← Previous day

Next day →
Day in brief

PSSO documentation flags a macOS 15+ configuration issue; PIM and Lifecycle Workflows guidance clarified

14 August was largely a documentation-maintenance day: all 12 recorded changes were updates, with no new items, removals, or Message Center announcements. The most consequential updates document a known macOS Platform Single Sign-On (PSSO) concurrency issue, sharpen Privileged Identity Management approval guidance, clarify a Logic App Lifecycle Workflows syntax requirement, and explicitly list certificate-based authentication as a multifactor authentication strength. The evidence does not establish a product launch, availability change, or service-wide default change.

  • The updated troubleshooting page identifies a known concurrency issue on macOS 15+ (Sequoia): simultaneous updates from the system AppSSOAgent and AppSSODaemon processes can corrupt the PSSO device configuration. That corruption can trigger the operating system's re-registration remediation flow and produce unexpected registration prompts. The supplied change does not specify a remediation.

  • Updated PIM guidance recommends requiring approval for activation of eligible assignments, selecting at least one approver and preferably at least two. It also clarifies that when no specific approvers are selected, active Privileged Role Administrators and Global Administrators become the default approvers. This is documented configuration and security guidance, not evidence of a service-wide default change.

  • The Logic App Lifecycle Workflows instructions now explicitly say that the Issuer value must include the slash after the tenant ID. Owners configuring or checking this integration should validate that value; the evidence describes a configuration clarification rather than a feature release.

  • The Authentication Strengths update explicitly lists Microsoft Entra certificate-based authentication as “Multifactor.” No new availability, rollout, or policy behavior is stated, so the change should be treated as documentation clarification rather than evidence of a newly launched capability.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

12 updates

5

Macos Psso

Updated

macOS Platform Single Sign-on (PSSO) is a new feature powered by Microsoft’s Enterprise SSO plug-in, Platform Credentials for macOS that enables users to sign in to Mac devices using their Microsoft Entra ID credentials. This feature provides benefits for admins by simplifying the sign-in process for users and reducing the number of passwords they need to remember. It also allows users to authenticate with Microsoft Entra ID with a smart card or hardware-bound key. This feature improves the end-user experience by not having to remember two separate passwords and diminishes the need for admins to manage the local account password.

Integrate macOS Platform Single Sign-On (PSSO) into your MDM solution

Updated

Platform Single Sign-On (PSSO) for macOS devices is a feature that allows users to sign in to macOS devices using their Microsoft Entra credentials. This feature provides a seamless sign-in experience for users and helps organizations manage access to resources on macOS devices.

1
1
1

Troubleshoot Macos Platform Single Sign On Extension

Updated

There's a known concurrency issue on macOS 15+ (Sequoia) that can cause the PSSO device configuration to become corrupted. The device configuration can be corrupted by simultaneous updates from the system AppSSOAgent and AppSSODaemon processes. The corrupted configuration causes the operating system to trigger its re-registration remediation flow, resulting in unexpected registration prompts for users.

3

Pim How To Change Default Settings

Updated

We recommend requiring approval for activation of an eligible assignment. The approver doesn't have to have any roles. When you use this option, select at least one approver. We recommend that you select at least two approvers. If no specific approvers are selected, active Privileged Role Administrators/Global Administrators become the default approvers.

1
Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…