Configuring the Connection between Jamf Pro and Microsoft Intune

Technical Paper: Device Compliance with Microsoft Entra and Jamf Pro

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US
  1. Remove target users from the Partner Device Management scope in Microsoft Intune.
    Note:

    Users cannot be scoped for both Partner Device Management and Partner Compliance Management when registering or re-registering new computers with device compliance.

    1. Log in to Microsoft Intune.
    2. Navigate to Tenant administration > Connectors and tokens > Partner device management.
    3. Under Included groups, remove all groups that include users you want to migrate to device compliance.
    4. Click Save.
  2. Disable the Conditional Access integration in Jamf Pro by doing the following:
    1. Navigate to Settings > Global > Conditional access.
    2. Click Edit .
    3. Deselect the Enable Intune Integration for macOS checkbox.
    4. Click Save .
  3. Enable the device compliance integration. For more information, see Configuring the Microsoft Entra Integration.
  4. (Optional) Create a smart computer group to view computers that have not been migrated to device compliance.
    Best Practice:
    Use the following criteria to create the smart computer group:
    CriteriaOperatorValue

    Conditional Access Inventory State

    is

    Activated or Unresponsive

    Device Compliance Integration - Registration Status

    is

    Not Registered

  5. (Optional) Create a smart computer group to view computers that have been migrated to device compliance.
    Best Practice:
    Use the following criteria to create the smart computer group:
    CriteriaOperatorValue

    Device Compliance Integration - Registration Status

    is

    Registered

Your devices will be migrated to the device compliance integration after JamfAAD information has been collected and sent to Jamf Pro. This data collection occurs when users run the migration script policy from Self Service.