To allow Jamf Trust to use Microsoft Entra ID for single sign-on (SSO), an Microsoft Entra ID administrator must add and allow the Jamf SSO "Entra Enterprise app" to be used within their Microsoft Entra ID tenant.
An organization can link multiple Microsoft Entra ID tenants to a single Jamf tenant. Each of these links is called a "Connection", and is referenced in Activation Profiles when user devices are activating. The admin consent flow must be completed for each Microsoft Entra ID environment to create a valid IdP connection.
Microsoft Entra ID administrator credentials with at least one of the following Microsoft Entra ID roles:
Global Administrator
Application Administrator
Cloud Application Administrator
If you do not have one of the required roles, you must request the necessary admin consent from an administrator who does. Refer to Using Entra Admin Consent Activation Links to complete this Microsoft Entra ID authorization process, instead of completing the steps below.
This connection is now available for selection when Entra Active Directory is selected in the Associated User section within all defined Activation Profiles.