This registration flow is no longer the preferred registration method and is now considered legacy. In order to continue using this registration flow, the Microsoft Single Sign-on Extension must be deployed to managed computers. For more information, see Create a single sign-on app extension configuration policy from Microsoft.
You can create a policy in Jamf Pro that directs end users to initiate the device registration process by running the Company Portal app. Users must launch the Company Portal app from JamfSelf Service for macOS to register their Mac computers with Microsoft Entra ID as a device managed by Jamf Pro.
Note:
Computers with multiple user accounts can have compliance calculated and reported for each local user account that registered with Microsoft Intune. Each local user will need to complete the registration policy.
For organizations using Platform SSO for Microsoft Entra ID, users will not need to run a policy. Instead, computers are registered when users sign in to Company Portal during the registration process. For more information, see the Deploying macOS Platform SSO for Microsoft Entra ID with Jamf Pro article.
Prior to deploying the policy, Jamf recommends that you notify your end users that they will be prompted to launch the Company Portal app from Jamf Self Service for macOS to begin device registration.
You must exclude the "User registration" app for Device Compliance when creating conditional access policies that require compliant devices. Failing to exclude the "User registration" app for Device Compliance will prevent users from being able to register with Entra ID.
In Jamf Pro, click Computers in the sidebar.
Click Policies in the sidebar.
Click New.
Enter a display name for the policy (e.g., "Require users to register computer with Entra ID").
Use the General payload to specify policy settings.
Best Practice:
For Execution Frequency, Jamf recommends that you select "Once per computer". This prevents the policy from running multiple times on the same computer which can cause duplicate Entra ID records.
Select the Microsoft Device Compliance payload and click Configure.
Select the Register computers with Azure Active Directory checkbox.
Click the Scope tab, and scope the policy to the targeted Mac computers.
Click the Self Service tab and select the Make Policy available in Self Service checkbox.
Important:
The Company Portal app must be launched from JamfSelf Service for macOS to begin device registration. Launching the Company Portal app manually (e.g., from the Applications or Downloads folder) will not register the device. If an end user launches the Company Portal app manually, they will see an AccountNotOnboarded warning message.
Select the Include the policy in the Device Compliance category checkbox.
Click Save .
Jamf Pro prompts users to register their computers with Entra ID by opening the Company Portal app from JamfSelf Service for macOS.