Configuring SAML-Based Single Sign-On with Shibboleth

Technical Articles

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

This article includes step-by-step instructions for configuring single sign-on (SSO) settings in Shibboleth. For end users, you can integrate with Shibboleth to enable SAML-based SSO for Automated Device Enrollment (with an Enrollment Customization SSO authentication pane), Device Enrollment (also known as "user-initiated enrollment"), and Jamf Self Service for macOS.

Note:

While SAML-based SSO for administrators remains supported, Jamf recommends OIDC-based SSO through Jamf Account as a preferred authentication solution. OIDC-based SSO through Jamf Account offers seamless login across Jamf products and access to platform capabilities like blueprints and compliance benchmarks. End-user authentication for enrollment and Self Service can continue using SAML after transitioning administrator authentication to OIDC. For details on implementing OIDC-based SSO, see SSO with OIDC Through Jamf Account in the Jamf Pro Documentation.

This procedure involves the following steps:

  1. Obtaining the metadata XML file from Shibboleth identity provider

  2. Enabling single sign-on in Jamf Pro

  3. Adding a new relying party to Shibboleth identity provider

  4. Configuring Shibboleth identity provider SAML attributes

  5. Testing the Shibboleth identity provider single sign-on configuration

Keep the following in mind when configuring SSO in Shibboleth:

  • The SSO configuration procedure in this article was tested with Shibboleth Identity Provider 3.2.1 and with LDAP connected to the Shibboleth instance.

  • Some setting names were changed in Jamf Pro 10.13.0. If you are using an earlier version of Jamf Pro, the setting names will not match the updated names in this article. For a list of name changes, see the 10.13.0 version of the Jamf Pro Release Notes.

  • Setting up SSO may require simultaneous configuration between Shibboleth and Jamf Pro to ensure some settings are mapped correctly. Additional settings or steps may also be required. See the Single Sign-On section of the Jamf Pro Documentation for Jamf Pro-specific requirements and instructions.