OIDC-Based Single Sign-On (SSO) Enhancements
Starting with Jamf Pro 11.20.0, you can specify a custom username claim when you integrate Jamf Account SSO with Microsoft Entra or Google Workspace as your identity provider (IdP). This is helpful if your environment does not use email claims to identify users. If you use Okta or Generic OIDC connections, you can configure username mapping using the custom mapping feature.
Note:Not all IdPs support the username claim by default. If necessary, you can map a different attribute from your IdP to the Identity Provider User Mapping attribute in Jamf Account. This can be done with the Custom Mapping settings for generic OIDC connections or the Custom Username Claim Name setting for Entra ID and Google Identity connections. See Adding an SSO Connection in Jamf Account for information specific to your environment, or contact Jamf Support for assistance.
User and Contact Management Enhancements
You can remove users from the IdP users list in Jamf Account.
Note:
You must also remove users from the identity provider (IdP).
Resolved Issues
Fixed: Managed Service Providers may be unable to manage users, contacts, or roles for customer accounts.
Fixed: Safelisted custom Jamf Pro domains may still display a redirect warning.