- Domain —
com.jamf.connect - Dictionary —
TemporaryUserPermissions - Description —
Used to configure the Privilege Elevation feature in Self Service+.
Setting | Description |
|---|---|
Temporary User Promotion
| (Required) Enables the option for users to request elevated privileges in Self Service+. |
User Promotion Timer
| Displays a timer in the user's menu bar next to the Self Service+ menu bar icon during privilege elevation. |
User Promotion Duration
| Determine duration of the privilege elevation, in minutes. The setting is set to 5 minutes by default. For more information, see Auditing Privilege Elevation with Logs. Note: A duration of 0 disables this feature to a defined group of users. The User Promotion Role ( |
Verify User Promotion
| Require users to authenticate with their identity provider before a promotion can occur. Note: The Verify User Promotion ( |
| Verify User Promotion via FIDO2
| Requires users to authenticate with their identity provider through a browser. This setting supports WebAuthn authenticators, including passkeys and FIDO2 keys, and takes priority over the Verify User Promotion setting. The setting is currently supported with the following identity providers:
Note:Requiring WebAuthn authentication for privilege elevation may require changes to your identity provider's authentication policies. After enabling the setting, the Jamf Connect OIDC application located in your identity provider configuration must use the following Redirect URI to prevent any errors: jamfconnect://loggedin |
User Promotion Limit
| Specifies a limit for how many times a user can request elevated privileges every calendar month. |
User Promotion Reason
| Require users to provide a reason for the temporary elevation request. All elevation reasons are logged locally in the Self Service+ logs. Note: The text entry field for users is limited to 200 characters. |
User Promotion Choices
| Specifies reasons for a temporary elevation request that a user can pick from. |
User Promotion Role
| Restricts who can use the feature and modify additional settings by user or role name for configurations with the following identity providers:
Note: To configure privilege elevation settings by role, you must select Verify User Promotion. The values entered in the User Promotion Role ( Jamf Connect configurations with Okta Identity Engine set as the identity provider require the Scopes ( A duration of 0 will make the feature unavailable to a defined group of users. |
User Promotion Biometrics
| Require users to use Touch ID as a form of authentication prior to a temporary elevation session. Note: The Verify User Promotion ( |
| URL Scheme and Command Line Elevation
| Restricts users from using the privilege elevation feature through the command-line interface or URL schemes. |
Admin Attribute
| Specifies which attribute to use within the User Promotion Role ( Note: If using Microsoft Entra ID, set this value to roles. If using Google Identity, user roles cannot be defined using an ID token. When configuring the Admin Attribute ( |