Jamf Pro - Jamf Security Cloud Portal Setup Guide

Jamf Security Cloud Portal Setup Guide

Solution
Application
Jamf Connect
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

The Jamf Pro integration supports the following features:

  • Device lifecycle management

  • Group mapping

  • Groupless device syncing

  • Location syncing

  • Syncing of macOS devices

  • Device field mapping

  • App inventory syncing (for App Insights)

  • UEM Signaling for data usage policies

  • Uploading Apple configuration profiles directly to Jamf Pro groups

Note:

Conditional Access is not supported.

Requirements
  • A Jamf Security Cloud administrator account

  • iOS, iPadOS, or macOS devices that are enrolled with Jamf Pro and have assigned users and email addresses

    To confirm a device is assigned an email address in Jamf Pro, go to Devices > [your device] > User and Location > Email Address.

  • Ability to create network firewall exceptions

  • One of the following API authentication methods:

    • A Jamf Pro API client that is assigned a custom API role.

      For more information about creating an API role and client and generating a client secret, see API Roles and Clients in the Jamf Pro Documentation.

    • A Jamf Pro user account with the Administrator (full) privilege set, or a Custom privilege set

The following table lists the custom Jamf Pro privileges needed for each authentication method:

UEM Connect SettingsOAuth AuthenticationUsername and Password Authentication
Device Lifecycle Management

(Required)

  • Read Mac Applications
  • Read Mobile Devices
  • Read Mobile Device Applications
  • Read Smart Mobile Device Groups
  • Create Static Mobile Device Groups
  • Read Static Mobile Device Groups
  • Read Computers
  • Read Smart Computer Groups
  • Create Static Computer Groups
  • Read Static Computer Groups
  • Mac Apps (Read)
  • Mobile Devices (Read)
  • Mobile Device Apps (Read)
  • Smart Mobile Device Groups (Read)
  • Static Mobile Device Groups (Create, Read)
  • Computers (Read)
  • Smart Computer Groups (Read)
  • Static Computer Groups (Create, Read)
Device Risk UEM Signaling

(Optional)

  • Create Computer Extension Attributes
  • Read Computer Extension Attributes
  • Update Computer Extension Attributes
  • Delete Computer Extension Attributes
  • Create Mobile Device Extension Attributes
  • Read Mobile Device Extension Attributes
  • Update Mobile Device Extension Attributes
  • Delete Mobile Device Extension Attributes
  • Update Mobile Devices
  • Update Computers
  • Update User
  • Computer Extension Attributes (Create, Read, Update, Delete)
  • Device Extension Attributes (Create, Read, Update, Delete)
  • Mobile Devices (Update)
  • Computers (Update)
  • Users (Update)
Configuration Profile Deployment

(Optional)

  • Create iOS Configuration Profiles
  • Read iOS Configuration Profiles
  • Update iOS Configuration Profiles
  • Create macOS Configuration Profiles
  • Read macOS Configuration Profiles
  • Update macOS Configuration Profiles
  • Update Smart Mobile Device Groups
  • Update Static Mobile Device Groups
  • Update Smart Computer Groups
  • Update Static Computer Groups
  • Mobile Device Configuration Profiles (Create, Read, Update, Delete)
  • macOS Configuration Profiles (Create, Read, Update)
  • Smart Mobile Device Groups (Update)
  • Static Mobile Device Groups (Update)
  • Smart Computer Groups (Update)
  • Static Computer Groups (Update)
  1. In Jamf Security Cloud, navigate to Integrations > UEM Connect.
  2. Select Jamf Pro in the UEM vendor pull-down menu.
  3. Enter your Jamf Pro instance URL in the UEM server URL field.
  4. Select an Authentication method:
    • Username and password

      Uses a username and password of a Jamf Pro API user account.

    • OAuth authentication

      Uses the client ID and client secret of a Jamf Pro API client.

  5. Click Save.

UEM Connect is now configured for Jamf Pro. Jamf Security Cloud and Jamf Pro will regularly sync information.

You can now set up the following: