Skip to content

Azure CLI on macOS got security upgrade: native broker authentication

Why we built this 


If you manage Azure resources from a Mac today, az login opens a browser tab, you sign in, and a token comes back to the CLI. That’s worked well for a long time. As security requirements become more stringent, many enterprise organizations are adopting secure authentication brokers to strengthen identity protection and reduce authentication-related risks. 


Many organizations require broker-based authentication as a matter of security policy. A broker is the operating system’s own credential broker — on Windows this is the Web Account Manager (WAM), and it’s what lets az login reuse your existing signed-in Windows account instead of opening a browser every time. Depending on the broker, device configuration, and policies applied by the organization, broker-based authentication can provide: 



  • Device-bound refresh tokens, which help protect tokens from exfiltration and misuse 



  • Support for Conditional Access and device compliance checks where those capabilities are configured and available 



  • Single sign-on using accounts known to the operating system, reducing repeated credential prompts 


Azure CLI has supported broker authentication on Windows for a while. Beginning with Azure CLI 2.91.0, organizations with stringent security requirements can also use broker-based authentication with Azure CLI on macOS.


What changed 


Beginning with Azure CLI 2.91.0, broker-based authentication is available in preview on macOS. The feature uses MSAL’s native macOS broker support and is disabled by default, so you remain in control of when to enable it. 


After you opt in and run az login, Azure CLI opens a native macOS account picker instead of starting the sign-in flow in a browser. You can select an account already known to the broker or add another account. If a compatible broker isn’t available, Azure CLI falls back to the existing browser-based sign-in flow. 


How Homebrew Cask supports broker authentication 


The core MSAL library is open source, but the macOS broker runtime is not. It is subject to strict internal compliance and intellectual property protection requirements and must also satisfy Apple-specific requirements such as notarization. 


Azure CLI is now available through Homebrew Cask, a supported installation method that can accommodate these requirements and support broker-based authentication on macOS. The familiar package name continues to work for new installations: 


brew update
brew install azure-cli

You can also select the Cask explicitly: 


brew update
brew install –cask azure-cli

 


We tested the migration on a Mac that had Azure CLI 2.90.0 installed through the former Homebrew Formula. After brew update, Homebrew detected that azure-cli had moved to homebrew/cask, unlinked the existing Formula, downloaded Azure CLI 2.91.0 or later, and linked the az executable and shell completions from the Cask. The final output confirmed: 


 


azure-cli was successfully installed! 
azure-cli has been moved to homebrew/cask. 
The existing keg has been unlinked. 



Homebrew detects the package migration, installs Azure CLI from Cask, and preserves the az command. 


Homebrew also recommended removing the old Formula record when convenient: 


brew uninstall –formula –force azure-cli

This means scripts that use brew install azure-cli can continue to use the same package name. If you previously used the Azure CLI preview tap and Homebrew still resolves stale Formula metadata, remove that tap and retry: 


brew untap azure/azure-cli
brew update
brew install azure-cli

What the broker sign-in experience looks like 



  1. Install Azure CLI 2.91.0 or later and make sure a compatible authentication broker, such as Microsoft Company Portal, is available on your Mac. 

  2. Enable broker-based authentication: 


az config set core.enable_broker_on_mac=true
az account clear

You can confirm the setting with: 


az config get core.enable_broker_on_mac

 


     3. Start a new sign-in: 


az login

 


     4. Azure CLI opens the native single sign-on account picker. Select an existing account and choose Continue or use the add-account button to sign in with another account. 



 


      After broker authentication is enabled, az login opens the native account picker instead of starting in a browser. 


     5. Run az account show to confirm that you’re signed in with the expected account and tenant. 


The broker changes how Azure CLI acquires credentials; it doesn’t change Azure CLI’s subscription or tenant selection model. If your account belongs to multiple tenants, you might still need to select the intended tenant explicitly: 


az login –tenant <tenant-id>

To opt out and return to browser-based authentication: 


az account clear
az config set core.enable_broker_on_mac=false
az login

If a compatible broker isn’t installed or available, Azure CLI automatically falls back to browser-based authentication. 


What’s next 


This is one part of a broader push to bring Azure CLI’s macOS experience up to parity with Windows and Linux — including packaging improvements (to keep pace with Apple’s tightening notarization requirements). If you run Azure CLI on macOS in an enterprise environment, we’d love to hear from you — file feedback or ask questions at Azure/azure-cli on GitHub. 


References 




Microsoft Tech Community originally posted this article on 9 October 2026 at 5:40 AM.

Leave a Reply