Configuring a Conditional Access Jamf MFA Policy

Jamf Connect Documentation

Solution
Application
Jamf Connect
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

While this policy will eliminate the need for MFA for devices with Jamf Connect's Zero Trust Network Access enabled, it will enable multi-factor authentication for the specified cloud apps for devices that are not using the service.

Therefore, if you already have one or more Conditional Access policies that enforce MFA, update them to exclude Zero Trust Network Access IP addresses as described below, rather than creating a new Conditional Access policy.

  1. In Azure AD, navigate to Security > Conditional Access.
  2. Click Named Locations, then New Location.
  3. Give the profile a memorable Name (for example, "Jamf Trusted IPs").
  4. Make sure the IP ranges are selected.
  5. Check the Mark as trusted location box.
  6. In the IP ranges area, add the Cloud Internet Gateway IP addresses for Zero Trust Network Access in CIDR notation. For more information, see Zero Trust Network Access Cloud Internet Gateways.
    Note:

    Add the suffix /32 to each IP address.

  7. Click Create.
  8. Back in the Conditional Access panel, click Policies in the left-hand menu.
  9. Click New policy.
  10. Enter a memorable Name (for example, "Jamf MFA").
  11. Click Assignments, then pick the users to which this policy should apply.
    Note:

    Jamf recommends that you start with a set of test users first.

  12. Click Cloud apps or actions, then include the apps for which Zero Trust Network Access should use to access.
    Note:

    Jamf recommends that you test your configuration with a specific cloud app first, before applying this setting to all apps.

  13. Click Conditions, then click Locations.
  14. Click Yes for Configure.
  15. Under Include, select Any Location.
  16. Under Exclude, select Selected Locations and choose the Jamf IPs location that you created above.
  17. Under Access Controls > Grant, select Require multi-factor authentication.
  18. Click Select.
  19. For Enable Policy, select Report Only or On if you are ready to enforce the policy.