2025-10-16

Jamf Account Documentation

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

OIDC-Based Single Sign-On (SSO) Enhancements

  • You can now use a private key JWT instead of the client secret when creating a new generic OIDC or new Okta connection.

  • When advanced features is enabled, only the openid value is required. You no longer need email and profile values, as well.

  • When logged in as a Managed Service Provider (MSP) and switching between customer accounts, the SSO tab displays for customer accounts.

  • Loading improvements were made for organizations with hundreds of domains or thousands of contacts.

  • Performance improvements were made for saving a connection with hundreds of domains.

Resolved Issues

  • Fixed: Change log groups may appear on MSP accounts instead of customer accounts.

  • Fixed: Adding the groups scope to an Okta connection does not properly apply mappings.

  • Fixed: AI Assistant, blueprints, or compliance benchmarks may fail to load for organizations with a large amount of groups.