After the device compliance integration is configured in Jamf Pro, you must then finish the Microsoft Intune configuration in Microsoft Intune.
Requirements
To accept permissions requested by Microsoft, you must have an Microsoft Entra ID account with global or domain administrator rights.
- On the Microsoft application registration page, enter your Entra ID credentials and follow the onscreen instructions to grant the permissions requested by Microsoft.
After permissions have been granted for the Cloud Connector for device compliance app and the User registration app for device compliance, you are redirected to the Configure Compliance Partner page.
- Click Open Microsoft Endpoint Manager.
A new tab opens to the Partner compliance management blade in Microsoft Intune.
- Click Add compliance partner.
- Choose from the Compliance partner pop-up menu.
- Choose the desired platform type from the Platform pop-up menu and click Next.
If you want to use device compliance for shared devices, select iOS.
- Click Add Groups and choose the Entra ID user groups you want to use from the Select groups to include pop-up menu.
If you want to use device compliance for shared devices, you are not required to assign a group for policy scoping.
Important:Do not select from the Assignments pane. Selecting this option will prevent the integration from working.
Note:When the integration between Jamf Pro and Microsoft Intune is established, Jamf Pro uses the Intune API to determine which groups are scoped in the "Partner Compliance Management" blade of Intune. Subsequent changes to group membership in Intune do not require any action in Jamf Pro, but if additional groups are added to the "Partner Compliance Management" blade after integrating, compliance data for those users and groups will not be reflected in Entra ID until the scope of groups is resynced. To resync the scope of groups in the "Partner Compliance Management" blade of Intune, click .
- Click Select and then click Next.
- Review your configuration and then click Create.
- Navigate back to the Jamf Cloud Connector tab and click Confirm.
You are redirected back to Jamf Pro. Jamf Pro completes and tests the configuration. The success or failure of the connection displays on the Device Compliance settings page.
- To connect additional Jamf Pro instances to the same Entra ID tenant, configure the device compliance settings for each instance and grant the requested permissions for the Cloud Connector for Device Compliance and the User registration app for device compliance. You do not need to add Jamf as a compliance partner again.
Once the connection is successfully enabled, Jamf Pro sends the compliance status to Entra ID through the Microsoft Intune Compliance Management connection for each computer or mobile device that is registered with Entra ID (registering with Entra ID is an end user workflow). You can view the compliance status of the device in Entra ID. Devices will not appear in Microsoft Intune under the Devices list.
Note:If Entra shows "N/A" for device compliance after what appears to be a successful device registration, it indicates a failure on the client device, where Entra did not receive the expected device compliance information. To fix this issue, remove the computer record from Entra ID and then re-register the computer.