Password syncing with Jamf Connect does not require the use of the Jamf Connect login window. This workflow enables the default password syncing feature and informs how to configure additional settings within the feature.
Implementing password syncing with Jamf Connect keeps user credentials secure across both local and network environments. By continuously verifying and syncing passwords, Jamf Connect enhances security, reduces the risk of unauthorized access, and simplifies password management for both users and IT administrators.
Additionally, Jamf Connect facilitates password management directly through your cloud identity provider (IdP).
When Jamf Connect is configured with your cloud IdP's minimum authentication settings, Jamf Connect will do the following by default:
- Continuous Password Verification —
The user's network and local passwords are checked every 60 minutes to verify that they are in sync.
- Sync Passwords —
Prompt a user to change their local password if it does not match the network password.
If a user's password syncing fails because their new password doesn't meet the requirements enforced by macOS (via MDM passcode configuration, etc.), the user sees a list of the requirements their password must meet.
- Manage Network Password Changes —
Facilitate a network password change when a password expires. Self Service+ completes this change by opening a web view to your cloud IdP's password change URL. If Kerberos is used, the password change is completed directly in the Self Service+ UI.
- Password Expiration Warnings —Self Service+ can display the number of days before a password expires in the UI. It can also notify the end user with a notification when a password is out of sync if notifications are allowed.