Jamf Pro SAML Authentication Flow

Technical Articles

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

Many organizations rely on SAML authentication as a trusted method for securing Jamf Pro access. When a user attempts to access Jamf Pro, they are redirected to the organization's identity provider. There, they authenticate using their SSO credentials. After authentication, the identity provider (IdP) returns a SAML assertion to Jamf Pro containing the user's identity information. Jamf Pro then validates this assertion and maps the user either directly or via group membership. The appropriate permissions are granted, the user is logged in, and the session begins. If anything goes wrong during this process, the failover URL can be used to gain access to Jamf Pro for remediation.

The following diagrams detail this process in full: