In environments integrating Mac device management platforms (e.g., JAMF Connect or Kandji) with OIDC authentication, password synchronization or login attempts may fail silently.
Administrators may observe:
The issue typically appears during local password sync or device-level authentication workflows rather than browser-based login.
The issue is caused by incompatibility between:
ROPG-based authentication does not support interactive MFA challenges. When MFA is required:
For device management platforms:
As a result, any MFA requirement enforced at the policy level blocks these flows.
To resolve the issue, implement a configuration that separates MFA requirements between authentication flows using App Security Policies.
Create a secondary OIDC application connector:
Apply an App Security Policy to this secondary app:
Configure JAMF to use:
This approach ensures:
Configure two separate OIDC applications:
Apply an App Security Policy to the local/device app:
Confirm feature requirement:
Ensure:
This prevents:
© 2026 One Identity LLC. ALL RIGHTS RESERVED. Terms of Use Privacy Cookie Preference Center