Creating Context-Aware Access Smart Groups

Jamf Pro Documentation 11.16.0

Solution
Application
Content Type
Technical Documentation
Utilities & Services
version
11.16.0
ft:locale
en-US
vrm_version
11.16.0

The Context-Aware Access integration uses smart groups in Jamf Pro to determine device compliance. As part of the integration, you must create both an “applicable group” and a “compliance group”.

macOS
  • Applicable group

    This smart group should contain all the computers that need access to company resources, regardless of whether they are compliant or not.

  • Compliance group

    This smart group should contain the computers that must meet specific criteria to be considered compliant. For example, the criteria could be meeting macOS version requirements, or the presence of a certain application.

    Best Practice:

    Creating a Compliance Group for macOS

    When creating the compliance group for macOS, add the criteria that computers must have to be considered compliant. For example, you may want to include the following criteria:
    • Operating System Version

    • Last Inventory Update

    • FileVault Status

    Jamf recommends selecting Send email notification on membership change when creating the Compliance Group to be notified when a computer falls out of compliance.
    Smart Computer Group example
iOS and iPadOS
  • Applicable group

    This smart group should contain all the mobile devices that need access to company resources, regardless of whether they are compliant or not.

  • Compliance group

    This smart group should contain the mobile devices that must meet specific criteria to be considered compliant. For example, the criteria could be meeting iOS version requirements, or the presence of a certain application.

    Best Practice:

    Creating a Compliance Group for iOS or iPadOS

    When creating the compliance group for iOS or iPadOS, add the criteria that mobile devices must have to be considered compliant. For example, you may want to include the following criteria:
    • iOS/iPadOS Version

    • Jailbreak Detected

    • Last Backup

    • Passcode Status

    Jamf recommends selecting Send email notification on membership change when creating the smart device group to be notified when a device falls out of compliance.

    Smart Mobile Device Group example

For information on creating smart groups, see Smart Groups.