Configuring the Microsoft Entra Integration with Jamf Pro

Technical Paper: Device Compliance with Microsoft Entra and Jamf Pro

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

You must configure a connection between Jamf Pro and Microsoft Entra to allow Jamf Pro to send the compliance status to Microsoft Entra ID (formerly Azure AD) for each computer and mobile device registered with Entra ID. If you have multiple Jamf Pro instances, you can connect them to a single Entra tenant.

Note:

This integration is not available for personally owned computers.

Important:

For iOS or iPadOS compliance and shared devices workflows, do not enable the iOS platform under Microsoft Intune device compliance while already using the Context-Aware Access with Google integration for iOS devices (or vice versa), as this will cause compliance data flow issues.

Requirements

If you already have one platform enabled (e.g., macOS) and would like to add another one (e.g., iOS), ensure the platform type is enabled in Entra before you enable it in Jamf Pro.

  1. In Jamf Pro, use smart groups to create an Applicable Group and Compliance Group for each platform (macOS, iOS/iPadOS, and shared devices) that you want to manage with device compliance.

    For more information on creating smart groups, see Smart Groups in the Jamf Pro Documentation.

    macOS
    • (Applicable Group) This group should contain all of the computers that need access to company resources, regardless of whether they are compliant or not.

    • (Compliance Group) This group should contain the computers that must meet specific criteria to be considered compliant. For example, the criteria could be meeting macOS version requirements, or the presence of a certain application.
      Best Practice:
      When creating the Compliance Group, add the criteria you want compliant computers to have. For example, you may want to include the following criteria:
      • Operating System Version

      • Last Inventory Update

      • FileVault Status

      Jamf recommends selecting Send email notification on membership change when creating the Compliance Group to be notified when a computer falls out of compliance.
      Smart Computer Group example
    iOS/iPadOS
    • (Applicable Group) This group should contain all of the mobile devices that need access to company resources, regardless of whether they are compliant or not. Once configured in device compliance, the Register with Microsoft button is made available in Jamf Self Service for iOS.

    • (Compliance Group) This group should contain the mobile devices that must meet specific criteria to be considered compliant. For example, the criteria could be meeting iOS version requirements, or the presence of a certain application.
      Best Practice:
      When creating the smart device group, add the criteria that devices must have to be considered compliant. For example, you may want to include the following criteria:
      • OS Version

      • Jailbreak Detected

      • Last Backup

      • Passcode Status

      Jamf recommends selecting Send email notification on membership change when creating the smart device group to be notified when a device falls out of compliance.

      Smart Mobile Device Group example
    Shared devices
    • (Applicable Group) This group should contain all of the mobile devices that need access to company resources, regardless of whether they are compliant or not.

    • (Compliance Group) This group should contain the mobile devices that must meet specific criteria to be considered compliant. For example, the criteria could be meeting iOS version requirements, or the presence of a certain application.

      Important:

      Device compliance for shared devices can be enabled at the same time as device compliance for iOS and iPadOS, but the applicable group for shared devices should not include devices that are included in the applicable group for iOS and iPadOS.

      If an end user device is registered with the incorrect applicable group, the only way to re-register the device is to erase the device, add the device to the correct applicable group, then and register the device with Microsoft Entra again. For more information on erasing a device, see Removing a Mobile Device Registered with Microsoft Entra ID and Managed by Jamf Pro.

    • (Custom configuration for single sign-on extension) Device compliance for shared devices uses a predefined single sign-on extension (SSOe) payload which contains the following key-value pairs:
      • AppPrefixAllowList set to com.microsoft., com.apple., com.jamfsoftware.

      • Enable_SSO_On_All_ManagedApps set to 1 (true)

      The Custom configuration for single sign-on extension option allows you to upload a PLIST file to define specific SSOe key-value pairs, enabling additional configuration options for SSOe profiles. Consider the following when uploading a custom PLIST file:

      • If a device already has a Single Sign-on Extension payload, the device must be erased to use the new, custom SSOe payload.

      • If the custom PLIST file contains values that conflict with the values in the default SSOe payload, Jamf Pro prioritizes the values in the custom PLIST file.

      • For more information about configurable keys, see Summary of keys from Microsoft.

  2. In Jamf Pro, click Settings in the sidebar.
  3. In the Global section, click Device compliance .
  4. Click Edit .
  5. Use the switch to enable the integration.
  6. Choose your platform type.
  7. Choose the Compliance Group you want Jamf Pro to use to calculate device compliance.
  8. Choose the Sovereign Cloud location that best reflects your environment.
  9. Choose the Applicable Group you want Jamf to use to send compliance status to Microsoft Entra.
  10. Select one of the following landing page options for devices that are not recognized by Microsoft Entra ID:
    • The default Jamf Pro Device Registration page

    • The Access Denied page

    • A custom webpage

  11. Click Save .
The Microsoft Entra integration is configured in Jamf Pro and you are redirected to the Microsoft Entra webpage to create a compliance partner.