The previous examples show how authentication works in different login and logout scenarios, and why Jamf recommends using OIDC-based SSO through Jamf Account. Whether users log in through your organization's identity provider or with a Jamf ID, access is handled consistently, and support for additional platform features is enabled. As you plan your implementation, consider the following:
Configure failover access methods as a safeguard when modifying your configuration.
Ensure user accounts are aligned between your identity provider and Jamf Pro to avoid mapping issues.
Consider how different authentication paths affect feature availability. OIDC-based SSO through Jamf Account is required for some platform services.
If you plan to use OIDC-based SSO through Jamf Account:
IdP settings must be configured in Jamf Account before they can be used by Jamf Pro or other services.
The DNS TXT record must be maintained to ensure continued functionality, but you can account for a 14-day grace period if you need to change your DNS records in the future.