Jamf Platform Authentication allows you to use your organization's existing third-party identity provider (IdP) to authenticate administrators to your Jamf platform products. In order to do this, your IdP sends a token to Jamf Account containing information about user attributes called claims, which are then matched to corresponding account attributes for your Jamf platform users to identify them and log them in.
For most organizations, the default options of email and username attributes are sufficient for user mapping. However, if your organization manages identity for its administrators using other attributes (e.g., user principal name, or "UPN"), you can configure Jamf Account to identify users using a different claim from the IdP token.
This article explains how to configure custom claim mapping in different ways depending on your IdP:
If using Entra ID, you can configure an optional claim to be sent to Jamf Account, which can then be mapped to the username attribute of your Jamf platform users.
Note:For the sake of example, this workflow assumes authentication with Jamf Pro as the end goal.
If using Okta or any other generic OIDC-based SSO provider, you can modify the mapping configuration that Jamf Account uses to map attributes as needed to fit your organization's identity infrastructure.