You can use administrator roles and accounts to allow staff at a school to access Jamf School. Administrator accounts are used to create usernames and passwords for administrators to sign in to Jamf School. You define the access rights and privileges that administrator accounts have by assigning the accounts to one or more administrator roles. Any administrator account assigned to a role is granted all of the access rights for that role. If you update access rights and privileges for a role, those changes are updated for any administrator accounts assigned to that role.
Only administrator accounts can be assigned to an administrator role.
Administrator accounts can also configure account settings, including their profile name and the two-factor authentication (2FA) method used to sign in to Jamf School. Jamf School supports 2FA apps, SMS, and backup codes as 2FA methods.
- App —Generates a time-based method to authenticate the user and is typically the most secure option. For example, the app could use a temporary password, a one-time code, or a fingerprint scan.
- SMS —Sends a one-time code via text message for the user to input when they sign into their account.
- Backup codes —Creates a set of codes that must be stored in a secure location to be used when 2FA cannot be completed via app or SMS. Each code expires upon use. If a user generates another set of codes, all previous codes become invalid even if they have not been used. Backup codes are the least secure option and should only be used when other methods are unavailable.
Account settings, including 2FA, are not available when logging in with a Jamf ID. Use Jamf Account to configure account settings for your Jamf ID.