Microsoft Entra ID

Jamf Security Cloud Portal Setup Guide

Solution
Application
Jamf Connect
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

To allow Jamf Trust to use Microsoft Entra ID for single sign-on (SSO), an Microsoft Entra ID administrator must add and allow the Jamf SSO "Entra Enterprise app" to be used within their Microsoft Entra ID tenant.

An organization can link multiple Microsoft Entra ID tenants to a single Jamf tenant. Each of these links is called a "Connection", and is referenced in Activation Profiles when user devices are activating. The admin consent flow must be completed for each Microsoft Entra ID environment to create a valid IdP connection.

Requirements

Microsoft Entra ID administrator credentials with at least one of the following Microsoft Entra ID roles:

  • Global Administrator

  • Application Administrator

  • Cloud Application Administrator

Note:

If you do not have one of the required roles, you must request the necessary admin consent from an administrator who does. Refer to Using Entra Admin Consent Activation Links to complete this Microsoft Entra ID authorization process, instead of completing the steps below.

  1. Sign in to Jamf Security Cloud and navigate to Integrations > Identity Providers.
  2. Click Add Connection to create a new IdP connection.
  3. Enter a name for the connection.
  4. Click Perform Consent Grant.

    The connection is added and you are redirected to the Microsoft Entra sign in screen.

  5. Sign in using an Entra Administrator Account that has been assigned to at least one of the roles mentioned previously.
  6. Review the required permissions when prompted.
  7. Click Accept to complete the authorization process and return to Jamf Security Cloud.

    If the process is successful, the connection details are updated with a green checkmark and the Entra tenant ID that has been authorized within this account.

  8. Repeat these steps for any other Microsoft Entra ID tenants you want to use for authentication in this Jamf account.

This connection is now available for selection when Entra Active Directory is selected in the Associated User section within all defined Activation Profiles.