Share via

Office problem with macOS + Intune + Platform SSO

Jesper Kristensen 5 Reputation points
2026-05-18T12:15:21.47+00:00

Hello community,
We have a large number of Macs in our organization, and we are experiencing an issue where, after a Mac wakes from sleep, Microsoft Office applications and Teams prompt the user to sign in again.

The user can simply click the sign-in button, and everything starts working normally again. However, we would like to understand why this behavior occurs.

Is there a way to prevent this prompt and allow the authentication to happen automatically instead?

Microsoft Security | Intune | Microsoft Intune MacOs
0 comments No comments

2 answers

Sort by: Most helpful
  1. Jesper Kristensen 5 Reputation points
    2026-05-18T12:17:55.5333333+00:00

    We already has Platform SSO Enclave in our setup

    Was this answer helpful?

    0 comments No comments

  2. Q&A Assist
    2026-05-18T12:15:36.79+00:00
    AI generated content. This question contains an answer created with AI from Q&A Assist. Learn more

    On macOS with Intune and Microsoft Entra–based auth, repeated sign-in prompts after sleep typically occur because each Office/Teams app is re-establishing its Microsoft Entra session and keychain access when the device wakes. If SSO isn’t fully configured, or if each app is handling auth independently, users see a sign-in button instead of a silent re-authentication.

    To reduce or eliminate these prompts and move toward automatic authentication, use single sign-on (SSO) for macOS with Intune and the Microsoft Enterprise SSO plug-in:

    1. Configure the Microsoft Enterprise SSO plug-in in Intune
      • In Intune, create and deploy an SSO policy for macOS using the Platform SSO / SSO app extension options that are part of the Microsoft Enterprise SSO plug-in for Microsoft Entra ID.
      • This allows supported apps (including Microsoft 365 apps like Teams and Office) to reuse the same Microsoft Entra session instead of prompting individually.
    2. Ensure apps support and use SSO
      • Most Microsoft 365 apps on macOS support SSO via the plug-in. When combined with the Intune SSO policy, the number of credential prompts is reduced because apps can silently obtain tokens.
    3. Handle keychain prompts correctly when using Jamf + Intune
      • If Jamf Pro is also in use with Intune conditional access, users may see prompts such as:

        "Microsoft Teams wants to sign using key 'Microsoft Workplace Join Key' in your keychain."

      • In that case, instruct users to choose Always Allow so the app can reuse the stored keychain item and avoid repeated prompts. Each app must be approved once; cached credentials for one app can’t be used by another until it is also set to Always Allow.
    4. Expected behavior after configuration
      • With Platform SSO / SSO app extension correctly deployed and users having allowed keychain access, Office apps and Teams should be able to silently refresh tokens after sleep in most cases, significantly reducing or eliminating visible sign-in prompts.

    If prompts still appear after SSO is configured, verify that:

    • The SSO policy is successfully applied to the device.
    • The apps are updated and support the Microsoft Enterprise SSO plug-in.
    • Users have not denied keychain access for the relevant Microsoft keys.

    References:

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.