Users accessing internet sites via Cloud SWG using WSS Agents on Windows and macOS.
MFA required for any user authenticating to Azure, which is bypassed from going into Cloud SWG.
Windows users not experiencing issue, but macOS users report problems where authentication fails.
Enabling the samlWebAuth non ephemeral settings with the 'always intercept' entry for login.microsoftonline.com addresses the issue using
sudo "/Applications/Symantec WSS Agent.app/Contents/MacOS/wssad" -p samlWebAuth=non-ephemeral
Cloud SWG admin wants to minimise changes and use ATM configuration to 'always intercept' login.microsoftonline.com for macOS users.
Adding the tag to the macOS host and then adding an always intercept rule for matching device tags fail - user traffic is still bypassed.
macOS.
WSS Agent.
SAML Authentication via Entra.
WSS Agent Device tags are case sensitive.
Make sure the device tags applied to the macOS hosts match what is defined in Cloud SWG Portal ATM configuration.
In the above case, the device tag assigned on the host was MacOS, whilst the ATM setting was macos.