Compliance Benchmarks and Third-Party Compliance Workflows

Compliance Benchmarks Configuration Guide

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

Compliance benchmarks streamlines how you define compliant computers in Jamf Pro when using device compliance with Microsoft Entra or context-aware access with Google. When you create a benchmark in Jamf Pro, the system automatically creates a smart computer group criteria specifically for that benchmark. This criteria, which appears as "[Benchmark Name] - Compliant," tracks all computers that meet the rules defined in your benchmark. By using this group as the compliance group for device compliance or context-aware access, you can ensure that computers in your environment can only access your organization's resources if they meet the standards defined by a specific benchmark.

An extension attribute titled "[Benchmark Name] - Failed Result List" is automatically created for each benchmark. You can use this extension attribute as a smart computer group criteria to track computers that fail to meet the standards defined in the benchmark. By creating a smart computer group that checks if the failed result list is empty, you can easily and automatically identify which computers are compliant with your benchmark standards. This approach also allows for additional criteria to be added, so you can create a more customized compliance group that still adheres to the standards defined in the benchmark.