A Jamf Connect configuration setup with the minimum authentication settings enabled will grant access to several default features. Password syncing can be managed with more granularity via additional settings within Jamf Connect.
Within the Jamf Connect Configuration app or Jamf Pro, the settings and their corresponding keys can enable or disable specific functions to suit your organization's needs. The following settings allow you to:
Enable local passwords for users, creating an additional layer of security for all accounts
Provide specific password changing and resetting URLs for users
Specify accounts that do not have to sync their local credentials with Jamf Connect
An existing Jamf Connect configuration with your identity provider configured
Access to the Jamf Connect Configuration app
Access to Jamf Pro
The URL where users can change or reset their password can be configured with the Change Password URL (ChangePasswordURL) and Reset Password URL (ResetPasswordURL) preferences. For more information about default and recommended password change and reset URLs, see Menu Bar Authentication Settings.
You can also disable password syncing for specific local accounts using the Password Sync Block List (PasswordSyncBlockList) setting. It allows you to specify a list of local macOS accounts that you do not want to go through password syncing (typically admin accounts). For more information, see Password Policy Settings.
Jamf Connect will now sync passwords for your organization's needs.
For information on how to deploy Jamf Connect to already managed computers using Jamf Pro, see Automatically Deploy and Update Jamf Connect Using Jamf Pro.