Planning Your Transition

Technical Articles

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

Unlike other system changes, OIDC-based SSO configuration cannot be implemented gradually—it requires a complete cutover from your existing SAML-based SSO configuration (end user authentication for enrollment and Self Service can continue to use SAML). Create a detailed transition plan that includes a specific maintenance window, user communication strategy, and verification procedures. Before transitioning to OIDC-based SSO through Jamf Account in your production environment, Jamf recommends planning and testing your configuration in a non-production environment. However, if you don't have access to a test environment, you can proceed with the transition using the steps outlined in this guide.

Important:

Before making any changes to SSO settings, make sure to copy and securely store your failover URL. This URL will allow you to log in using your Jamf Pro credentials if something goes wrong with the SSO configuration. You can find this URL in Jamf Pro in Settings > System > Single sign-on.