{"id":75139,"date":"2023-05-17T12:17:01","date_gmt":"2023-05-17T16:17:01","guid":{"rendered":"https:\/\/jumpcloud.com\/?post_type=support&p=75139"},"modified":"2024-05-14T09:07:20","modified_gmt":"2024-05-14T13:07:20","slug":"understand-mac-keychain-access","status":"publish","type":"support","link":"https:\/\/jumpcloud.com\/support\/understand-mac-keychain-access","title":{"rendered":"Understand Mac Keychain Access"},"content":{"rendered":"\n
MacOS Keychain Application Access is a unique feature for macOS devices using Device Trust. When some SSO-enabled applications on macOS devices attempt to authenticate users via JumpCloud, they don\u2019t open a browser window to do so. Instead, they present the website in-app, and the app can\u2019t be added to the Device Trust certificate used to authenticate because the device authorizes only supported browsers (Safari, Chrome) access to the Device Trust private key. This results in the user’s device prompting the user for the keychain password when accessing the app, which can cause confusion. When you encounter apps that cause these prompts to appear on macOS devices, you can add these apps as trusted so that your users aren’t prompted.<\/p>\n\n\n\n
Prerequisites<\/strong>:<\/p>\n\n\n\n When you turn Global Certificate Distribution ON<\/strong>, a default list of JumpCloud’s preconfigured trusted applications is added to MacOS Keychain Application Access. The user\u2019s device will renew its Device Trust certificates, and when the device imports a certificate\u2019s private key, it will add these applications as trusted apps. The default list includes common applications that cause the password prompt issue, such as Keeper Password Manager, ZScaler, and Microsoft 365 applications.<\/p>\n\n\n\n JumpCloud cannot predict every application that will send keychain access prompts outside of this common list. For this reason, you can configure additional trusted applications.<\/p>\n\n\n\n <\/a>To grant MacOS Keychain Application Access<\/strong>:<\/p>\n\n\n\n\n
Granting MacOS Keychain App Access<\/h2>\n\n\n\n