Migrating from macOS Conditional Access to macOS Device Compliance

Technical Paper: Device Compliance with Microsoft Entra and Jamf Pro

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US
If you have computers enrolled under the legacy Conditional Access integration, you must migrate the computers to the new device compliance integration before the deprecation of the Microsoft Partner Device Management API (removal date: 31 January 2025).
Important:
  • After Conditional Access integration is disabled, Microsoft Intune allows a 60 day grace period to migrate registered computers to the new device compliance integration before marking registered computers as non-compliant in Entra ID.

  • To ensure device compliance remains accurately reported, Jamf recommends that you enable the device compliance integration immediately after disabling the Conditional Access integration.

  • Once you have begun the migration from Conditional Access to device compliance, Jamf does not recommend re-enabling Conditional Access. If you need assistance to complete the migration, contact Jamf Support.

Migrating from macOS Conditional Access to macOS device compliance involves the following steps:
  1. Configuring the connection between Jamf Pro and Microsoft Intune

  2. In Jamf Pro 11.5.0 or later, deploying a script to migrate users from Conditional Access to device compliance

Requirements
  • Computers registered under the Conditional Access integration

  • A Jamf Cloud-hosted or on-premise environment that meets the requirements listed in Jamf Pro Device Compliance Requirements section, including allowing Jamf Pro to access the appropriate network ports and URLs

  • The Cloud Services Connection must be enabled. To enable the Cloud Services Connection, follow the steps outlined in Enabling the Cloud Services Connection in the Jamf Pro Documentation