AzureAD Single Sign On (SSO)

AzureAD Single Single On (SSO) is both an application (Company Portal.app) and a Configuration Profile applied to Jamf enrolled Macs for authentication purposes to DOI Azure Active Directory. Once applied, applications that rely on DOI Active Directory Federated Services should automatically authenticate with AzureAD SSO.

What’s the difference between AzureAD SSO and Apple Kerberos SSO?

Azure AD SSO …

Read More…

SSH with GSSAPI

Generic Security Service Application Program Interface (GSSAPI) allows for passthrough authentication using Active Directory Kerberos Tickets. The protocol is supported on all operating systems including Windows, Mac, Linux, and Solaris. This allows for passwordless authentication. When used alongside MIT Kerberos, you can also have Kerberos tickets sent for passwordless AD authentication on the host server.

Known Issues:

Sudo will …

Read More…

Apple Kerberos Single Sign On (SSO)

Apple Kerberos Single Single On (SSO) is a Configuration Profile applied to Jamf enrolled Macs for the purposes of Kerberos Ticket Granting Tokens (TGTs) used to authenticate the user to on-premise Active Directory resources. The user must be on VPN/on the DOI Network to get a Kerberos Ticket. When the user is on the network and a ticket needs to …

Read More…