Goal
Create standard Jamf Pro users and groups with various privilege sets.
Video
Key points
-
Jamf Pro user accounts and groups can be created and given privileges in .
-
Jamf Pro user accounts are used to authenticate to and perform management tasks in Jamf Pro.
-
A variety of privilege sets can be assigned to users.
-
"Administrator" grants full create, read, update, and delete privileges.
-
"Auditor" grants read-only access to Jamf Pro.
-
"Enrollment Only" grants privileges to enroll devices in Jamf Pro and log in to send enrollment invitations.
-
"Custom" allows granular privilege assignments.
-
-
Groups can be used to assign the same privileges to multiple users.
-
If a user is assigned to multiple groups, every privilege from those groups is available to that user.
-
Review
To view answers, click arrow next to each question.
Practice
-
Create a new standard user in Jamf Pro with the privilege set "Enrollment Only".
-
In User accounts and groups, click New.
-
With Create Standard Account selected, click Next.
-
Enter a username and a password.
-
From the Privilege Set pop-up menu, select "Enrollment Only".
-
Click Save.
-
-
Log in as this user to see how their view of Jamf Pro is different from that of an administrator.
-
Log out and log back in as an administrator.
-
Create a new standard group with the "Administrator" privilege set.
-
In User accounts and groups, click New.
-
With Create Standard Group selected, click Next.
-
Enter a display name for the group.
-
From the Privilege Set pop-up menu, select "Administrator".
-
Click Save.
-
-
Change the access type of the user you created in Task 1 to "Group Access" and add them to the newly created group.
-
In User accounts and groups, click the username of the account created in Task 1.
-
Click Edit.
-
From the Access Level pop-up menu, select "Group Access".
-
On the Group Membership tab, select the group that was created in Task 4.
-
Click Save.
-
-
Log in as this user once more to see how their privileges have changed.
Resources
Jamf Pro Documentation