Jamf Pro Device Compliance Requirements

Technical Paper: Device Compliance with Microsoft Entra and Jamf Pro

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

Administrator Requirements

To configure the Microsoft Entra integration with Jamf Pro, you need the following:
  • Jamf Cloud-hosted environment or an on-premise environment
    Jamf Cloud-hosted environments must have the following:
    • Cloud Services connection enabled in Jamf Pro. To enable the Cloud Services connection, follow the steps outlined in Enabling the Cloud Services Connection in the Jamf Pro Documentation.
      Note:

      The Cloud Services connection is enabled by default in most Jamf Cloud-hosted environments.

    • Jamf Pro 10.29.0 or later (iOS and iPadOS) or Jamf Pro 10.43.0 or later (macOS)

    On-premise environments must have the following:

    • Jamf Pro 11.6.0 or later for non-government environments
    • Jamf Pro 11.7.1 or later for government environments

    • Cloud Services connection enabled in Jamf Pro. To enable the Cloud Services connection, follow the steps outlined in Enabling the Cloud Services Connection in the Jamf Pro Documentation

    • Your network must be configured to allow port TCP 443 traffic between the server and the appropriate cloud connector network address:
      • Non-government environments: registration.cloudconnector.services.jamfcloud.com
      • Government environments: registration.cloudconnector.gov.services.jamfcloud.com

  • A Jamf Pro user account with device compliance privileges

  • Experience with creating smart groups in Jamf Pro. For more information, see Smart Groups in the Jamf Pro Documentation.

  • Microsoft Enterprise Mobility + Security (specifically Microsoft AAD Premium and Microsoft Intune)

  • An Entra ID account with permission to grant admin consent on behalf of the organization, such as a Global Administrator

  • A supported version of Microsoft's Company Portal app

  • The "User Registration" app must be excluded from conditional access policies that require compliant devices

  • A configured Microsoft Single Sign-on extension or Platform Single Sign-on extension

Computer Requirements

Computers you want to monitor for compliance must have the following:
  • macOS 10.11 or later

  • Local or mobile user accounts
    Note:

    Network accounts are not supported in the Microsoft Entra integration for macOS.

  • Latest version of Jamf Self Service for macOS

Mobile Device Requirements

Mobile devices you want to monitor for compliance must have the following:
  • iOS 11 or later, or iPadOS 13 or later

  • Latest version of Microsoft Authenticator app (available from the App Store)

  • Jamf Pro Self Service for iOS 10.10.3 or later