Skip to content

Commit d6707ec

Browse files
committed
added macOS support
1 parent 65fe523 commit d6707ec

File tree

2 files changed

+41
-24
lines changed

2 files changed

+41
-24
lines changed

articles/active-directory/authentication/TOC.yml

Lines changed: 13 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -120,18 +120,6 @@
120120
href: how-to-mfa-microsoft-managed.md
121121
- name: Windows Hello for Business
122122
href: /windows/security/identity-protection/hello-for-business/hello-identity-verification
123-
- name: Use a Temporary Access Pass
124-
href: howto-authentication-temporary-access-pass.md
125-
- name: Use SMS-based authentication
126-
items:
127-
- name: Manage
128-
href: howto-authentication-sms-signin.md
129-
- name: Supported apps for SMS-based authentication
130-
href: how-to-authentication-sms-supported-apps.md
131-
- name: Two-way SMS unsupported
132-
href: how-to-authentication-two-way-sms-unsupported.md
133-
- name: Use email address sign-in
134-
href: howto-authentication-use-email-signin.md
135123
- name: Certificate-based authentication
136124
items:
137125
- name: Azure AD CBA
@@ -144,7 +132,7 @@
144132
href: how-to-certificate-based-authentication.md
145133
- name: Windows smart card logon
146134
href: concept-certificate-based-authentication-smartcard.md
147-
- name: iOS devices
135+
- name: Apple devices
148136
href: concept-certificate-based-authentication-mobile-ios.md
149137
- name: Android devices
150138
href: concept-certificate-based-authentication-mobile-android.md
@@ -162,6 +150,18 @@
162150
href: active-directory-certificate-based-authentication-android.md
163151
- name: Use on iOS Devices
164152
href: active-directory-certificate-based-authentication-ios.md
153+
- name: Use a Temporary Access Pass
154+
href: howto-authentication-temporary-access-pass.md
155+
- name: Use SMS-based authentication
156+
items:
157+
- name: Manage
158+
href: howto-authentication-sms-signin.md
159+
- name: Supported apps for SMS-based authentication
160+
href: how-to-authentication-sms-supported-apps.md
161+
- name: Two-way SMS unsupported
162+
href: how-to-authentication-two-way-sms-unsupported.md
163+
- name: Use email address sign-in
164+
href: howto-authentication-use-email-signin.md
165165
- name: Self-service password reset
166166
items:
167167
- name: Deployment guide

articles/active-directory/authentication/concept-certificate-based-authentication-mobile-ios.md

Lines changed: 28 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -1,40 +1,57 @@
11
---
2-
title: Azure Active Directory certificate-based authentication on iOS devices - Azure Active Directory
3-
description: Learn about Azure Active Directory certificate-based authentication on iOS devices
2+
title: Azure Active Directory certificate-based authentication on Apple devices - Azure Active Directory
3+
description: Learn about Azure Active Directory certificate-based authentication on Apple devices that run macOS or iOS
44

55
services: active-directory
66
ms.service: active-directory
77
ms.subservice: authentication
88
ms.topic: how-to
9-
ms.date: 01/29/2023
9+
ms.date: 02/09/2023
1010

1111
ms.author: justinha
1212
author: justinha
13-
manager: daveba
13+
manager: amycolannino
1414
ms.reviewer: vimrang
1515

1616
ms.collection: M365-identity-device-management
1717
ms.custom: has-adal-ref
1818
---
19-
# Azure Active Directory certificate-based authentication on iOS
19+
# Azure Active Directory certificate-based authentication on Apple devices
2020

21+
This topic covers Azure Active Directory (Azure AD) certificate-based authentication (CBA) support for macOS and iOS devices.
22+
23+
## Azure Active Directory certificate-based authentication on macOS devices
24+
25+
Devices that run macOS can use CBA to authenticate against Azure AD by using their X.509 client certificate. Azure AD CBA is supported with certificates on-device and external hardware protected security keys. On macOS, Azure AD CBA is supported on all browsers and on Microsoft first-party applications.
26+
27+
**Browsers supported on macOS**
28+
29+
|Edge | Chrome | Safari | Firefox |
30+
|--------|---------|------|-------|
31+
|✅ |✅ | ✅ |✅ |
32+
33+
**macOS device sign in with Azure AD CBA**
34+
35+
Azure AD CBA today is not supported for device based sign into macOS machines. While the certificate used to sign-into the device may be the same certificate used to subsequently authenticate to Azure AD from a browser/desktop application, the device sign-in itself is not supported against Azure AD yet. 
36+
37+
## Azure Active Directory certificate-based authentication on iOS devices
2138
Devices that run iOS can use certificate-based authentication (CBA) to authenticate to Azure Active Directory (Azure AD) using a client certificate on their device when connecting to:
2239

2340
- Office mobile applications such as Microsoft Outlook and Microsoft Word
2441
- Exchange ActiveSync (EAS) clients
2542

2643
Azure AD CBA is supported for certificates on-device on native browsers and on Microsoft first-party applications on iOS devices.
2744

28-
## Prerequisites
45+
### Prerequisites
2946

3047
- iOS version must be iOS 9 or later.
3148
- Microsoft Authenticator is required for Office applications and Outlook on iOS.
3249

33-
## Support for on-device certificates and external storage
50+
### Support for on-device certificates and external storage
3451

3552
On-device certificates are provisioned on the device. Customers can use Mobile Device Management (MDM) to provision the certificates on the device. Since iOS doesn't support hardware protected keys out of the box, customers can use external storage devices for certificates.
3653

37-
## Supported platforms
54+
### Supported platforms
3855

3956
- Only native browsers are supported
4057
- Applications using latest MSAL libraries or Microsoft Authenticator can do CBA
@@ -47,7 +64,7 @@ On-device certificates are provisioned on the device. Customers can use Mobile D
4764
|--------|---------|------|-------|
4865
|❌ | ❌ | ✅ |❌ |
4966

50-
## Microsoft mobile applications support
67+
### Microsoft mobile applications support
5168

5269
| Applications | Support |
5370
|:---------|:------------:|
@@ -63,7 +80,7 @@ On-device certificates are provisioned on the device. Customers can use Mobile D
6380
|Word / Excel / PowerPoint | ✅ |
6481
|Yammer | ✅ |
6582

66-
## Support for Exchange ActiveSync clients
83+
### Support for Exchange ActiveSync clients
6784

6885
On iOS 9 or later, the native iOS mail client is supported.
6986

@@ -74,7 +91,7 @@ To determine if your email application supports Azure AD CBA, contact your appli
7491
Certificates can be provisioned in external devices like hardware security keys along with a PIN to protect private key access.
7592
Microsoft's mobile certificate-based solution coupled with the hardware security keys is a simple, convenient, FIPS (Federal Information Processing Standards) certified phishing-resistant MFA method.
7693

77-
As for iOS 16/iPadOS 16.1, Apple devices provide native driver support for USB-C or Lightning connected CCID-compliant smart cards. This means Apple devices on iOS 16/iPadOS 16.1 will see a USB-C or Lightning connected CCID-compliant device as a smart card without the use of additional drivers or 3rd party apps. Azure AD CBA will work on these USB-A or USB-C, or Lightning connected CCID-compliant smart cards.
94+
As for iOS 16/iPadOS 16.1, Apple devices provide native driver support for USB-C or Lightning connected CCID-compliant smart cards. This means Apple devices on iOS 16/iPadOS 16.1 will see a USB-C or Lightning connected CCID-compliant device as a smart card without the use of additional drivers or third-party apps. Azure AD CBA will work on these USB-A or USB-C, or Lightning connected CCID-compliant smart cards.
7895

7996

8097
### Advantages of certificates on hardware security key

0 commit comments

Comments
 (0)