Skip to main content
Mac login with Primo is in private beta. If the control shows This control is in private beta. Contact Primo to enable it., contact support@getprimo.com to turn it on for your company.

Platform compatibility

Mac login with Primo requires macOS 27 or later.

How to set it up

1

Pick the login methods

Under Login methods, select how employees sign in on the Primo sign-in page. Select at least one:
  • Password — the employee’s work email, then their Primo password or a code sent by email, then their two-factor authentication if they set one up. Selected by default.
  • Google — the Google account of the employee’s work email.
  • Microsoft — the Microsoft account of the employee’s work email.
When you select a single provider without Password, the sign-in page opens that provider directly.
2

Set the sign-in frequency and the offline grace period

  • Full sign-in frequency (days) — how often macOS asks for a full Primo sign-in instead of a silent token refresh. From 1 to 30 days, 7 by default.
  • Offline grace period (days) — how long after the last successful Primo sign-in the local password still unlocks the Mac without a network connection. From 1 to 30 days, 7 by default.
3

Select targeting

Choose which devices to apply the control to: all macOS devices, specific device groups, or a custom target. The control only reaches Macs on macOS 27 or later.
A company runs one enabled Mac login with Primo control at a time. To create another one, disable the first one.
Keep a local administrator account on every Mac this control covers, for example with Admin management. That account does not sign in through Primo, so it still opens the Mac when a Primo sign-in fails.

Modify or remove the control

Disable the control from the profile settings. Disabling stops enforcement but does not remove existing configurations from devices. Each Save pushes an updated profile to the targeted Macs.

How it works

The control deploys Primo Desktop and a configuration profile to the targeted Macs. The profile turns on the web-based Platform SSO that Apple introduced in macOS 27, with Primo as the identity provider.

Registration

Once the profile is installed, macOS shows the employee a Registration required notification. The employee clicks it and signs in with their Primo account in a macOS sign-in window. The Mac login with Primo guide & FAQ walks employees through it.

Everyday sign-in

  • At the lock screen, Sign in with Primo opens the Primo sign-in page. The local password and Touch ID keep working next to it.
  • macOS refreshes the Primo session in the background every 4 hours, and asks for a full sign-in once the Full sign-in frequency has passed.
  • Without a network connection, the local password unlocks the Mac for the Offline grace period after the last successful Primo sign-in.
  • The sign-in window keeps no cookies from one sign-in to the next. Employees who use Google or Microsoft sign in to that provider, two-factor authentication included, every time. This is how macOS presents the window, and no setting changes it.

Mac password

When an employee signs in with their Primo password, macOS makes it their Mac password as well. Signing in with Google or Microsoft does not change the Mac password. macOS refuses a password that breaks the Mac’s password rules, and the sign-in fails. To prevent that, while the control is enabled, the company’s macOS Password and screenlock controls follow the Primo password rules (at least 8 characters, upper and lower case, a number and a special character): These settings are locked, and Screenlock stays editable. Disabling or deleting the Mac login with Primo control unlocks them; they keep their values until you change them. A password rule pushed by another profile, such as a Custom file, is not aligned. Remove it from these Macs, or make it no stricter than the Primo password rules.

Troubleshooting

The sign-in window shows “Sign-in site not allowed”
  • Open the control and click Save to push the current profile. Once the Mac has it, ask the employee to sign in again.
  • If the message persists, see Resolve Mac login with Primo issues.
The sign-in fails right after the employee enters their Primo password
  • Look for a password rule on the Mac that is stricter than the Primo password rules, for example in a Custom file.
Google or Microsoft is missing from the sign-in page
  • Check that the provider is selected under Login methods, then click Save.