Lesson 10: User Accounts and Groups

Jamf 100 Course

Solution
Application
Content Type
Training Content
Utilities & Services
ft:locale
en-US

Goal

Create standard Jamf Pro users and groups with various privilege sets.

Video

Key points

  • Jamf Pro user accounts and groups can be created and given privileges in Settings > System > User accounts and groups.

  • Jamf Pro user accounts are used to authenticate to and perform management tasks in Jamf Pro.

  • A variety of privilege sets can be assigned to users.

    • "Administrator" grants full create, read, update, and delete privileges.

    • "Auditor" grants read-only access to Jamf Pro.

    • "Enrollment Only" grants privileges to enroll devices in Jamf Pro and log in to send enrollment invitations.

    • "Custom" allows granular privilege assignments.

  • Groups can be used to assign the same privileges to multiple users.

    • If a user is assigned to multiple groups, every privilege from those groups is available to that user.

Review

To view answers, click arrow next to each question.

  1. Jamf Pro offers Administrator, Auditor, Enrollment Only, and Custom privilege sets for users and groups.
  2. Users added to two or more groups receive the combined privileges of every group they belong to.
  3. Jamf Pro user accounts can be found in Settings > System > User accounts and groups.

Practice

  1. Create a new standard user in Jamf Pro with the privilege set "Enrollment Only".

    1. In User accounts and groups, click New.

    2. With Create Standard Account selected, click Next.

    3. Enter a username and a password.

    4. From the Privilege Set pop-up menu, select "Enrollment Only".

    5. Click Save.

  2. Log in as this user to see how their view of Jamf Pro is different from that of an administrator.

  3. Log out and log back in as an administrator.

  4. Create a new standard group with the "Administrator" privilege set.

    1. In User accounts and groups, click New.

    2. With Create Standard Group selected, click Next.

    3. Enter a display name for the group.

    4. From the Privilege Set pop-up menu, select "Administrator".

    5. Click Save.

  5. Change the access type of the user you created in Task 1 to "Group Access" and add them to the newly created group.

    1. In User accounts and groups, click the username of the account created in Task 1.

    2. Click Edit.

    3. From the Access Level pop-up menu, select "Group Access".

    4. On the Group Membership tab, select the group that was created in Task 4.

    5. Click Save.

  6. Log in as this user once more to see how their privileges have changed.

Resources

Jamf Pro Documentation