Jamf Pro can be integrated with a network access management service, such as Cisco Identity Services Engine (ISE). Network integration allows the service to communicate with Jamf Pro to verify that the computers and mobile devices on your network are compliant with your organization’s standards. With information from Jamf Pro, the service can determine the level of network access to grant to a computer or mobile device, provide messaging to end users, and refer end users to enroll their computers and mobile devices to Jamf Pro to become compliant.
When the network access management service refers end users to enroll their computer or mobile device with Jamf Pro, an enrollment URL is provided to the user in a webpage when they access the Internet. The end user can then access the enrollment URL to enroll with Jamf Pro via user-initiated enrollment.
Network integration can also allow the network access management service to send remote commands to computers and mobile devices via Jamf Pro, including passcode lock and wipe commands.
Creating a network integration instance in Jamf Pro prepares Jamf Pro to integrate with a network access management service. This allows you to do the following:
When sites are defined in Jamf Pro, select the site to add the network integration instance to.
Select the saved advanced computer search and advanced mobile device search to be used by the network access management service to verify computers and mobile devices that are compliant with your organization’s standards. Computers and mobile devices that appear in the search results are reported as compliant to the network access management service.
Specify compliance verification failure and compliance remediation messaging that can be displayed to end users via the network access management service.
Configure the passcode to be used when remotely locking or wiping computers via the network access management service.
After saving the network integration instance, view the network integration URL to be used by the network access management service to communicate with the specific Jamf Pro network integration instance.
When using network integration on a per-site basis in Jamf Pro, ensure that any site-specific configuration profiles and policies in Jamf Pro do not conflict with computer and mobile device compliance verification performed through network integration.