Enabling OIDC Authentication in Jamf Pro

Jamf Pro Documentation 11.30.0

Solution
Application
Content Type
Technical Documentation
Utilities & Services
version
11.30.0
ft:locale
en-US
vrm_version
11.30.0
Requirements
  • Jamf Commercial Cloud, Jamf Premium Cloud, or Jamf High Compliance Cloud-hosted environment

    Note:

    Not available for Jamf GovCloud Premium Cloud Plus

  • One of the following:

    • If administrators will log in to Jamf Pro using Jamf IDs, ensure that each administrator has their own Jamf ID that is linked to your organization.

      For more information, see Jamf ID in the Jamf Account Documentation.

      Note:

      Environments hosted in Jamf High Compliance Cloud do not currently support authentication with Jamf ID.

    • If administrators will log in to Jamf Pro using a cloud-based IdP, do the following:

      1. Configure your organization's IdP for an SSO integration.

        For more information, see Creating an OIDC App in Your Identity Provider (IdP) in the Jamf Account Documentation and follow the procedure for your IdP.

      2. Verify your SSO domain.

        For more information, see Verifying Your SSO Domain in Jamf Account in the Jamf Account Documentation.

      3. Add an SSO connection in Jamf Account, with the Jamf Pro tenant selected as an application allowed to use the connection.

        For more information, see Adding an SSO Connection in Jamf Account in the Jamf Account Documentation.

  • Jamf Pro user accounts or groups with credentials that match the Jamf ID or IdP account. For more information about creating user accounts and groups in Jamf Pro, see Jamf Pro User Accounts and Groups.

Before you can use OIDC-based SSO through Jamf Account to log in to Jamf Pro or use the functionality that requires it, you must configure it in Jamf Pro.

Training Video

Watch the Single Sign-On (SSO) with Jamf Account training video to learn how to configure SSO through Jamf Account.

  1. In Jamf Pro, click Settings in the sidebar.
  2. In the System section, click Single sign-on .
  3. Click Edit .
  4. Select Enable SSO Authentication to enable the configuration.
    Note:

    In the Failover Login URL box, click Copy to clipboard, and then save the failover login URL to a secure location. This URL will allow you to log in using your Jamf Pro credentials after SSO is configured and enabled.

  5. Select Jamf Account (OIDC).
  6. (Optional) To enable single sign-on for end users, select Use SAML authentication for end users (using IdP settings from Jamf Pro).

    To configure SAML authentication, follow the instructions in SSO with SAML.

  7. Under OIDC IdP integration settings, click Username or Email for Identity Provider User Mapping.
  8. Under OIDC IdP integration settings, click Username or Email for Jamf Pro User Mapping.

    Jamf Pro must have user accounts or groups with usernames or email addresses that match the value of the chosen mapping.

    These options determine how users in your IdP will be mapped to Jamf Pro users. By default, Jamf Pro gets information about the user from the IdP and matches it with existing Jamf Pro user accounts. If the incoming user account does not exist in Jamf Pro, then group name matching occurs.

  9. Click Save .
  10. (Optional) Copy the Direct IdP login URL to your clipboard for later use.

    This URL can be used to navigate directly to your identity provider login page instead of having to first enter an email address and be redirected. You can add this URL to your bookmarks for a more streamlined login process.

After OIDC authentication is enabled, you will be able to log in to Jamf Pro using single sign-on with Jamf Account by entering your Jamf ID credentials at login.

Alternatively, go to your Jamf Pro instances in the Jamf Account portal and click Log In next to the instance you want to log in to.

Note:

If your Jamf Pro instance uses a custom URL or port, you may see an "Unable to verify Jamf Pro URL: On premise-and Premium Cloud URLs cannot be verified automatically" warning dialog displayed when attempting to log in to Jamf Pro. This is currently expected behavior for Jamf Pro instances using a custom URL or port, because Jamf Account depends on a JSON web token validation process to verify the connection, which cannot be completed for instances with custom URLs or ports. A future release of Jamf Account will allow for exceptions to be added to this validation process by request, preventing this warning from appearing on a per-instance basis.