Configuring single sign-on through Jamf Account for administrator authentication to the Jamf platform now supports Microsoft's admin consent flow for Entra ID connections.
From Organization > SSO > New Connection, choose Entra, then select "Use Microsoft's admin consent flow for multi tenant applications." Click Connect with Microsoft and approve the screen. If you're not the Entra Global Admin, copy the link and send it to them instead. Once they approve, Jamf configures the connection. Manual configuration is still available as an option.
New Entra connections request GroupMember.Read.All and User.Read instead of Directory.Read.All. Existing connections on the old scope can switch to the new scope using the "Entra Scopes" selector, which preserves existing group mappings.
If your organization's domain is already verified in Microsoft Entra ID, Jamf inherits that verification automatically. Domain verification in Jamf Account is skipped for that connection.
Full setup steps: Setting Up Microsoft Entra ID Consent Flow.
