Manually Adding a SAML 2.0 Application for Jamf Pro

Technical Articles

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US
  1. In Okta, click Admin.
  2. Navigate to Applications > Applications.
  3. Click Create App Integration.
  4. Select SAML 2.0 and click Next.
  5. In the General Settings section, enter the application name and click Next.
  6. Configure the General SAML settings to match the following corresponding values in Jamf Pro.
    • Single sign on URL

      Match the following format: https://instancename.jamfcloud.com/saml/SSO

    • Audience URI (SP Entity ID)

      Match the Entity ID field in Jamf Pro using the following format:

      https://instancename.jamfcloud.com/saml/metadata

    • Name ID formatSet the Name ID format pop-up menu to EmailAddress.
    • Application username

      Match the Jamf Pro User Mapping field. If Jamf Pro will map users by username, select Okta username prefix. Use the default setting Okta username to match users by email.

  7. Configure Advanced Settings.
  8. Configure the Group Attribute Statements.
    1. Enter http://schemas.xmlsoap.org/claims/Group in the Name field.
    2. Choose "Matches regex" from the Filter pop-up menu. The Filter setting will send a list of all groups where a particular user is a member; this can be narrowed if needed (typically this is set to .*).
      Note:

      Okta groups assigned to the Jamf Pro application will have the same permissions as the group added in Jamf Pro if the names of both groups match. For User-Initiated Enrollment, no specific permissions are required. Ensure that users configured in Okta have permission to authenticate via the Jamf Pro application. In Jamf Pro, the enrollment can be restricted to the specific group in the Single Sign-On settings by selecting Only this Group in the Enable Single Sign-On for User-Initiated Enrollment configuration.

  9. Click Next and finish configuring the application.
  10. Use the Assignment pane to assign users or groups to the Jamf Pro application.

    Jamf recommends creating a test user and verifying the configuration before assigning it to target users or groups.

  11. (Optional) Depending on your environment, use the General, Sign On, Import, and Assignments panes to configure additional options.
Your SAML application in Okta is now ready to be used with Jamf Pro.

Next, you will need to copy metadata from Okta.