Skip to content

Consider making broker | web the default auth mode on macOS #455

@dggsax

Description

@dggsax

Summary

Once macOS brokered auth has been validated in production, consider changing the default auth mode on macOS from Web to Broker | Web — matching the Windows default behavior.

Context

Raised by @kyle-rader-msft in PR #453 review:

Depending on how this rollout goes, we might want to include broker | web as the default for Mac in the future.

Current state

Broker is opt-in on macOS via --mode broker because apps with broker-required Conditional Access policies (e.g., token protection, error 530084) will hang indefinitely if web auth is attempted as fallback — the browser shows an error page but never redirects back to localhost.

When to revisit

This should be reconsidered once:

  • Broker has been validated across a wider set of macOS deployments
  • The web-auth-hang issue for broker-required CA policies is better understood or mitigated
  • There's confidence that Company Portal adoption is widespread enough that broker-first is a safe default

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions