SAML-Based SSO Integrations

Technical Articles

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

The articles in this section provide guidance for integrating with a third-party identity provider (IdP) to enable SAML-based single sign-on (SSO) for portions of Jamf Pro. When SSO is configured, users are automatically redirected to your organization's IdP login page to authenticate before they can access resources.

For end users, you can integrate with an IdP to enable SAML-based SSO for Automated Device Enrollment (with an Enrollment Customization SSO authentication pane), Device Enrollment (also known as "user-initiated enrollment"), and Jamf Self Service for macOS.

SAML-based SSO can also be used to require administrators to authenticate when accessing the Jamf Pro server; however, for administrators with supported environments, Jamf recommends using OIDC-based SSO through Jamf Account as a preferred authentication solution.

Note:

For administrators, OIDC-based SSO integration through Jamf Account is required for full compatibility with Jamf platform capabilities and services. You can enable OIDC-based SSO in Jamf Account for administrators alongside SAML-based SSO in Jamf Pro for end users. For more information, see SSO with OIDC Through Jamf Account in the Jamf Pro Documentation.