Configuring Jamf Pro for Seamless Learning Access with Blueprints

RapidIdentity Platform Documentation

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

To configure Jamf Pro for Seamless Learning Access, you need to create an API role and client for RapidIdentity and then create a blueprint to deploy the declarations to managed devices.

Important:

Only one blueprint containing a Seamless Learning Access component can be scoped to a device at a time. If multiple blueprints with this component are scoped to the same device, the Seamless Learning Access configuration will not apply correctly. Before deploying, confirm that no other blueprint containing a Seamless Learning Access component is already scoped to the target devices.

Requirements

A smart group or static group containing iPad devices that meet user requirements for Seamless Learning Access. For user requirements, see Requirements for Seamless Learning Access. Device users must be synchronized with Apple School Manager. For more information, see Apple School Manager Integration in the Jamf Pro Documentation.

For a full list of blueprints requirements, including privileges, site limitations, and OIDC authentication, see Requirements for Jamf Pro Blueprints in the Jamf Pro Blueprints Configuration Guide.

  1. In Jamf Pro, click Settings in the sidebar.
  2. In the System section, click API Roles and Clients .
  3. Click New .
  4. Enter a display name for the role.
  5. From the Privileges pop-up menu, choose "Read User".
  6. Click Save in the bottom-right corner of the pane.
  7. In the API Clients tab, click + New.
  8. Enter a display name for the API client, such as Seamless Learning Access.
  9. In the API Roles field, add the roles you want to assign to the client.
  10. Click Enable API Client to allow the client to be used to generate a client secret, and then click Save.
  11. Copy the Client ID and the Client Secret values, which are required to configure the integration for Jamf Pro in RapidIdentity.

    For more information, see Creating RapidIdentity API Credentials.

  12. In the sidebar, click Blueprints.
  13. Create a blueprint with a Seamless Learning Access component.

    For more information, see Building a Blueprint from a Library of Components in the Jamf Pro Blueprints Configuration Guide.

  14. Enter the Base URL and API key from your RapidIdentity integration.
  15. Click Save.
  16. Click Deploy to deploy the blueprint to the configured device groups.

After deployment, the blueprint installs the required declarations on managed devices. On Shared iPad devices, a user configuration declaration is installed. On standard iPad devices, a standard configuration declaration is installed. Both configurations include the single sign-on extension and the binding token required for Seamless Learning Access.

Use the following information to resolve common issues after deploying a Seamless Learning Access blueprint.

  • If users see login screens after the blueprint is deployed, verify that the SSO extension is installed and active on the device. Also confirm that the Seamless Learning Access app is installed. If either is missing, redeploy the blueprint and check that the target devices are in the correct scope.

  • If users can access the device but Seamless Learning Access does not activate, confirm that a Managed Apple Account is synced to the device from Apple School Manager. Also verify that the user account is synced from Jamf Pro into RapidIdentity. If the Managed Apple Account or user sync is missing, resolve the sync issue and then redeploy the blueprint.

  • If the Seamless Learning Access configuration does not apply correctly, confirm that only one blueprint containing a Seamless Learning Access component is scoped to the affected devices. Review any smart groups used for scoping to ensure that membership changes have not added devices to a second blueprint. Remove the duplicate scope assignment, then redeploy.