An outbound communication mode has been added for Active Directory Certificate Services integrations. Outbound mode requires Jamf Pro 11.13.0 or later and Jamf AD CS Connector 2.0.0 or later, and is intended for Jamf Cloud-hosted environments. In outbound mode, the connector will periodically connect outbound to Jamf Pro to retrieve any outstanding certificate requests. No firewall ports or reverse proxy configuration are required.
In the connector's traditional inbound mode, when a device needs a certificate, Jamf Pro contacts the connector, which passes a certificate request on to AD CS. AD CS returns newly generated certificates to Jamf Pro. This inbound connectivity typically requires Jamf Cloud customers to open a firewall port and configure a bridge through their DMZ to allow the connection from Jamf Cloud into their network.
If you have an existing AD CS integration and do not need outbound communication mode, Jamf recommends continuing to use Jamf AD CS Connector 1.1.0. You only need Jamf AD CS Connector 2.0.0 if you want to use outbound communication mode.
To move an existing AD CS integration from inbound to outbound communication mode, you must create a new PKI integration and deploy new or updated configuration profiles.
For more information, see the Integrating with Active Directory Certificate Services (AD CS) Using Jamf Pro technical paper.