Creating an App Registration Using a New API Permission

Technical Articles

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

  1. Click Microsoft Entra ID in the left sidebar.
  2. Click App registrations, and then click new registration.
  3. Name the app Jamf Connect - OIDC Endpoint.
  4. Select Accounts in this organizational directory only in Supported account types.
  5. Choose "Public client (mobile & desktop)" from the Redirect URI pop-up menu, and then enter https://127.0.0.1/jamfconnect in the Redirect URI field.
  6. Click Register.
  7. Navigate to API permissions in the Manage section of the sidebar.
  8. In Grant Consent settings, click Grant admin consent for your company and then click Yes when prompted.
  9. Click Add a permission.
  10. Select the My APIs tab.
  11. Select the name of the app you created in Step 2.
  12. Click Delegated permissions and select the jamfconnect checkbox.
  13. Click Add permissions.
  14. In Grant Consent settings, click Grant admin consent for your company and then click Yes when prompted.
  15. (Optional) Create an app role for users to become an administrator user on a client Mac computer.

    For more information about creating an app role, see the Configuring Local Account Role Assignment between Jamf Connect and Entra ID article.

  16. (Optional) Create an app role for users to have standard rights on a client Mac computer.
  17. Navigate to Entra ID Active Directory > Enterprise Application.
  18. Select the Jamf Connect - OIDC Endpoint application.
  19. Select users or groups to add to the Jamf Connect - OIDC Endpoint application, and then select a role for each new user or group.
    Note:

    Users or Groups must be assigned to the application for the Roles attribute to work.