Fix Platform SSO (PSSO) Sign-In Loop with Entra ID on macOS
Question details
Users experience a continuous authentication loop when enabling the Platform SSO extension on managed macOS devices.
- Product
- macOS, Microsoft Intune, Entra ID
- Device & OS
- macOS (macOS 15 and later)
- Scenario
- Enabling the Platform SSO extension for macOS devices enrolled via Apple Business Manager and Microsoft Intune.
- Observed behavior
- The system repeatedly requests authentication and displays a password policy error, even after password compliance policies have been removed.
Verify your exact macOS version and ensure you have administrative access to your Microsoft Intune dashboard before beginning the troubleshooting process.
Report Concurrency Issue and Gather Device Logs
Since this is a known bug in macOS 15 and later, gathering logs and reporting to support is the current recommended action while Apple investigates.
This issue is caused by a concurrency bug affecting macOS 15 and later. The system daemons AppSSOAgent and AppSSODaemon may attempt to update the PSSO device configuration simultaneously. This corrupts the configuration, resulting in a continuous sign-in loop and false password policy errors.
Click the Apple menu in the top-left corner of your screen, then select 'About This Mac' to confirm if the device is running macOS 15 or later.
Take note of the specific password policy error message and record the exact sequence of the authentication loop.
Provide your macOS version, specific device hardware details, and Intune enrollment logs to Apple Support or Microsoft Support to assist their ongoing investigation.
Experience a Hassle-Free Office Suite on macOS
While waiting for OS-level SSO and Intune issues to be resolved by Apple, you can still maintain peak productivity. WPS Office offers a lightweight, highly compatible alternative to Microsoft Office that works seamlessly on your Mac without complex enterprise sign-in dependencies.
- 1. Download the Installer: Visit the official WPS Office website and download the installation package designed for macOS.
- 2. Install the Application: Open the downloaded .dmg file and drag the WPS Office icon into your Applications folder.
- 3. Start Creating: Launch WPS Office from Launchpad to immediately open, edit, and save your Microsoft Office formatted documents.

Frequently Asked Questions
Why does the password policy error persist after removing compliance policies?
This occurs due to a configuration corruption on macOS 15 and later. The system daemons (AppSSOAgent and AppSSODaemon) simultaneously update the PSSO device configuration, causing the system to incorrectly flag a policy violation even when none exists.
Which versions of macOS are affected by this Platform SSO sign-in loop?
The concurrency issue leading to the sign-in loop is currently known to affect macOS 15 and later versions.
Can I bypass the PSSO sign-in loop by reinstalling the Microsoft Intune profile?
Reinstalling the profile typically does not permanently resolve the issue, as the underlying bug is tied to the macOS SSO agents corrupting the configuration. You will need to wait for an official system patch from Apple.
What information should I provide when reporting this PSSO issue to support?
When escalating the issue to Apple or Microsoft, be sure to provide your exact macOS version, device hardware details, and any enrollment logs generated from Apple Business Manager and Microsoft Intune.




