Directory Service Group Criteria - Jamf Pro Documentation 11.29.0

Jamf Pro Documentation 11.29.0

Solution
Application
Content Type
Technical Documentation
Utilities & Services
version
11.29.0
ft:locale
en-US
vrm_version
11.29.0

Directory service group criteria allow users who are included in connected directory service groups, such as on an LDAP server or in a connected cloud IdP (Identity Provider), to appear in smart groups and advanced search results.

The directory service criteria are described in the table.

Category

Criteria

Computer

User last logged in - Computer directory service group

User last logged in - Self Service directory service group

User last logged in - MDM directory service group

Username directory service group

Assigned user directory service group

Mobile device

User last logged in - Self Service directory service group

User last logged in - MDM directory service group

Username directory service group

Assigned user directory service group

User

Username directory service group

Smart groups and advanced searches with these criteria use a local cache to store user information obtained from an LDAP server or cloud identity provider (IdP). The local cache synchronizes with directory services every 20 minutes, triggering smart groups to recalculate membership. For groups with a large number of users, the initial sync may take additional time to complete.

When you add one of these criteria to a smart group or advanced search, you can select the Browse (...) button to open the Search Directory Service User Groups dialog and search the name of a directory group.
Note:

Jamf Pro uses the Group UUID mapping on the LDAP or Cloud IdP page to resolve group membership for smart groups that use the new directory criteria.

For example, with an Okta configuration that uses the default uniqueIdentifier, cn, and objectGUID options, the directory lookup does not return a uuid field, which may result in a validation error that prevents the smart group from saving.

Configure the following LDAP mappings:

  • User mappings Set User UUID to uid
  • Group mappings: Set Group UUID to uniqueIdentifier

If you previously used a different value for User UUID, verify smart group behavior after making the change.