- Sign your employees into anny seamlessly without enabling Safari as a browser
- Use single sign-on across all apps (anny, Microsoft 365, custom apps)
- Automatically pass device compliance and device state to Conditional Access
This setup is done entirely on the IT admin side in Microsoft Intune. No changes to the anny app are required.
Prerequisites
Before setting up the SSO plug-in, make sure the following requirements are met:- iOS 13.0 or later on the devices
- Devices are enrolled in Microsoft Intune MDM
- Microsoft Entra ID (formerly Azure AD) is used as the identity provider
- The anny login goes through SAML/OIDC federation with Entra ID (the auth flow redirects to
login.microsoftonline.com)
Set Up the SSO Plug-in
1
Create SSO App Extension Profile
Open the Microsoft Intune Admin Center (intune.microsoft.com) and navigate to Devices > Manage devices > Configuration > Create > New Policy.Select the following settings:
- Platform: iOS/iPadOS
- Profile type: Templates > Device features
- Name: e.g.
iOS: SSO App Extension
- SSO app extension type: Microsoft Entra ID
- Enable shared device mode: Not configured
2
Set Recommended Configuration
Add the following key-value pairs under Additional configuration:
3
Assign the Profile
Assign the profile to a device or user group that contains your iOS devices. The settings are applied automatically at the next device check-in.
4
Deploy Microsoft Authenticator
Navigate to Apps > All Apps and make sure Microsoft Authenticator is assigned as a required app to the same device group.
The Authenticator app only needs to be installed. Your employees do not need to actively set it up or use it. The app must be obtained through an Apple Volume Purchase Program (VPP).
5
Adjust Conditional Access Policy
This is the most important step. Instead of a policy that only allows Edge as a browser, the policy should be changed to one of the following conditions:
- Require compliant device (recommended): Checks whether the device is Intune-compliant
- Require approved client app: Allows authentication via the Authenticator app
6
Test
Open the anny app on an enrolled iOS device and start the login:
- First login after setup: A short auth dialog where Entra ID credentials are entered.
- All subsequent logins: SSO kicks in automatically, no re-login needed.
Background: Why Not Just Use Edge as an In-App Browser?
iOS does not allow apps to use any browser other than Apple’s system browser (ASWebAuthenticationSession) for OAuth logins. Even if Edge is set as the default browser, iOS always uses the Safari engine internally for authentication flows.
The Enterprise SSO plug-in solves this at a deeper level: it works at the operating system level and intercepts authentication requests before a browser is opened. This means Conditional Access policies are correctly satisfied without needing to enable Safari as a browser.
FAQ
Does Safari need to be enabled on the devices?
Does Safari need to be enabled on the devices?
No. Safari can remain blocked via Intune. The SSO plug-in does not use Safari as a browser. It works at the operating system level. The auth dialog is a sandboxed system dialog, not an open browser.
Does anything need to change in the anny app?
Does anything need to change in the anny app?
No. The SSO plug-in intercepts auth requests to Entra ID automatically, regardless of which app triggers them. The entire setup is done in Intune.
Does this work only with anny or with other apps too?
Does this work only with anny or with other apps too?
The SSO plug-in provides single sign-on across all apps that authenticate against Microsoft Entra ID: Microsoft 365 apps, anny, and any other app whose login flow goes through Entra ID.
What happens on unmanaged devices?
What happens on unmanaged devices?
The SSO plug-in requires MDM enrollment. On unmanaged devices, anny uses the standard OAuth login via the system browser. Make sure your Conditional Access policy allows this fallback if employees also work on personal devices.
Do I need an additional license?
Do I need an additional license?
No. The Enterprise SSO plug-in is part of Microsoft Intune and Entra ID. No separate license or approval from Microsoft is needed.
What is the difference from brokered auth via MSAL?
What is the difference from brokered auth via MSAL?
Brokered auth requires the app to have the MSAL SDK built in. The SSO plug-in works at the operating system level and works with any app, regardless of the SDK used. For anny, the SSO plug-in is the right approach.
Troubleshooting
Login fails despite SSO plug-in
Login fails despite SSO plug-in
Check the following:
- Has the Conditional Access policy been adjusted? An Edge-only policy will still block login.
- Is the Authenticator app installed on the device?
- Does the device have a device identity certificate? Check under Settings > General > VPN & Device Management > MDM Profile > More Details.
- Are the URLs
login.microsoftonline.comandlogin.microsoft.comreachable through your proxy or firewall?
Employees are still prompted for credentials
Employees are still prompted for credentials
The first login after setup always requires credentials, as this is when the Primary Refresh Token (PRT) is created. After that, SSO should take over. Tip: Have your employees sign into Microsoft Teams first. This bootstraps the SSO token most reliably.
SSO works in anny but not in other apps
SSO works in anny but not in other apps
For apps not from Apple or Microsoft, the app’s bundle ID must be added under App bundle ID in the SSO profile. You can find bundle IDs using debug mode: Temporarily set
admin_debug_mode_enabled = 1 in the Additional Configuration, sign into the app, and check the Authenticator logs under Help > Send Logs > View Logs.