← All Guides

Simplified Setup

The Apple Platform

Simplified Setup is an Apple workflow, introduced in macOS 26, that registers Platform SSO (PSSO) directly inside Setup Assistant during Automated Device Enrollment. Instead of registering PSSO after a user reaches the desktop, the Mac pauses early in setup, the user authenticates with their identity provider (IdP) credentials, and that identity becomes the first local account created on the device.

What to Know

Before Simplified Setup, PSSO registration happened after enrollment — either through a pop-up prompt on the desktop or a manually triggered agent — which left a gap where a device could be in use without being fully bound to the IdP identity. Simplified Setup closes that gap by folding registration into the enrollment flow itself: the Mac won’t exit Setup Assistant until the specified PSSO app and its configuration profile finish installing and the user successfully authenticates.

Because the authenticating user’s IdP credentials are used to create the first local account, the device is tied to that identity from the moment the desktop appears, and the user can immediately use single sign-on with supported native and web apps. This works best for single-user Macs, since the account created during setup belongs to whichever person authenticates.

Simplified Setup requires macOS 26 or later, a device management service that supports triggering PSSO registration during Setup Assistant, and an IdP whose PSSO app explicitly supports the Simplified Setup flow. Not every IdP’s PSSO app supports it yet, so admins should confirm support with their identity provider before relying on it.

Common Scenarios

Enterprise IT: Security and compliance teams use Simplified Setup to guarantee that every Mac is bound to a verified IdP identity before it’s ever used, closing the window where an unregistered device could sit unmanaged after enrollment.

MSP: Managed Service Providers deploying Macs for multiple clients rely on Simplified Setup to standardize identity binding at first boot, reducing the manual follow-up needed to confirm PSSO registered correctly on each device after a technician hands it off.

Education: Schools issuing shared or lab Macs use Simplified Setup carefully, since it’s designed around single-user devices — a shared Mac’s first local account still gets tied to whichever student or staff member authenticates during setup.

In Addigy

Addigy supports Platform SSO through Extensible SSO configuration profiles for identity providers including Microsoft Entra ID and Okta, deployed via policy. Addigy’s Enrollment SSO for Automated Device Enrollment already authenticates the enrolling user against Okta, Google Workspace, or Microsoft Entra ID during Setup Assistant — but on its own, Enrollment SSO doesn’t create a local account from that identity.

Simplified Setup is what completes that flow natively on macOS 26: once a Mac is running macOS 26 or later and the IdP’s PSSO app supports Simplified Setup, admins configure the Extensible SSO profile in Addigy so registration happens during enrollment instead of after. For fleets on older macOS versions, or IdPs without Simplified Setup support yet, Addigy Identity remains the recommended path for just-in-time local account creation tied to IdP credentials.

Also Known As

  • Platform SSO Simplified Setup
  • PSSO Simplified Setup
  • Simplified Enrollment SSO