為Entra ID部署單一登入延伸功能承載資料 - Jamf Setup 和 Reset 設定指南

Jamf Setup 和 Reset 設定指南

Solution
Application
Jamf Reset
Jamf Setup
Content Type
技術說明文件
Utilities & Services
ft:locale
zh-TW

Requirements

Microsoft Authenticator 必須為共用裝置模式。如需更多資訊,請參閱下列來自 Microsoft 的說明文件:

共用裝置模式的概觀

  1. Jamf Pro中,於側邊欄中按一下裝置
  2. 按一下側邊欄中的 設定描述檔
  3. 按一下 新建
  4. 使用「一般」承載資料設定描述檔的基本設定,包括發佈方法。
  5. 按一下「單一登入延伸功能」承載資料,並按一下新增
  6. 使用切換開關啟用SSO作為承載資料類型。
  7. 擴充識別碼欄位中輸入com.microsoft.azureauthenticator.ssoextension
    Note:

    團隊識別碼欄位保留空白。

  8. 選取重新導向作為登入類型。
  9. 新增下列URL,用於您的App與Entra ID之間的認證:
    • https://login.microsoftonline.com/
    • https://login.microsoft.com/
    • https://sts.windows.net/
    • https://login.partner.microsoftonline.cn/
    • https://login.chinacloudapi.cn/
    • https://login.microsoftonline.de/
    • https://login.microsoftonline.us/
    • https://login.usgovcloudapi.net/
    • https://login-us.microsoftonline.com/
  10. 打開終端機並建立下列 PLIST 檔,其透過執行以下defaultsplutil命令即可啟用共用裝置模式:
    defaults write ~/Desktop/jamfsetup.plist sharedDeviceMode -bool true
    
    plutil -convert xml1 ~/Desktop/jamfsetup.plist
    PLIST檔案會建立在您的本機桌面上,包含下列內容:
    <?xml version="1.0" encoding="UTF-8"?>
    <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
    <plist version="1.0">
    <dict>
        <key>sharedDeviceMode</key>
        <true/>
    </dict>
    </plist>
  11. Jamf Pro中,使用自訂配置方塊新增PLIST檔案至承載資料。
  12. 按一下範圍標籤頁並配置描述檔的範圍。
    若要發佈使用者層級的描述檔,請確保您將iPad新增至已啟用「共享的iPad」範圍。這可針對裝置的每位潛在使用者將描述檔安裝在該裝置上。當每位使用者登入時,便會將描述檔安裝在該裝置上。
    Note:

    若要基於LDAP使用者或LDAP使用者群組進行限制或排除,則必須在行動裝置清單中填入使用者名稱欄位。

  13. 按一下儲存