Identify common causes
- A page blocked by the Mac’s profile — the sign-in window shows Sign-in site not allowed. The Mac runs an older profile than the current sign-in page needs, usually until the control is saved again.
- A Mac password rule stricter than the Primo password — the sign-in fails right after the employee enters their Primo password, because macOS refuses to make it the Mac password.
- A registration that does not complete — the Mac shows Registration failed and will automatically retry and keeps asking the employee to register.
- A login method the control does not offer — the employee does not see Google or Microsoft on the sign-in page.
Verify the situation
- In the cockpit, open the Mac login with Primo control. Check its Login methods, and check that the Mac is in its targeting and runs macOS 27 or later.
-
On the Mac, open Terminal and run:
A registered account shows the state
POUserStateNormal.POUserStateNeedsRegistrationmeans the registration has not completed. -
For Sign-in site not allowed, list the pages the Mac blocked:
Each blocked page appears as
Navigation blocked: host=… url=…. -
For a failed sign-in, read the Mac’s sign-in log:
Password does not meet local policyconfirms a Mac password rule stricter than the Primo password.
Type
/usr/bin/log, not log: in the default macOS shell, log is a different, built-in command.Resolve the issue
Choose the option that matches the cause.Option 1 — Save the control again
For Sign-in site not allowed and for a missing login method. Requirements:- The Mac is online and enrolled.
- Open the Mac login with Primo control.
- Check the Login methods, then click Save. Each save pushes an updated profile to the targeted Macs.
- Once the Mac has the new profile, ask the employee to sign in again.
Navigation blocked line.
Option 2 — Align the Mac password rules
For a sign-in that fails withPassword does not meet local policy.
Requirements:
- You can edit the controls that target the Mac.
- Find the password rule that is stricter than the Primo password rules (at least 8 characters, upper and lower case, a number and a special character). The macOS Password and screenlock controls already follow these rules; look for a password policy in a Custom file or in another profile.
- Remove that rule from the Mac, or make it no stricter than the Primo password rules.
- Ask the employee to sign in again.
Option 3 — Reset the registration
For a registration that keeps failing. Requirements:- The Mac is online and enrolled.
- The employee can unlock the Mac with their Mac password.
- Remove the Mac from the control’s targeting, for example by taking it out of the targeted device group.
- Wait until the Mac has checked in and the profile is removed.
- Add the Mac back to the targeting. The Mac receives the profile again and asks the employee to register.
Do not rely on the Repair button in System Settings > Users & Groups: on macOS 27.0, it does not recover a registration once the Mac password has been synced.
Prevent future incidents
- Keep a local administrator account on every Mac the control covers, with Admin management. It still opens the Mac when a Primo sign-in fails.
- Do not push a password rule stricter than the Primo password rules to these Macs.
- Roll the control out to a device group first, then widen the targeting.
What if the Mac is offline?
The employee unlocks the Mac with their Mac password during the Offline grace period set on the control, counted from their last successful Primo sign-in. They sign in with Primo again once the Mac is back online.Summary
- Read the message the Mac shows, then check the registration with
app-sso platform -sand the Mac’s sign-in log. - Sign-in site not allowed or a missing login method: save the control again.
Password does not meet local policy: remove the stricter Mac password rule, or change the Primo password.- A registration that keeps failing: take the Mac out of the targeting, then add it back.
Contact
If none of the options above works, contact support@getprimo.com with:- The Mac’s serial number and macOS version
- The time of the failed registration or sign-in
- The output of
app-sso platform -s - The
Navigation blockedline, if the Mac shows Sign-in site not allowed