- Click Microsoft Entra ID in the left sidebar.
- Click App registrations, and then click new registration.
- Name the app Jamf Connect - OIDC Endpoint.
- Select Accounts in this organizational directory only in Supported account types.
- Choose "Public client (mobile & desktop)" from the Redirect URI pop-up menu, and then enter https://127.0.0.1/jamfconnect in the Redirect URI field.
- Click Register.
- Navigate to API permissions in the Manage section of the sidebar.
- In Grant Consent settings, click Grant admin consent for your company and then click Yes when prompted.
- Click Add a permission.
- Select the My APIs tab.
- Select the name of the app you created in Step 2.
- Click Delegated permissions and select the jamfconnect checkbox.
- Click Add permissions.
- In Grant Consent settings, click Grant admin consent for your company and then click Yes when prompted.
- (Optional) Create an app role for users to become an administrator user on a client Mac computer.
For more information about creating an app role, see the Configuring Local Account Role Assignment between Jamf Connect and Entra ID article.
- (Optional) Create an app role for users to have standard rights on a client Mac computer.
- Navigate to Entra ID Active Directory > Enterprise Application.
- Select the Jamf Connect - OIDC Endpoint application.
- Select users or groups to add to the Jamf Connect - OIDC Endpoint application, and then select a role for each new user or group.Note:
Users or Groups must be assigned to the application for the Roles attribute to work.