft Authenticator SSO (iOS/iPadOS)
  4. Define Extensible SSO for Microsoft Authenticator SSO (iOS/ iPadOS)
  5. Deploy the Microsoft Authenticator SSO Payload and Application (iOS/ iPadOS)
  6. Register Devices for Microsoft Authenticator SSO (iOS/ iPadOS)