Mac login with Primo is in private beta. If the control shows This control is in private beta. Contact Primo to enable it., contact support@getprimo.com to turn it on for your company.
Platform compatibility
Mac login with Primo requires macOS 27 or later.
How to set it up
1
Pick the login methods
Under Login methods, select how employees sign in on the Primo sign-in page. Select at least one:
- Password — the employee’s work email, then their Primo password or a code sent by email, then their two-factor authentication if they set one up. Selected by default.
- Google — the Google account of the employee’s work email.
- Microsoft — the Microsoft account of the employee’s work email.
2
Set the sign-in frequency and the offline grace period
- Full sign-in frequency (days) — how often macOS asks for a full Primo sign-in instead of a silent token refresh. From 1 to 30 days, 7 by default.
- Offline grace period (days) — how long after the last successful Primo sign-in the local password still unlocks the Mac without a network connection. From 1 to 30 days, 7 by default.
3
Select targeting
Choose which devices to apply the control to: all macOS devices, specific device groups, or a custom target. The control only reaches Macs on macOS 27 or later.
A company runs one enabled Mac login with Primo control at a time. To create another one, disable the first one.
Modify or remove the control
Disable the control from the profile settings. Disabling stops enforcement but does not remove existing configurations from devices. Each Save pushes an updated profile to the targeted Macs.How it works
The control deploys Primo Desktop and a configuration profile to the targeted Macs. The profile turns on the web-based Platform SSO that Apple introduced in macOS 27, with Primo as the identity provider.Registration
Once the profile is installed, macOS shows the employee a Registration required notification. The employee clicks it and signs in with their Primo account in a macOS sign-in window. The Mac login with Primo guide & FAQ walks employees through it.Everyday sign-in
- At the lock screen, Sign in with Primo opens the Primo sign-in page. The local password and Touch ID keep working next to it.
- macOS refreshes the Primo session in the background every 4 hours, and asks for a full sign-in once the Full sign-in frequency has passed.
- Without a network connection, the local password unlocks the Mac for the Offline grace period after the last successful Primo sign-in.
- The sign-in window keeps no cookies from one sign-in to the next. Employees who use Google or Microsoft sign in to that provider, two-factor authentication included, every time. This is how macOS presents the window, and no setting changes it.
Mac password
When an employee signs in with their Primo password, macOS makes it their Mac password as well. Signing in with Google or Microsoft does not change the Mac password. macOS refuses a password that breaks the Mac’s password rules, and the sign-in fails. To prevent that, while the control is enabled, the company’s macOS Password and screenlock controls follow the Primo password rules (at least 8 characters, upper and lower case, a number and a special character):
These settings are locked, and Screenlock stays editable. Disabling or deleting the Mac login with Primo control unlocks them; they keep their values until you change them.
A password rule pushed by another profile, such as a Custom file, is not aligned. Remove it from these Macs, or make it no stricter than the Primo password rules.
Troubleshooting
The sign-in window shows “Sign-in site not allowed”- Open the control and click Save to push the current profile. Once the Mac has it, ask the employee to sign in again.
- If the message persists, see Resolve Mac login with Primo issues.
- Look for a password rule on the Mac that is stricter than the Primo password rules, for example in a Custom file.
- Check that the provider is selected under Login methods, then click Save.