> ## Documentation Index
> Fetch the complete documentation index at: https://docs.anny.co/llms.txt
> Use this file to discover all available pages before exploring further.

# Set Up Microsoft Enterprise SSO on iOS

> How to configure the Microsoft Enterprise SSO plug-in for anny on Intune-managed iOS devices.

On iOS, all apps use Apple's system browser (Safari engine) for OAuth login under the hood. If your organization has a Conditional Access policy that only allows Microsoft Edge, the anny login may be blocked.

The solution is the **Microsoft Enterprise SSO plug-in**. It intercepts authentication requests to Microsoft Entra ID at the operating system level and provides tokens automatically, without opening a browser. Safari does **not** need to be enabled for this.

With the Enterprise SSO plug-in you can:

* Sign your employees into anny seamlessly without enabling Safari as a browser
* Use single sign-on across all apps (anny, Microsoft 365, custom apps)
* Automatically pass device compliance and device state to Conditional Access

<Info>
  This setup is done entirely on the IT admin side in Microsoft Intune. No changes to the anny app are required.
</Info>

## Prerequisites

Before setting up the SSO plug-in, make sure the following requirements are met:

* iOS 13.0 or later on the devices
* Devices are enrolled in **Microsoft Intune MDM**
* **Microsoft Entra ID** (formerly Azure AD) is used as the identity provider
* The anny login goes through SAML/OIDC federation with Entra ID (the auth flow redirects to `login.microsoftonline.com`)

<Tip>
  If the anny login does not go through Entra ID, the SSO plug-in will not apply. In that case, anny must be registered as an app in Entra ID and SSO configured via SAML/OIDC federation.
</Tip>

## Set Up the SSO Plug-in

<Steps>
  <Step title="Create SSO App Extension Profile">
    Open the **Microsoft Intune Admin Center** (intune.microsoft.com) and navigate to **Devices > Manage devices > Configuration > Create > New Policy**.

    Select the following settings:

    * **Platform:** iOS/iPadOS
    * **Profile type:** Templates > Device features
    * **Name:** e.g. `iOS: SSO App Extension`

    Under **Configuration settings** > **Single sign-on app extension**:

    * **SSO app extension type:** Microsoft Entra ID
    * **Enable shared device mode:** Not configured
  </Step>

  <Step title="Set Recommended Configuration">
    Add the following key-value pairs under **Additional configuration**:

    | Key                               | Type    | Value                                | Purpose                                           |
    | :-------------------------------- | :------ | :----------------------------------- | :------------------------------------------------ |
    | `AppPrefixAllowList`              | String  | `com.apple.,com.microsoft.,co.anny.` | Allows Apple, Microsoft, and anny apps to use SSO |
    | `browser_sso_interaction_enabled` | Integer | `1`                                  | Enables SSO in Safari and WebView-based apps      |
    | `disable_explicit_app_prompt`     | Integer | `1`                                  | Suppresses unnecessary consent popups per app     |
    | `device_registration`             | String  | `{{DEVICEREGISTRATION}}`             | Enables just-in-time device registration          |

    <Warning>
      Make sure there are no trailing spaces before or after keys and values. Otherwise, registration will fail.
    </Warning>
  </Step>

  <Step title="Assign the Profile">
    Assign the profile to a **device or user group** that contains your iOS devices. The settings are applied automatically at the next device check-in.
  </Step>

  <Step title="Deploy Microsoft Authenticator">
    Navigate to **Apps > All Apps** and make sure **Microsoft Authenticator** is assigned as a **required app** to the same device group.

    <Info>
      The Authenticator app only needs to be installed. Your employees do not need to actively set it up or use it. The app must be obtained through an Apple Volume Purchase Program (VPP).
    </Info>
  </Step>

  <Step title="Adjust Conditional Access Policy">
    This is the most important step. Instead of a policy that only allows Edge as a browser, the policy should be changed to one of the following conditions:

    * **Require compliant device** (recommended): Checks whether the device is Intune-compliant
    * **Require approved client app**: Allows authentication via the Authenticator app

    The SSO plug-in automatically provides device identity and compliance status with every auth request. This offers better protection than a browser-only restriction, because it checks the entire device state, not just the browser.

    <Warning>
      Without this adjustment, the existing Edge-only policy will continue to block login even if the SSO plug-in is set up correctly.
    </Warning>
  </Step>

  <Step title="Test">
    Open the **anny app** on an enrolled iOS device and start the login:

    * **First login after setup:** A short auth dialog where Entra ID credentials are entered.
    * **All subsequent logins:** SSO kicks in automatically, no re-login needed.

    Check in the Intune Admin Center under **Devices > Device > Device configuration** that the SSO profile shows as Succeeded.
  </Step>
</Steps>

## Background: Why Not Just Use Edge as an In-App Browser?

iOS does not allow apps to use any browser other than Apple's system browser (`ASWebAuthenticationSession`) for OAuth logins. Even if Edge is set as the default browser, iOS always uses the Safari engine internally for authentication flows.

The Enterprise SSO plug-in solves this at a deeper level: it works at the operating system level and intercepts authentication requests before a browser is opened. This means Conditional Access policies are correctly satisfied without needing to enable Safari as a browser.

## FAQ

<AccordionGroup>
  <Accordion title="Does Safari need to be enabled on the devices?">
    No. Safari can remain blocked via Intune. The SSO plug-in does not use Safari as a browser. It works at the operating system level. The auth dialog is a sandboxed system dialog, not an open browser.
  </Accordion>

  <Accordion title="Does anything need to change in the anny app?">
    No. The SSO plug-in intercepts auth requests to Entra ID automatically, regardless of which app triggers them. The entire setup is done in Intune.
  </Accordion>

  <Accordion title="Does this work only with anny or with other apps too?">
    The SSO plug-in provides single sign-on across all apps that authenticate against Microsoft Entra ID: Microsoft 365 apps, anny, and any other app whose login flow goes through Entra ID.
  </Accordion>

  <Accordion title="What happens on unmanaged devices?">
    The SSO plug-in requires MDM enrollment. On unmanaged devices, anny uses the standard OAuth login via the system browser. Make sure your Conditional Access policy allows this fallback if employees also work on personal devices.
  </Accordion>

  <Accordion title="Do I need an additional license?">
    No. The Enterprise SSO plug-in is part of Microsoft Intune and Entra ID. No separate license or approval from Microsoft is needed.
  </Accordion>

  <Accordion title="What is the difference from brokered auth via MSAL?">
    Brokered auth requires the app to have the MSAL SDK built in. The SSO plug-in works at the operating system level and works with any app, regardless of the SDK used. For anny, the SSO plug-in is the right approach.
  </Accordion>
</AccordionGroup>

## Troubleshooting

<AccordionGroup>
  <Accordion title="Login fails despite SSO plug-in">
    Check the following:

    1. Has the **Conditional Access policy** been adjusted? An Edge-only policy will still block login.
    2. Is the **Authenticator app** installed on the device?
    3. Does the device have a **device identity certificate**? Check under Settings > General > VPN & Device Management > MDM Profile > More Details.
    4. Are the URLs `login.microsoftonline.com` and `login.microsoft.com` reachable through your proxy or firewall?
  </Accordion>

  <Accordion title="Employees are still prompted for credentials">
    The first login after setup always requires credentials, as this is when the Primary Refresh Token (PRT) is created. After that, SSO should take over. Tip: Have your employees sign into **Microsoft Teams** first. This bootstraps the SSO token most reliably.
  </Accordion>

  <Accordion title="SSO works in anny but not in other apps">
    For apps not from Apple or Microsoft, the app's bundle ID must be added under **App bundle ID** in the SSO profile. You can find bundle IDs using debug mode: Temporarily set `admin_debug_mode_enabled = 1` in the Additional Configuration, sign into the app, and check the Authenticator logs under Help > Send Logs > View Logs.
  </Accordion>
</AccordionGroup>

> Important information for agents:
>
> **Context:** Enterprise customers with Intune-managed iOS devices often have Conditional Access policies that only allow Edge as a browser. Since iOS always uses the Safari engine internally for OAuth logins (ASWebAuthenticationSession), the anny login fails.
>
> **Solution:** The Microsoft Enterprise SSO plug-in intercepts auth requests at OS level. It requires no changes to anny. Setup is done entirely in the Microsoft Intune Admin Center on the customer's side.
>
> **Customer-side prerequisites:** iOS 13+, Intune MDM enrollment, Microsoft Authenticator app installed, Entra ID as IdP, SAML/OIDC federation with Entra ID for the anny login.
>
> **Most common mistake:** Conditional Access policy not adjusted. An Edge-only policy blocks login even with the SSO plug-in. Policy must be changed to Require compliant device or Require approved client app.
>
> **Safari does NOT need to be enabled.** This is the most common misconception among customers. The SSO plug-in operates below the browser at OS level.
>
> **No MSAL SDK required:** The plug-in works with standard OAuth/OIDC flows. anny does not need to integrate any Microsoft SDK.
>
> **No extra license:** Part of Intune + Entra ID.
