Directory service group criteria allow users who are included in connected directory service groups, such as on an LDAP server or in a connected cloud identity provider (IdP), to appear in smart groups and advanced search results.
The directory service criteria are described in the table.
Category | Criteria |
|---|---|
Computer | User last logged in - Computer directory service group |
User last logged in - Self Service directory service group | |
User last logged in - MDM directory service group | |
Username directory service group | |
Assigned user directory service group | |
Mobile device | User last logged in - Self Service directory service group |
User last logged in - MDM directory service group | |
Username directory service group | |
Assigned user directory service group | |
User | Username directory service group |
Smart groups and advanced searches with these criteria use a local cache to store user information obtained from an LDAP server or cloud IdP. Jamf Pro initiates a sync with directory services every 20 minutes, adding new users to the local cache and removing expired users. Users that are already included in the cache are updated according to the caching rules in Jamf Pro and the IdP (usually every 24 hours). Synchronization can take additional time to complete if groups contain a large number of users.
Jamf Pro uses the Group UUID mapping on the LDAP or Cloud IdP page to resolve group membership for smart groups that use the new directory criteria.
For example, with an Okta configuration that uses the default uniqueIdentifier, cn, and objectGUID options, the directory lookup does not return a uuid field, which may result in a validation error that prevents the smart group from saving.
Configure the following LDAP mappings:
- User mappings Set
User UUIDtouid - Group mappings: Set
Group UUIDtouniqueIdentifier
If you previously used a different value for User UUID, verify smart group behavior after making the change.