Hello, I have been working on deploying Jamf Connect: Verify/Login and have had lots of issues.
Some details:
Using AzureAD only no on-prem AD
1 local admin account on Macs.
No MDM in play. :(
I have tried 2 different deployments with different results and issues.
1.Migrate deployment:
1.Created mobileconfig profiles from plist files for jamf login and jamf connect
2.install profiles
3.logout of user account
4.Login to AzureAD
5.Asks to Migrate with local account
6.Click yes and logs you into the existing local account and adds a AzureAD alias to the local account
7.Logout account
8.Back to AzureAD login screen.
9.Log in and now you're in a login loop.
10.WORKAROUND: Revert back to default macOS login screen and login like normal.
Issues:
No way to verify if the AzureAD tokens are working.
Jamf Verify will let you sign in over and over again.
2.New User Deployment
1.Created mobileconfig profiles from plist files for jamf login and jamf connect
2.install profiles
3.logout of user account
4.Login to AzureAD
5.Create new standard account
6.Jamf verify auto opens
7.Log out and have double login with AzureAD first then Jamf Connect re-enter password
Issues:
No way to Verify AzureAD Tokens
No way to move user data from the other local account
Questions:
Is there a way have the color of Jamf Verify change to green on success without Kerberos tickets?
Is there a way to display on the menu bar how many days till password expires?
Is there a way to hide the sign in button when you have already signed in?
Is there a way to test the AzureAD tokens are working?
Conclusion:
I'm a big big Jamf fan and love the product. I think Jamf Connect Login/Verify is a great idea, but it seems like it's half baked and very poor documentation and support account it.
Yes, I have seen all the documentation from Jamf nation on this tool.
So please someone who has any knowledge on this please share.