Verify the configuration.
After deploying the SSO extension profile, test the configuration by having a
user log into their macOS device and observe the Prisma Agent
authentication behavior. The agent should connect automatically without
prompting for credentials.
Check the agent logs to confirm that SSO token retrieval is successful and
that authentication completes using the Platform SSO mechanism. If
authentication fails, verify that the AppPrefixAllowList
includes the correct Palo Alto Networks application identifier and that the
SSO extension is properly communicating with your identity provider.