Google - Jamf Security Cloud Portal Setup Guide

Jamf Security Cloud Portal Setup Guide

Solution
Application
Jamf Connect
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

Users can activate the Jamf Trust app using their Google user credentials with Google Workspace native identity provider integration. Administrators can link more than one Google Workspace to a single Jamf tenant.

Requirements
You can use Google Workspace for single sign-on with Jamf Trust in the following environments:
  • iOS, Jamf Trust 11.12.0 or later

  • macOS, Jamf Trust 2.10 or later

  • Android, Jamf Trust 11.24.0 or later

  • Windows, Jamf Trust 8.2.0 or later

A Google Workspace administrator must have permission to read groups in order to authorize Jamf Trust. If using pre-built administrator roles, Super Admins and Groups Admins both have the necessary permission. However, if Google Workspace administrators have restricted access, Jamf Trust must be added as a trusted app in the App Access Control window.

For more information about Google Workspace administrator roles, see https://support.google.com/a/answer/2405986?hl=en.

  1. Sign in to Jamf Security Cloud and navigate to Integrations > Identity Providers.
  2. Navigate to the Google identity services section and click Add Connection to create a new IdP connection.
  3. Enter a name for the new connection.
  4. Click Sign in with Google.

    The connection is added and you are redirected to the Google sign in screen.

  5. Sign in using a Google Workspace administrator account that has permission to read groups.
  6. Review and approve the required permissions.
  7. Click Continue to complete the authorization process and return to Jamf Security Cloud.

    If the process is successful, the new connection appears in the list of Linked organizations with a green checkmark in the Status column and the Google tenant ID that has been authorized for this account.

  8. Repeat these steps for any other Google Workspace you want to use for authentication in this Jamf account.

This connection is now available when Google is selected in the Authentication section within all defined Activation Profiles.