Enabling Single Sign-on (SSO)
Table of Contents:
This SSO feature will allow you to sign-in to your Mac using your UW Account credentials. Once signed in to your device, you will also be automatically signed into Microsoft apps and UW websites without having to re-enter your password each time. Limiting the total number of passwords you need to remember and the number of times you need to authenticate.
Password Registration Instructions
When the policy is applied, click on the notification to start the process.
Click Continue to confirm the settings being applied.
Type in your current macOS password. This is a general macOS admin prompt.
Sign in with your UW/WatIAM account and validate any 2fa as needed.
Type in your UW password.
Process is now complete. Your UW password has been linked to the local Mac account.
When viewing the account, we can see the local account is now linked to the UW account.
Clicking on Edit under Network account server, again showcases that this account is set up using Platform SSO.
This is also visible in the settings of the Company Portal app.
After a bit of time, it is a good idea to restart your Mac to ensure the password is stored properly and can unlock FileVault.
Tools that currently leverage Platform SSO
Safari
Most Microsoft Apps
Edge – when signed into the browser with a profile
Firefox – with a SSO config profile
Chrome – with MS SSO extension
Password Resets
If your UW/WatIAM password is changed, you will need to navigate to System Settings > Users & Groups > Your User > Tokens > Authenticate.
You will be prompted to type in your new UW/WatIAM password. You should then see the that the password has been synchronized and the “SSO tokens present” is lit green.
You should close any open Microsoft Apps and relaunch them so they can authenticate with your updated password. You should also restart to ensure you can unlock FileVault properly. You may also need to re-authenticate to Eduroam with your new password.
Additional Feature – Sign-in with other UW Microsoft Accounts (macOS 14+)
Click on “Other…” and sign-in with a UW Microsoft Account using the full @uwaterloo.ca address.
If you don’t see “Other…” you may need to hit “esc” on the keyboard or press Command+Return(Enter), or if the device was just powered on, you will need to sign-in to unlock FileVault then sign-out.
Viewing this account provides the same Platform SSO information
These accounts are by default available to unlock the FileVault and are accessible at the login screen after reboot.
Related articles
Finding files and restoring deleted files or folders in OneDrive
Adding and using the Zoom widget on LEARN to simplify classroom management
Moving files from a OneDrive account to another OneDrive account
Need help?
Contact the IST Service Desk online or 519-888-4567 ext. 44357.
Article feedback
If you’d like to share any feedback about this article, please let us know.