Computer Registration User Experience

Technical Paper: Device Compliance with Microsoft Entra and Jamf Pro

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US
Important:

This registration flow is no longer the preferred registration method and is now considered legacy. As of early 2026, the Microsoft Single Sign-on extension is required for this registration flow. When using the Microsoft Single Sign-on extension, the Jamf Conditional Access prompts in this document may not appear. Jamf Conditional Access.app attempts to silently use the Single Sign-on extension to complete the authentication request, and will only fall back to the interactive prompts depicted here if the authentication request cannot be completed silently.

Users must register their computers with Microsoft Entra ID (formerly Azure AD) for the computer's compliance status to be sent to Entra ID. The following section describes the user registration experience in environments that do not use Platform SSO for Microsoft Entra ID.
Note:

You must deploy the Company Portal App before users can register computers with Entra ID. For more information, see Deploying the Company Portal App from Microsoft to End Users.

Due to Authentication Services framework limitations, the workflow can only run in one of the following web browsers:
  • Safari

  • Microsoft Edge 92 or later

  • Google Chrome 92 or later

  1. From Self Service for macOS, the user runs the registration policy.
    Note:

    For instructions on creating the registration policy, see Creating a Policy Directing Users to Register Mac Computers with Microsoft Entra ID.

    Image showing Self Service JamfAAD install option

    The policy opens the Company Portal app.

  2. The user enters their Microsoft credentials in the Company Portal app.

  3. Workplace Join opens and creates the computer record in Microsoft Azure. If the computer is managed by Jamf Pro and compliant, a message displays stating that registration was successful.
    Note:

    Inventory information for the computer does not display in Microsoft Intune at this point.

    Image showing completed user registration
  4. JamfAAD opens.

    Image showing JamfAAD helper
    Depending on your environment, the user is asked to do one of the following:
    • If your Entra ID environment is federated with another authentication domain, such as an on-premise environment, the user is prompted to enter their authentication credentials for a second time and accept a multifactor authentication prompt if configured.

    • If your Entra ID environment is exclusively cloud-based, the user is prompted to enter their passwords again and accept a multifactor authentication prompt if configured.

  5. The user is prompted to unlock the login keychain in Keychain Access to grant permissions. End users must select Always Allow in the Keychain Access prompt.

    If your environment only uses Entra ID accounts, the user is prompted to enter their passwords again and accept a multifactor authentication prompt if configured.

    Image showing JamfAAD login password field

    Jamf Pro sends device compliance and other device information to Entra ID. Device information can be found in Entra ID after a successful registration under All Devices, or under a user's Devices list.