Jamf Pro Authentication with OIDC-based Single Sign-On through Jamf Account

Technical Articles

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

When users attempt to sign in to a Jamf Pro instance configured for OIDC-based single sign-on through Jamf Account, they are redirected to their organization's identity provider by the Jamf identity broker service.

After the user is authenticated, the IdP returns a secure token that includes tenant context information. These tokens allow Jamf Pro to match users to the appropriate permissions and give them access to other Jamf services, making the login experience consistent across the platform.

The following diagram details this process in full: