Further Considerations

Technical Articles

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

The previous examples show how authentication works in different login and logout scenarios, and why Jamf recommends using OIDC-based SSO through Jamf Account. Whether users log in through your organization's identity provider or with a Jamf ID, access is handled consistently, and support for additional platform features is enabled. As you plan your implementation, consider the following:

  • Configure failover access methods as a safeguard when modifying your configuration.

  • Ensure user accounts are aligned between your identity provider and Jamf Pro to avoid mapping issues.

  • Consider how different authentication paths affect feature availability. OIDC-based SSO through Jamf Account is required for some platform services.

  • If you plan to use OIDC-based SSO through Jamf Account:

    • IdP settings must be configured in Jamf Account before they can be used by Jamf Pro or other services.

    • The DNS TXT record must be maintained to ensure continued functionality, but you can account for a 14-day grace period if you need to change your DNS records in the future.