Configuring the Microsoft Enterprise SSO plug-in
Microsoft Enterprise SSO plug‑in enables seamless single sign‑on across apps and websites using corporate credentials. On shared iPads, it streamlines user login by automatically handling authentication and reducing repeated sign‑ins.
To configure, follow the steps below:
- Sign in to the Microsoft Intune admin center.
- Select Devices > Manage devices > Configuration > Create > New policy.
- Enter the following properties:
- Platform: Select
iOS/iPadOS. - Profile type: Select
Templates > Device features.
- Platform: Select
- Select Create:
- In Basics, enter the following properties:
- Name: Enter a descriptive name for the policy.
- Description: Enter a description for the policy.
- Select Next.
- In Configuration settings, select Single sign-on app extension, and configure the following properties:
SSO app extension type:
Redirect.Extension ID:
com.microsoft.azureauthenticator.ssoextensionTeam ID: Not required for iOS
URLs:
https://login.microsoftonline.com https://login.microsoft.com https://sts.windows.net https://login.partner.microsoftonline.cn https://login.chinacloudapi.cn https://login.microsoftonline.us https://login-us.microsoftonline.comAdditional configuration:
key type value AppPrefixAllowList String com.idemlon.,com.microsoft.,com.apple. browser_sso_interaction_enabled Integer 1 disable_explicit_app_prompt Integer 1