Skip to main content
On iOS, all apps use Apple’s system browser (Safari engine) for OAuth login under the hood. If your organization has a Conditional Access policy that only allows Microsoft Edge, the anny login may be blocked. The solution is the Microsoft Enterprise SSO plug-in. It intercepts authentication requests to Microsoft Entra ID at the operating system level and provides tokens automatically, without opening a browser. Safari does not need to be enabled for this. With the Enterprise SSO plug-in you can:
  • Sign your employees into anny seamlessly without enabling Safari as a browser
  • Use single sign-on across all apps (anny, Microsoft 365, custom apps)
  • Automatically pass device compliance and device state to Conditional Access
This setup is done entirely on the IT admin side in Microsoft Intune. No changes to the anny app are required.

Prerequisites

Before setting up the SSO plug-in, make sure the following requirements are met:
  • iOS 13.0 or later on the devices
  • Devices are enrolled in Microsoft Intune MDM
  • Microsoft Entra ID (formerly Azure AD) is used as the identity provider
  • The anny login goes through SAML/OIDC federation with Entra ID (the auth flow redirects to login.microsoftonline.com)
If the anny login does not go through Entra ID, the SSO plug-in will not apply. In that case, anny must be registered as an app in Entra ID and SSO configured via SAML/OIDC federation.

Set Up the SSO Plug-in

1

Create SSO App Extension Profile

Open the Microsoft Intune Admin Center (intune.microsoft.com) and navigate to Devices > Manage devices > Configuration > Create > New Policy.Select the following settings:
  • Platform: iOS/iPadOS
  • Profile type: Templates > Device features
  • Name: e.g. iOS: SSO App Extension
Under Configuration settings > Single sign-on app extension:
  • SSO app extension type: Microsoft Entra ID
  • Enable shared device mode: Not configured
2

Set Recommended Configuration

Add the following key-value pairs under Additional configuration:
Make sure there are no trailing spaces before or after keys and values. Otherwise, registration will fail.
3

Assign the Profile

Assign the profile to a device or user group that contains your iOS devices. The settings are applied automatically at the next device check-in.
4

Deploy Microsoft Authenticator

Navigate to Apps > All Apps and make sure Microsoft Authenticator is assigned as a required app to the same device group.
The Authenticator app only needs to be installed. Your employees do not need to actively set it up or use it. The app must be obtained through an Apple Volume Purchase Program (VPP).
5

Adjust Conditional Access Policy

This is the most important step. Instead of a policy that only allows Edge as a browser, the policy should be changed to one of the following conditions:
  • Require compliant device (recommended): Checks whether the device is Intune-compliant
  • Require approved client app: Allows authentication via the Authenticator app
The SSO plug-in automatically provides device identity and compliance status with every auth request. This offers better protection than a browser-only restriction, because it checks the entire device state, not just the browser.
Without this adjustment, the existing Edge-only policy will continue to block login even if the SSO plug-in is set up correctly.
6

Test

Open the anny app on an enrolled iOS device and start the login:
  • First login after setup: A short auth dialog where Entra ID credentials are entered.
  • All subsequent logins: SSO kicks in automatically, no re-login needed.
Check in the Intune Admin Center under Devices > Device > Device configuration that the SSO profile shows as Succeeded.

Background: Why Not Just Use Edge as an In-App Browser?

iOS does not allow apps to use any browser other than Apple’s system browser (ASWebAuthenticationSession) for OAuth logins. Even if Edge is set as the default browser, iOS always uses the Safari engine internally for authentication flows. The Enterprise SSO plug-in solves this at a deeper level: it works at the operating system level and intercepts authentication requests before a browser is opened. This means Conditional Access policies are correctly satisfied without needing to enable Safari as a browser.

FAQ

No. Safari can remain blocked via Intune. The SSO plug-in does not use Safari as a browser. It works at the operating system level. The auth dialog is a sandboxed system dialog, not an open browser.
No. The SSO plug-in intercepts auth requests to Entra ID automatically, regardless of which app triggers them. The entire setup is done in Intune.
The SSO plug-in provides single sign-on across all apps that authenticate against Microsoft Entra ID: Microsoft 365 apps, anny, and any other app whose login flow goes through Entra ID.
The SSO plug-in requires MDM enrollment. On unmanaged devices, anny uses the standard OAuth login via the system browser. Make sure your Conditional Access policy allows this fallback if employees also work on personal devices.
No. The Enterprise SSO plug-in is part of Microsoft Intune and Entra ID. No separate license or approval from Microsoft is needed.
Brokered auth requires the app to have the MSAL SDK built in. The SSO plug-in works at the operating system level and works with any app, regardless of the SDK used. For anny, the SSO plug-in is the right approach.

Troubleshooting

Check the following:
  1. Has the Conditional Access policy been adjusted? An Edge-only policy will still block login.
  2. Is the Authenticator app installed on the device?
  3. Does the device have a device identity certificate? Check under Settings > General > VPN & Device Management > MDM Profile > More Details.
  4. Are the URLs login.microsoftonline.com and login.microsoft.com reachable through your proxy or firewall?
The first login after setup always requires credentials, as this is when the Primary Refresh Token (PRT) is created. After that, SSO should take over. Tip: Have your employees sign into Microsoft Teams first. This bootstraps the SSO token most reliably.
For apps not from Apple or Microsoft, the app’s bundle ID must be added under App bundle ID in the SSO profile. You can find bundle IDs using debug mode: Temporarily set admin_debug_mode_enabled = 1 in the Additional Configuration, sign into the app, and check the Authenticator logs under Help > Send Logs > View Logs.