Single Sign-On Options for Jamf Pro FAQ

Technical Articles

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

The single sign-on (SSO) integration with Jamf Account allows administrators to use a centralized SSO configuration for all supported Jamf products. This integration also enables multi-factor authentication for an additional layer of security.

The SSO integration with Jamf Account is powered by a protocol called OIDC (OpenID Connect). OIDC-based SSO in Jamf Account is available to administrators starting with Jamf Pro 11.13.0.

This article covers questions related to using OIDC-based SSO in Jamf Account for administrators. For an overview of the SSO options available for administrators and end users, see Single Sign-On (SSO) in the Jamf Pro Documentation.

What are the technical benefits to using OIDC-based SSO in Jamf Account?
Using OIDC-based SSO in Jamf Account allows Jamf to build smaller applications and insert them into Jamf Pro with a seamless user interface, reducing the number of times you need to log in to different Jamf applications. Because SSO through Jamf Account uses a shared authentication method, new applications will be able to interact with Jamf Pro without additional setup. This is not possible with the current limitations of SAML-based SSO through Jamf Pro. Additionally, new features that rely on SSO through Jamf Account can receive updates outside of the Jamf Pro release cycle.
I already have SSO configured in Jamf Pro. Why would I want to use an SSO integration through Jamf Account?
OIDC-based SSO in Jamf Account is required for administrators to access certain features in Jamf Pro and other Jamf applications. Using this integration enables you to access multiple Jamf products with one set of login credentials.
I already have SSO configured in Jamf Pro, but I want to use the SSO integration with Jamf Account. What should I do?
If you haven't already, you will need to configure OIDC-based SSO in Jamf Account or create a Jamf ID. After the SSO integration is configured in Jamf Account, go to the single sign-on settings in Jamf Pro and enable OIDC authentication. If you want to continue using SAML-based SSO for end users, you can select that option in Jamf Pro.
Why do I need to have a different SSO configuration for administrators through Jamf Account and end users through Jamf Pro?

Jamf Account only supports SSO integrations using OIDC. The integration with Jamf Account is required to use certain Jamf platform capabilities and services, so Jamf recommends that administrators with cloud-hosted environments set up an OIDC application through Jamf Account to ensure access to these features. Without the integration with Jamf Account, Jamf Pro only supports authentication through SAML 2.0.

If your Jamf Pro environment is on-premise, or you use Jamf Premium Cloud Plus, you can continue using SAML-based SSO through Jamf Pro.

It is possible to enable both OIDC and SAML configurations at the same time. For example, if you want to use OIDC-based SSO through Jamf Account for administrators and continue using SAML-based SSO for end users, you can select that option in Jamf Pro. For information on SSO functionality for end users, see SSO with SAML in the Jamf Pro Documentation.

I already have Users and Groups set up in Jamf Pro that I use with my current IdP. Do I need to redo this setup to use OIDC-based SSO in Jamf Account?
If the new IdP returns the same email address or group names as the old one, no action is required. If the email addresses or group names do not match, you will need to add the necessary group names or email addresses.
I already have OIDC-based SSO enabled in Jamf Account for other Jamf products. What should I do if I want to use the SSO integration with Jamf Account for Jamf Pro?
In Jamf Account, navigate to Organization > SSO and select an identity provider connection from the list. After selecting an IdP connection, scroll down to Applications and select the Jamf Pro instances that you want to make the integration available to. Make sure your users' email addresses match what is configured in Jamf Pro.
My organization does not have an IdP, but I still want to use the SSO integration with Jamf Account. What can I do?
You can use your Jamf ID. To enable Jamf ID as a login option:
  1. If you don't already have one, create a Jamf ID:

    1. Go to account.jamf.com.

    2. Click Create one now and follow the onscreen instructions to set up your Jamf ID.

  2. Add a user in Jamf Pro with a username and email address that matches the Jamf ID.

  3. Enable OIDC authentication for SSO in Jamf Pro.

What if I can't use my organization's IdP to access Jamf Pro but I still want to use OIDC-based SSO in Jamf Account. Alternatively, what if I don't want to configure SSO with an IdP on my test instance?
You can use your Jamf ID.
How does SSO through Jamf Account affect Jamf IDs that already exist in Jamf Account?
There is no change to how Jamf ID works. However, Jamf ID can be used to log in to Jamf Pro starting with version 11.13.0.
Can I only have one SSO connection in Jamf Account? What if I have multiple Jamf Pro instances?
You can configure multiple SSO instances in Jamf Account. You can use one SSO connection to access multiple Jamf Pro instances, or you can use different SSO connections to access different Jamf Pro instances. You cannot currently use multiple SSO connections to access the same Jamf Pro instance.
How can I use the SSO integration with Jamf Account if I already have Jamf Connect configured in my IdP?
You should configure separate OIDC apps for servers and services in your IdP. Even if you already have an OIDC app configured for end users via Jamf Connect, you will still need to configure a separate OIDC app for the administrator SSO integration in Jamf Account.