Organization Unit Hierarchy, Inheritance, and Overrides - Jamf Security Cloud Portal Setup Guide

Jamf Security Cloud Portal Setup Guide

Solution
Application
Jamf Connect
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

One organization unit (OU) at root level is equivalent to one portal in Jamf Security Cloud, which represents one enterprise (for example, Jamf). If you have more than one OU, you can create a root level policy that is inherited across all leaf OUs (for example, Jamf UK, Jamf AUS), and all groups within those OUs. Further changes at lower levels can be made to override your root level policies.

A diagram that visualizes OUs with various policies and overrides.
To view your organization hierarchy, navigate to Settings > Organization Units in Jamf Security Cloud. The following table describes the hierarchy levels:
OU LevelDescription

Root OU

  • This single OU represents the organization itself at the highest level of your organization's hierarchy.

  • The root OU does not have a parent OU.

Leaf OU

  • The leaf OU cannot contain any other OUs.

  • This is the only OU to which devices can be enrolled.

  • Within a leaf OU you can create groups, which allow for more granular policies.

Group

A group level sits under the leaf OU.

Parent OU

A parent OU is an OU one level higher than another level in the structure.

Child OU

A child OU is an OU one level lower than another level in the structure.

Rule configurations are inherited from the root OU level by default. The changes you can make at the leaf OU level that override the root OU level rule configurations are below:
  • Override a root OU level rule configuration by clicking Override at the leaf OU level.

  • To revert an overridden rule configuration back to the root level policy, change the setting back to Inherit.

Select an OU under Settings > Audit Logs in Jamf Security Cloud to view changes made at either the leaf OU level that you're currently logged into or at the root OU level.