Skip to main content

Configure Extensible Single Sign-On Profile

The Extensible Single Sign-On profile enables administrators to set up an app extension that achieves single sign-on functionality on enrolled devices. 

note

This profile is supported on iOS 13 or higher devices.

To configure an app extension that performs Single Sign-On on enrolled devices, follow these steps:

  1. On the SureMDM Web Console, navigate to Profile > iOS/iPadOS > Add > Extensible Single Sign-On > Configure.

  2. Enter a Profile Name and click Add.

  3. Configure Single Sign-On Settings and click Add.

SettingsDescription
SSO ProviderChoose the identity provider responsible for handling Single Sign-On authentication for this configuration.
- Microsoft Authenticator for SSO
- Manual Configuration
Extension IdentifierEnter the bundle Id of the app extension that performs single sign-on for the specified URLs.
Applicable only if Manual Configuration is selected as SSO Provider.
Single Sign-On TypeSelect the SSO type.
- Credential
- Redirect
Applicable only if Manual Configuration is selected as SSO Provider.
RealmEnter the Realm name for the credential payload.
Applicable only if Manual Configuration is selected as SSO Provider and Credential as Single Sign-On Type.
HostEnter the array of hostnames or domain names that are authenticated using app extensions.
Applicable only if Manual Configuration is selected as SSO Provider and Credential as Single Sign-On Type.
URLsAn array of URL prefixes of identity providers where the app extension performs SSO.
Shared Device ModeEnable this option to configure Microsoft Authenticator in Shared Device mode for a seamless user experience and secure sharing across the organization. Available in iOS 14.0 / iPadOS 14.0 or later.
Applicable only if Microsoft Authenticator for SSO is selected as SSO Provider.

The configured entries will appear in the table on the DNS Settings screen.

  1. Click Save.
    The newly created profile will be listed in the Profiles section.

  2. Go back to the Home tab and select the iOS/iPadOS device(s) or group(s).

  3. Click Apply to launch the Apply Job/Profile To Device prompt.

  4. In the Apply Job/Profile To Device prompt, select the created profile and click Apply.