Embedded browser used in AW authentication cannot access Entra ID device certificates that are stored in macOS keychain and therefore SSO authentication does not work. This is the case for example when OKTA is used for Platform SSO in macOS platform.