修改您的 iOS 或 iPadOS 應用程式以支援共享裝置模式

在這個教學中,你將學習如何修改 iOS 或 iPadOS 應用程式以支援共享裝置模式(SDM)。 SDM 是 Microsoft Entra ID 的一項功能,讓組織能夠設定 iOS、iPadOS 或 Android 裝置,方便多位員工共享,這是前線工作者常見的做法。

在本教學課程中,您會:

  • 新增支援單一帳號模式。
  • 把你的應用程式設定成使用 SDM。
  • 偵測共用裝置模式。
  • 確認登入使用者是否已更改。

先決條件

偵測共用裝置模式

偵測共享裝置模式對你的應用程式很重要。 許多應用程式在共用裝置上使用時,需要改變使用者體驗(UX)。 例如,你的應用程式可能有「註冊」功能,但這不適合第一線工作者,因為他們很可能已經有帳號。 如果你的應用程式處於共享裝置模式,你也可以考慮在資料處理上增加額外的安全性。

請使用 getDeviceInformationWithParameters:completionBlock: API MSALPublicClientApplication 來判斷應用程式是否在裝置上以共享裝置模式運行。

以下程式碼片段展示了使用 getDeviceInformationWithParameters:completionBlock: API 的範例。

Swift

application.getDeviceInformation(with: nil, completionBlock: { (deviceInformation, error) in

    guard let deviceInfo = deviceInformation else {
        return
    }

    let isSharedDevice = deviceInfo.deviceMode == .shared
    // Change your app UX if needed
})

Objective-C

[application getDeviceInformationWithParameters:nil
                                completionBlock:^(MSALDeviceInformation * _Nullable deviceInformation, NSError * _Nullable error)
{
    if (!deviceInformation)
    {
        return;
    }

    BOOL isSharedDevice = deviceInformation.deviceMode == MSALDeviceModeShared;
    // Change your app UX if needed
}];

取得已登入使用者,並判斷裝置上的使用者是否已變更

支援共享裝置模式的另一個重要部分是判斷使用者在裝置上的狀態,並在使用者變更或裝置上完全沒有使用者時清除應用程式資料。 你有責任確保資料不會外洩給其他使用者。

你可以用 getCurrentAccountWithParameters:completionBlock: API 查詢裝置上目前已登入的帳號。

Swift

let msalParameters = MSALParameters()
msalParameters.completionBlockQueue = DispatchQueue.main

application.getCurrentAccount(with: msalParameters, completionBlock: { (currentAccount, previousAccount, error) in

    // currentAccount is the currently signed in account
    // previousAccount is the previously signed in account if any
})

Objective-C

MSALParameters *parameters = [MSALParameters new];
parameters.completionBlockQueue = dispatch_get_main_queue();

[application getCurrentAccountWithParameters:parameters
                             completionBlock:^(MSALAccount * _Nullable account, MSALAccount * _Nullable previousAccount, NSError * _Nullable error)
{
    // currentAccount is the currently signed in account
    // previousAccount is the previously signed in account if any
}];

全局性登入使用者

當裝置被設定為共享裝置時,你的應用程式可以呼叫 acquireTokenWithParameters:completionBlock: API 登入該帳號。 當第一個應用程式登入帳號後,該帳號將對裝置上所有符合資格的應用程式開放。

Objective-C

MSALInteractiveTokenParameters *parameters = [[MSALInteractiveTokenParameters alloc] initWithScopes:@[@"api://myapi/scope"] webviewParameters:[self msalTestWebViewParameters]];

parameters.loginHint = self.loginHintTextField.text;

[application acquireTokenWithParameters:parameters completionBlock:completionBlock];

全域登出使用者

以下程式碼會移除已登入的帳號,並清除應用程式及共享裝置中快取的令牌。 不過,它不會清除應用程式 中的資料 。 你必須清除應用程式中的資料,並清除應用程式可能向使用者顯示的任何快取資料。

Swift

let account = .... /* account retrieved above */

let signoutParameters = MSALSignoutParameters(webviewParameters: self.webViewParamaters!)
signoutParameters.signoutFromBrowser = true // To trigger a browser signout in Safari.

application.signout(with: account, signoutParameters: signoutParameters, completionBlock: {(success, error) in
    if let error = error {

        // Signout failed

        return

    }

    // Sign out completed successfully

})

Objective-C

MSALAccount *account = ... /* account retrieved above */;

MSALSignoutParameters *signoutParameters = [[MSALSignoutParameters alloc] initWithWebviewParameters:webViewParameters];

signoutParameters.signoutFromBrowser = YES; // To trigger a browser signout in Safari.

[application signoutWithAccount:account signoutParameters:signoutParameters completionBlock:^(BOOL success, NSError * _Nullable error)

{

    if (!success)

    {

        // Signout failed

        return;

    }

    // Sign out completed successfully

}];

Microsoft Enterprise 的 SSO 外掛(Apple 裝置)僅清除應用程式的狀態。 在 Safari 瀏覽器上它無法清除狀態。 你可以使用程式碼片段中顯示的可選 signoutFromBrowser 屬性,在 Safari 中觸發瀏覽器登出。 這會讓瀏覽器在裝置上短暫啟動。

接收廣播以偵測從其他應用程式起始的全域登出

若要接收帳戶變更廣播,您必須註冊廣播接收器。 收到帳戶變更廣播時,立即獲取當前登入的使用者,並確認裝置上的使用者是否已變更。 如果偵測到變更,就會開始為先前登入的帳戶進行資料清理。 建議您適當地停止所有作業並清除資料。

下列程式碼片段示範如何註冊廣播接收器。

NSString *const MSAL_SHARED_MODE_CURRENT_ACCOUNT_CHANGED_NOTIFICATION_KEY = @"SHARED_MODE_CURRENT_ACCOUNT_CHANGED";

- (void) registerDarwinNotificationListener 

{ 

   CFNotificationCenterRef center =

   CFNotificationCenterGetDarwinNotifyCenter(); 

   CFNotificationCenterAddObserver(center, nil,

   sharedModeAccountChangedCallback,

   (CFStringRef)MSAL_SHARED_MODE_CURRENT_ACCOUNT_CHANGED_NOTIFICATION_KEY, 

   nil, CFNotificationSuspensionBehaviorDeliverImmediately); 

} 

// CFNotificationCallbacks used specifically for Darwin notifications leave userInfo unused 

void sharedModeAccountChangedCallback(CFNotificationCenterRef center, void * observer, CFStringRef name, void const * object, __unused CFDictionaryRef userInfo) 

{ 

    // Invoke account cleanup logic here 

} 

欲了解更多關於可用選項 CFNotificationAddObserver 或查看 Swift 中對應方法簽名的資訊,請參閱:

以 iOS 為例,應用程式需要背景權限才能在背景保持活躍並收聽達爾文通知。 背景功能必須新增以支援不同的背景操作——如果您的應用程式僅具備聽取達爾文通知的背景功能,可能會被蘋果 App Store 拒絕。 如果你的應用程式已經設定完成背景操作,你可以把監聽器加入該操作中。 欲了解更多 iOS 背景功能,請參閱 設定背景執行模式

支援共享裝置模式的 Microsoft 應用程式

以下 Microsoft 應用程式支援 Microsoft Entra 共享裝置模式:

Important

公開預覽是在沒有服務等級協議的情況下提供,且不建議用於生產工作負載。 部分功能可能未被支援或功能受限。 欲了解更多資訊,請參閱 線上服務通用授權條款。

支援共用裝置模式的第三方 MDM

這些第三方行動裝置管理(MDM)提供者支援 Microsoft Entra 的共用裝置模式:

下一步

要查看共享裝置模式的運作,以下 GitHub 上的程式碼範例包含一個在 iOS 裝置上以共享裝置模式執行前線員工應用程式的範例:

MSAL iOS Swift Microsoft 圖形 API 範例