Requirements
You must meet the general Requirements for SSO.
Note:Organization privileges in Microsoft Entra ID are required to import verified domains from Microsoft. After setup, users configured in the IdP require only Profile and Group Read privileges in Microsoft Entra ID.
- Log in to the Jamf Account portal.
- Click Organization.
- Click SSO.
- Click New Connection.
- Under Connection Settings, click the Connection Type pop-up menu, and choose Microsoft Entra ID.
- Add a name for your connection and choose your hosting region from the Hosting region pop-up menu.
- Under Setup method, ensure Use Microsoft's admin consent flow for multi tenant applications is selected.
- Click the Connect with Microsoft button.
Note:You can share a link to the page that opens after clicking Connect with Microsoft with other administrators on your team whom have privileges to make changes in Microsoft Entra ID.
- Log in to your organization's Microsoft Entra admin center.
- Click Accept on the Permissions requested pane.
- Configure the remaining settings in Jamf Account.
- Click Save.
Users configured in the IdP can now log in using SSO for all enabled
Jamf applications.
Note:Users can still log in to Jamf applications using Jamf ID if desired by clicking Continue with Jamf ID.
Specific user authorization roles and permissions must be configured in each
Jamf application.