18 August 2023
This article is no longer being updated because Microsoft has deprecated the Azure Active Directory Authentication Library. For more information, see the following documentation from Microsoft:
For instructions on configuring single sign-on with Microsoft Entra ID (formerly Azure AD) see Tutorial: Microsoft Entra SSO integration with Jamf Pro from Microsoft.
This article includes step-by-step instructions for configuring single sign-on (SSO) settings with Active Directory Federation Services (AD FS), which will allow you to enable SSO for portions of Jamf Pro.
This procedure involves the following steps:
Adding Relying Party Trust in AD FS
(Optional) Adding Jamf Pro built-in root certificate to trusted certificates
(Optional) Setting the SSO lifetime value
Keep the following in mind when configuring SSO with AD FS:
Some setting names were changed in Jamf Pro 10.13.0. If you are using an earlier version of Jamf Pro, the setting names will not match the updated names in this article. For a list of name changes, see the 10.13.0 version of the Jamf Pro Release Notes.
The SSO configuration procedure provided in this article was tested with AD FS 3.0. AD FS 3.0 was deployed on Windows Server 2012 R2.
Setting up SSO may require simultaneous configuration between AD FS and Jamf Pro to ensure some settings are mapped correctly. Additional settings or steps may also be required. See the Single Sign-On section of the Jamf Pro Documentation for Jamf Pro-specific requirements and instructions.