DNSFilter’s current macOS Identity Sync development appears to rely on the Active Directory SID of the Mac, which means the device would need to be traditionally domain-joined to AD.
For a new macOS identity feature, this seems like it is being built around a legacy deployment model. Traditional AD binding on macOS has been declining for years, while Apple is heavily pushing organizations toward MDM-managed devices and Platform SSO for modern enterprise identity.
Our Macs are managed through MDM and are moving toward Platform SSO rather than being bound to on-premises Active Directory. Requiring an AD computer SID would mean introducing a legacy AD dependency solely to support Identity Sync.
It would be much better if macOS Identity Sync could leverage the identity established through Platform SSO and the associated Microsoft/Entra device or user identifiers rather than requiring the Mac to have an AD SID.
This would make the feature usable for organizations following Apple’s current recommended identity architecture and avoid building new macOS functionality around traditional domain binding.
Request: Support Identity Sync for macOS devices using Platform SSO / modern cloud identity without requiring the Mac to be domain-joined to Active Directory.