If your organization is leveraging Platform Single Sign-on (Platform SSO), you can use it to significantly streamline the device compliance registration process for end users. When configured properly, computers will be automatically registered for device compliance when an end user registers with Entra ID Platform SSO.
Important: Device compliance registration during Setup Assistant requires Jamf Pro 11.26.0 or later and a version of Microsoft Company Portal that supports Simplified Setup during enrollment. Verify support status with your identity provider to ensure full feature availability.
A device compliance integration configured in Jamf Pro
Target computers must be members of the Applicable group within the Device Compliance configuration in Jamf Pro
The company portal app deployed to target computers
After ensuring that target computers have the company portal and are are members of the Applicable group within the Device Compliance configuration in Jamf Pro, follow the instructions for deploying a Platform Single Sign-on configuration profile in the Deploying macOS Platform SSO for Microsoft Entra ID with Jamf Pro article. Instruct users to complete Platform SSO registration by signing in to the Platform SSO notification center prompt when they log into their computer.
When device compliance is configured in Jamf Pro, an agent is created on computers that monitors user sign-ins to Platform SSO. Then, when a user completes Platform SSO registration by signing in to the notification center prompt, a shell record is created in Entra ID. At the same time, the Jamf Conditional Access.app on target computers automatically attempts to authenticate to the User Registration App for Device Compliance. If authentication succeeds, a confirmation is sent to the Jamf Pro server. Jamf Pro then sends compliance information to the shell record in Entra ID, marking the computer as compliant or non-compliant based on its smart group membership.