Configuring App Roles in Microsoft Entra ID

Jamf Connect Documentation

Solution
Application
Jamf Connect
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

You can create users as local administrators on computers by using app roles defined in Microsoft Entra ID.

You can use app roles in Microsoft Entra ID to assign users specific roles for Jamf Setup.

Keep the following in mind when configuring roles in Microsoft Entra ID for Jamf Setup:

  • Any role assignments in Microsoft Entra ID will override any roles assigned via managed app configuration.

  • If a user is assigned only one role, Jamf Setup will automatically set up the device using that role and will not display the role selection screen.

  • If a user is not assigned any roles, Jamf Setup will display the role selection screen with a list of all roles available via managed app configuration.

  • To ensure the correct role is configured via Jamf Pro, the app role values must correspond to a Jamf Pro smart group.

Requirements
An app registration for Jamf Connect in Microsoft Entra ID. For more information, see Integrating with Microsoft Entra ID in the Jamf Connect Documentation.
  1. Click the Microsoft Entra ID in the left sidebar.
  2. Click App registrations, and then select your Jamf Connect app registration.
  3. Click App Roles from the sidebar.
  4. Click + Create app role.
  5. In the Create app role pane, do the following:
    1. Enter a role name, such as Administrator, in the Display Name field.

      This value is only used in the Microsoft Entra ID UI.

    2. Select Users/Groups for Allowed member types.
    3. Enter a role value, such as Administrator, in the Value field.

      This value is included in the user's ID token during Jamf Connect authentication.

    4. Add an app role description.
    5. Make sure the Do you want to enable this app role? checkbox is selected.
    6. Click Apply.
  6. Repeat this process to create additional app roles.

Your Jamf Connect app registration now has two or more app roles for role-based local account creation.

You can now assign the roles to any users who are also assigned the app. Assigned users will only be able to select those roles from Jamf Setup, and any other roles will be hidden.