Creating a Device Identity Activation Profile

Technical Paper: Integrating Zscaler with Jamf Device Identity

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

To integrate Zscaler with Jamf Device Identity, create an activation profile that enrolls Jamf Trust with your devices.

Requirements

An existing identity provider integration with Jamf Security Cloud. For additional information, see Identity Provider Integrations in the Jamf Security Cloud documentation.

  1. In Jamf Security Cloud, navigate to Devices > Activation profiles.
  2. Click Create profile.
  3. On the Capabilities and routing page, select the Network security and Device identity security capabilities to enable with the activation profile.
    Note:

    If Device Identity does not display in this section, then click Switch to Advanced Mode and select Device Identity.

  4. Choose a traffic vectoring option and then click Next.
  5. If Device identity is the only capability of the activation profile, in the Authentication section, select Without identity provider and Assign random identifier.

    If you are using Jamf Connect's' Zero Trust Network Access capabilities along with the Device identity security capability, configure the following:

    1. Select User credentials (SSO) and choose your identity provider.
    2. Manually open the Jamf Trust app and use single sign-on for Zero Trust Network Access.
      Important:

      Selecting other options are not supported for macOS, and the profile will not install correctly.

  6. On the Advanced settings page, specify additional settings for the profile, such as the profile's expiration date.

    Available settings depend on which service capabilities you selected for the activation profile.

  7. On the Naming and grouping page, enter general information about the profile:
    1. Enter a descriptive name for the activation profile.
      Best Practice:

      Use descriptive names and a consistent naming convention for all activation profiles in your environment.

    2. Choose a device group to associate with the profile.
      Devices that use the activation profile to enroll are automatically added to this group in the Jamf Security Cloud portal.
      Note:If UEM Connect is configured, this group is overwritten during the next UEM Connect sync.
  8. On the Review page, confirm the details of the activation profile and then click Save and create.
  9. Expand the Configuration profiles section, then click Download configuration profile to download the .mobileconfig file.

You can now upload the .mobileconfig file into your UEM and scope it to your test devices.