Jamf Commercial Cloud, Jamf Premium Cloud, or Jamf High Compliance Cloud-hosted environment
Note:Not available for Jamf GovCloud Premium Cloud Plus
One of the following:
If administrators will log in to Jamf Pro using Jamf IDs, ensure that each administrator has their own Jamf ID that is linked to your organization.
For more information, see Jamf ID in the Jamf Account Documentation.
Note:Environments hosted in Jamf High Compliance Cloud do not currently support authentication with Jamf ID.
If administrators will log in to Jamf Pro using a cloud-based IdP, do the following:
Configure your organization's IdP for an SSO integration.
For more information, see Creating an OIDC App in Your Identity Provider (IdP) in the Jamf Account Documentation and follow the procedure for your IdP.
Verify your SSO domain.
For more information, see Verifying Your SSO Domain in Jamf Account in the Jamf Account Documentation.
Add an SSO connection in Jamf Account, with the Jamf Pro tenant selected as an application allowed to use the connection.
For more information, see Adding an SSO Connection in Jamf Account in the Jamf Account Documentation.
Jamf Pro user accounts or groups with credentials that match the Jamf ID or IdP account. For more information about creating user accounts and groups in Jamf Pro, see Jamf Pro User Accounts and Groups.
Training Video
Watch the Single Sign-On (SSO) with Jamf Account training video to learn how to configure SSO through Jamf Account.
After OIDC authentication is enabled, you will be able to log in to Jamf Pro using single sign-on with Jamf Account by entering your Jamf ID credentials at login.
Alternatively, go to your Jamf Pro instances in the Jamf Account portal and click Log In next to the instance you want to log in to.
If your Jamf Pro instance uses a custom URL or port, you may see an "Unable to verify Jamf Pro URL: On premise-and Premium Cloud URLs cannot be verified automatically" warning dialog displayed when attempting to log in to Jamf Pro. This is currently expected behavior for Jamf Pro instances using a custom URL or port, because Jamf Account depends on a JSON web token validation process to verify the connection, which cannot be completed for instances with custom URLs or ports. A future release of Jamf Account will allow for exceptions to be added to this validation process by request, preventing this warning from appearing on a per-instance basis.