Configuring User Import and Synchronization from Jamf Pro

RapidIdentity Platform Documentation

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

To create SSO sessions for Jamf Pro device users, RapidIdentity must synchronize user information from Jamf Pro on a regular basis.

Seamless Learning Access prefers the Managed Apple Account as the unique identifier for each user. The default mapping in the Jamf Pro Source Adapter sets the Managed Apple Account from Jamf Pro as the Seamless Learning Access User ID attribute in RapidIdentity.

User account requirements vary by iPad deployment model:

Shared iPad devices
Shared iPad devices always use Managed Apple Accounts. Users must be synchronized into Jamf Pro from Apple School Manager.
1:1 iPad devices
1:1 iPad users may or may not have Managed Apple Accounts. Users with Managed Apple Accounts must be synchronized into Jamf Pro from Apple School Manager. For deployments using Jamf Pro 11.28.0 or earlier, follow the additional mapping configuration described in Mapping the Seamless Learning Access User ID in Identity Hub.
Requirements
  • Access to your RapidIdentity administrator portal

  • An API client in Jamf Pro for importing and synchronizing users into RapidIdentity

  • The Base URL, Access Token URL, Client ID, and Client Secret for the Jamf Pro Seamless Learning Access API

  1. Navigate to your RapidIdentity administrator portal.
  2. From the module selector, choose "Identity Hub".
  3. Click + Add Source.
  4. Select the Jamf Pro source adapter from the list of available sources.
  5. Enter the Base URL and the Access Token URL of the Jamf Pro server.
  6. Enter the Client ID and Client Secret for the Jamf Pro Seamless Learning Access API.
  7. Set the email attribute as the key for matching data between Jamf Pro and RapidIdentity.
    Note:

    An attribute from Jamf Pro must be identified as the key. The Jamf Pro Source Adapter is configured to populate the Email attribute in RapidIdentity from the Managed Apple Account to ensure unique values are always provided. The attribute to use as the key depends on whether your environment syncs users into Jamf Pro from Apple School Manager:

    • Environments that sync users from Apple School Manager are guaranteed to have Managed Apple Accounts and can use the email attribute from Jamf Pro as the key.

    • Environments that do not sync users from Apple School Manager may not have Managed Apple Accounts and should use the id attribute from Jamf Pro, which maps to the System 4 ID attribute in RapidIdentity, as the key.

    1. Click the key icon to the left of the email attribute.
    2. Toggle on Is Key.
    3. Keep the default Type and Group Name settings of Exact Match and Default.
    4. Click Save, then click Next.

      The key icon becomes bold to indicate the key is set.

  8. Configure a source filter to prevent creating user accounts in RapidIdentity that do not have a Managed Apple Account.
    1. Click the radio button next to I want to filter data imported from Jamf Pro.
    2. Toggle on Enable Filter.
    3. In the Rules selector, click + Rule.
    4. For the When criteria, select Seamless Learning Access User ID.
    5. For the Operator, select exists.
    6. If email is used as the Seamless Learning Access User ID identifier, click + Rule.
    7. For the When criteria, select Email.
    8. For the Operator, select not equal to.
    9. For the Value, enter the email address belonging to the RapidIdentity tenant administrator.
    10. Click Save.
    11. Click Proceed to acknowledge any warning message, then click Next.
  9. Configure the synchronization schedule.
    1. Toggle on Enable Schedule.
    2. Set the Start Time to several hours after the start time configured in Jamf Pro for synchronizing users from Apple School Manager.

      This delay ensures that daily updates from Apple School Manager are reflected in RapidIdentity.

    3. Set Repeat Every (Hours) to 0 to avoid unnecessary syncs with Jamf Pro.
    4. Click Save.
  10. Toggle on Enable Source if it is not already on.
  11. Click Finish to complete the integration.

Users with a Managed Apple Account from Jamf Pro synchronize automatically with RapidIdentity on the configured schedule.

To run a manual sync or test that the integration with Jamf Pro is configured correctly:

  1. Click the Jamf Pro source adapter from the home screen in Identity Hub and select Schedule from the navigation tabs at the top of the page.

  2. Toggle on Enable Source if it is not already on.

  3. In the Manual run section, toggle off Run in log-only mode.

  4. Click Run Now to start the synchronization job.

To monitor the synchronization job, select Jobs from the navigation tabs at the top of the page. The Jamf Pro job displays a status of Running. When the job completes, click the ellipsis next to the Job ID and select View Report to see the outcome.