Directory Service Group Criteria

Jamf Pro Documentation 11.30.0

Solution
Application
Content Type
Technical Documentation
Utilities & Services
version
11.30.0
ft:locale
en-US
vrm_version
11.30.0

Directory service group criteria allow users who are included in connected directory service groups, such as on an LDAP server or in a connected cloud identity provider (IdP), to appear in smart groups and advanced search results.

The directory service criteria are described in the table.

Category

Criteria

Computer

User last logged in - Computer directory service group

User last logged in - Self Service directory service group

User last logged in - MDM directory service group

Username directory service group

Assigned user directory service group

Mobile device

User last logged in - Self Service directory service group

User last logged in - MDM directory service group

Username directory service group

Assigned user directory service group

User

Username directory service group

Smart groups and advanced searches with these criteria use a local cache to store user information obtained from an LDAP server or cloud IdP. Jamf Pro initiates a sync with directory services every 20 minutes, adding new users to the local cache and removing expired users. Users that are already included in the cache are updated according to the caching rules in Jamf Pro and the IdP (usually every 24 hours). Synchronization can take additional time to complete if groups contain a large number of users.

When you add one of these criteria to a smart group or advanced search, you can select the Browse (...) button to open the Search Directory Service User Groups dialog and search the name of a directory group.
Note:

Jamf Pro uses the Group UUID mapping on the LDAP or Cloud IdP page to resolve group membership for smart groups that use the new directory criteria.

For example, with an Okta configuration that uses the default uniqueIdentifier, cn, and objectGUID options, the directory lookup does not return a uuid field, which may result in a validation error that prevents the smart group from saving.

Configure the following LDAP mappings:

  • User mappings Set User UUID to uid
  • Group mappings: Set Group UUID to uniqueIdentifier

If you previously used a different value for User UUID, verify smart group behavior after making the change.