Hey Everyone!
Jamf Connect: 2.32.0
macOS: Sonoma 14.3.1
A little back story here. We have Jamf Connect setup with Azure/Entra as our IDP. Our organization is working on moving from a Local on premise AD to Azure/Entra cloud only solution. With that being said I made some cloud only accounts in Azure/Entra and have been playing with new cloud only groups for Jamf Connect with the "Standard" and "Administrator" roles.
I have no problem logging in as these cloud accounts with a standard or administrator role. Here is where I am stuck, on a login with my account which originates from LocalAD and is synced to Azure/Entra I am prompted to do MFA via the Microsoft Authenticator app at the Jamf Connect login screen when I restart or come up from a shut down to unlock the Mac (THIS IS WHAT I WANT) the PROBLEM is with these new Azure/Entra only cloud accounts I am NOT prompted for MFA even though it is setup for the user and they are not in any exclusion groups or CA policies that I can find in Azure/Entra.
I know this is more of an IDP problem I assume but maybe it is Jamf Connect? Jamf Connect does not make the decision to prompt MFA your IDP does but I can't seem to unbury what causes these cloud accounts to just be able to bypass MFA at restart (WHAT I DON'T WANT). I would ideally like the MFA prompting to occur for all accounts those in local ad and those in the cloud as we begin transition period which may last awhile.
Any ideas where I can start digging on the Jamf or Azure/Entra side that I may have missed?
Thank You!
-Paul