Device Compliance for Shared Devices

Technical Paper: Device Compliance with Microsoft Entra and Jamf Pro

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US
Microsoft's Shared Device Mode (SDM) is a feature in Microsoft Entra ID that allows a device to be shared among multiple users. Jamf Pro supports shared devices as a device compliance platform type.
Note:

Device compliance for shared devices is not available for Jamf Premium Cloud Plus.

To use device compliance for shared devices, the following requirements must be met:
  • Jamf Pro 11.13.0 or later

  • The Cloud Services connection must be enabled.

  • Jamf Setup and Jamf Reset need to be configured for Shared Device Mode and deployed to end user devices. com.jamf.config.sso.require-device-registration must be set to true. This configuration is available for 3.3.1 or later. For more information, see the Jamf Setup and Reset Configuration Guide.

  • Microsoft Authenticator must be deployed to end user devices.

Device compliance for shared devices is available as a platform type in Jamf Pro. When setting up device compliance for shared devices, consider the following:
  • The Applicable Group should not include devices that are included in a different Applicable Group for standard iOS compliance.

  • When selecting an Entra ID Group for policy scoping, no group assignment is required.

  • When configuring device compliance in Jamf Pro, you can select Custom configuration for single sign-on extension to upload a PLIST file containing custom key-value pairs.

For more information about configuring device compliance, see Configuring the Microsoft Entra Integration.

Important:When a device is registered using device compliance for shared devices, the Microsoft Authenticator app on the device enters Shared Device Mode. If shared device compliance is disabled, the device will need to be erased in order for the device to register with device compliance again, or to disable SDM. For more information on erasing a device, see the Deploying macOS Platform SSO for Microsoft Entra ID with Jamf Pro article.