Workforce MFA · macOS Login MFA
Keycloak MFA at the Mac login window
Macs sign in to local accounts by default. We add a login-window agent that authenticates users against Keycloak with MFA, keeps the local password in step with Keycloak, and behaves predictably with FileVault and without a network.
- OIDC sign-in at the login window
- Local password kept in sync
- Deployed through your MDM
Standards & integrations
- OpenID Connect
- PKCE
- macOS login window
- MDM configuration profiles
- FileVault
Overview
How Mac sign-in and Keycloak meet
The macOS login window doesn't speak OpenID Connect by itself. A login-window agent — XCreds is one option built for standard OIDC providers — extends it, sends the user to Keycloak for sign-in and MFA, and updates the local account password when it changes. Apple's Platform SSO is another route, but it needs an SSO extension from the identity provider, which Keycloak doesn't ship. We pick the approach that fits your fleet and MDM.
What we deliver
- Mac sign-in design including FileVault and offline behaviour
- Keycloak OIDC client for the login-window agent
- Agent package and MDM configuration profile
- Password sync and recovery procedure
- Pilot results and fleet rollout plan
- Help-desk runbook for Mac sign-in issues
Capabilities
What macOS Login MFA covers
Configured, tested and documented on upstream Keycloak — then handed over or operated by us.
OIDC at the login window
Users sign in with their Keycloak identity at the Mac login window instead of a password that only lives on the device.
Local password sync
When the Keycloak password changes, the agent updates the local account and keychain password so the two never drift apart.
MFA from Keycloak
Keycloak's MFA policy applies at sign-in — OTP today, and other factors where the login window's web view supports them.
Deployed through MDM
The agent and its configuration profile are pushed through Jamf, Intune, Kandji or your MDM of choice, group by group.
FileVault-aware design
FileVault unlock happens before the network is up, so we design where MFA applies and keep the unlock password aligned with Keycloak.
Offline and recovery
Offline sign-in falls back to the synced local password, and recovery steps are documented for the help desk.
Compatibility
Mac sign-in scenarios
Where MFA applies on a Mac and which component handles it. Confirmed for your macOS versions in the pilot.
| Platform | Integration | Notes |
|---|---|---|
| macOS login window | OIDC login agent → Keycloak | Agent deployed and configured through MDM. |
| FileVault unlock at boot | Local password, kept in sync | Happens before network access; MFA applies at the login window. |
| Screen unlock | Local password or agent-dependent | Behaviour varies by agent and is set by policy. |
| Apple Platform SSO | Not used | Requires an IdP-specific SSO extension that Keycloak doesn't provide. |
| Offline sign-in | Local password | MFA resumes at the next online sign-in. |
How it works
From first call to production
Choose the agent and design
We review your macOS versions, MDM and FileVault setup, then choose and test a login-window agent against your Keycloak realm.
Pilot on a small group
The agent and profile go to a pilot group through MDM, and we tune password sync, offline behaviour and help-desk procedures.
Roll out across the fleet
Deployment expands by MDM group, with the ability to remove the agent from any group if problems appear.
Use cases
Where teams put it to work
Engineering and design fleets
Mac-heavy teams get the same identity and MFA at the login window as they use for every web app.
Mixed Windows and Mac estates
One MFA policy for both platforms, managed centrally in Keycloak.
Onboarding new hires
New Macs can set up the local account from the Keycloak identity at first sign-in, where the agent supports it.
FAQ
macOS Login MFA questions, answered
Does Keycloak support Apple Platform SSO?
Platform SSO needs an identity-provider-specific SSO extension installed on the Mac. Keycloak doesn't ship one, so we use a login-window agent that works with standard OIDC instead.
What happens when a Mac is offline?
The user signs in with the local password, which the agent keeps in step with Keycloak. MFA applies again the next time the Mac signs in online.
Which login agent do you use?
We start from options that support generic OIDC providers, such as XCreds, and confirm compatibility with your macOS versions and MDM during the pilot.
Ready to roll out macOS Login MFA?
Walk us through your requirements on a free strategy call. We'll come back with an architecture, a delivery plan and a fixed scope.