Configuring Custom Claim Mapping for SSO with Entra ID and Jamf Account

Technical Articles

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US
If you are using Entra ID as a identity provider, you can configure it to send an optional claim to Jamf Account, which can then be mapped to a username attribute for your Jamf platform users.
Note:

For the sake of example, this workflow assumes authentication with Jamf Pro as the end goal.

Requirements
  • Entra ID integrated with Jamf Account

  • Administrator access to your organization's Entra ID tenant

  • Advanced features enabled in Jamf Account (Organization > Settings > Advanced Features)

  1. Log in to your organization's Microsoft Entra admin center.
  2. In the sidebar, click App registrations.
  3. Click the app you have configured for Jamf Account.
  4. Under Manage, click Token configuration.
  5. Click Add optional claim.
  6. Under Token type, select ID.
  7. Select the optional claim (e.g., upn) from the list that you will use to map users.
  8. Click Add.

    Entra ID now includes the selected claim in the token that it sends to Jamf Account.

  9. In a new browser tab, log in to Jamf Account.
  10. In the sidebar, click SSO.
  11. Locate your Entra ID integration and click Edit.
  12. In the Custom username claim name field, enter the name of the claim you added earlier in Entra ID (e.g., upn).
  13. Click Save.
  14. In Jamf Pro, navigate to Settings > System > Single sign-on.
  15. In the OIDC IdP integration settings section, under Identity Provider User Mapping select the Username radio button.
  16. Under Jamf Pro User Mapping, select the Username radio button.
  17. Click Save.

The optional claim configured in Entra ID is now mapped to the username field of Jamf Pro user accounts, allowing them to use their Entra ID credentials to log in to Jamf Pro.