To create single sign-on (SSO) sessions for Jamf School device users, RapidIdentity must synchronize user information from Jamf School on a regular basis.
Seamless Learning Access prefers the Managed Apple Account as the unique identifier for each user. The default mapping in the Jamf School source adapter sets the user's Managed Apple Account from Jamf School as the Seamless Learning Access User ID attribute in RapidIdentity. When the user does not have a Managed Apple Account, the email address from Jamf School is used instead.
User account requirements vary by iPad deployment model:
- Shared iPad devices
- Shared iPad devices always use Managed Apple Accounts. Users must be synchronized into Jamf School from Apple School Manager.
- 1:1 iPad devices
- 1:1 iPad users may or may not have Managed Apple Accounts. Users with Managed Apple Accounts must be synchronized into Jamf School from Apple School Manager. Users without Managed Apple Accounts will use their email address as the Seamless Learning Access User ID.
Requirements
- Access to your RapidIdentity administrator portal
- The base URL and network ID of the Jamf School instance
- An API key in Jamf School with read access rights for the Jamf School source adapter
- Navigate to your RapidIdentity administrator portal.
- From the module selector, choose .
- Click + Add Source.
- Select the Jamf School source adapter from the list of available sources, and then click Next.
- Enter the base URL of the Jamf School instance, and then click Next.
For example, https://your-school.jamfcloud.com.
- Enter the network ID and API key for the Jamf School instance, and then click Next.
- To locate your network ID, navigate to in Jamf School.
The network ID is the value of the network= parameter in the MDM server URL.
- To create an API key in Jamf School, navigate to and click +Add API Key. Set the access rights and click Apply.
The API key requires read access rights for the Jamf School source adapter.
- Set the Seamless Learning Access user ID attribute as the key for matching data between Jamf School and RapidIdentity.
- Click the key icon to the left of the mapping expression for the Seamless Learning Access user ID attribute.
- Toggle on Is key.
- Add a mapping that sets the Claimed attribute in RapidIdentity to
TRUE for all users.- Click + Add mapping.
- Select as the RapidIdentity attribute.
- Click the arrow between the two columns, select < > Code as the Mapping type, and then click Proceed.
- Enter ""TRUE"" in the Advanced editor, and then click Save.
- Modify any of the other pre-configured mappings as needed, and then click Save followed by Next.
Important:
Do not change the pre-configured mapping for the Seamless Learning Access user ID attribute. The expression maps the user's Managed Apple Account when it exists or the user's email address when it does not, matching the logic used by the Seamless Learning Access blueprint. The value of the Seamless Learning Access user ID in RapidIdentity must match the value used in the blueprint.
- Configure a source filter to limit the imported users to those who can use Seamless Learning Access.
- Click the radio button next to I want to filter data imported from Jamf School.
- Toggle on Enable filter.
- In the Rules selector, click + Rule.
- For the When criteria, select Seamless Learning Access User ID.
- For the Operator, select exists.
- Click Save.
- In the Rules selector, click + Rule to add a second rule to exclude the RapidIdentity tenant administrator account.
- For the When criteria, select Email.
- For the Operator, select not equal.
- For the Value, enter your tenant administrator's email address.
- Click Save.
- Click Proceed to acknowledge any warning message, then click Next.
Important:Seamless Learning Access bypasses multi-factor authentication and is not intended for privileged accounts. Excluding the tenant administrator prevents unauthorized access to RapidIdentity administrative functions.
- Configure the synchronization schedule.
- Toggle on Enable schedule.
- Set the Start time to several hours after the start time configured in Jamf School for synchronizing users from Apple School Manager.
This delay ensures that daily updates from Apple School Manager are reflected in RapidIdentity.
- Set Repeat every (hours) to 0 to avoid unnecessary syncs with Jamf School.
- Click Save.
- Toggle on Enable source if it is not already on.
- Click Finish to complete the integration.
Users from Jamf School synchronize automatically with RapidIdentity on the configured schedule.
To run a manual sync or test that the integration with Jamf School is configured correctly:
- Click the Jamf School source adapter from the home screen in Identity Hub and click Schedule from the top of the page.
- Toggle on Enable source if it is not already on.
- In the Manual run section, toggle off Run in log-only mode.
- Click Run now to start the synchronization job.
To monitor the synchronization job, click Jobs from the top of the page. The Jamf School job displays a status of Running. When the job completes, click the ellipsis next to the Job ID and select View report to view the outcome.