Skip to main content
Question

Jamf Pro Portal 2fa

  • December 20, 2023
  • 6 replies
  • 20 views

Forum|alt.badge.img+3

Am am trying to secure our jamf pro portal but cant seem to find any documents on this and cant see anywhere to add it in JAMF pro, has anyone secured there logins with 2fa 

6 replies

Chubs
Forum|alt.badge.img+21
  • Jamf Heroes
  • December 20, 2023

Are you using a cloud IdP?  We pass through Entra MFA or SecureAuth through our login screen.


Forum|alt.badge.img+3
  • Author
  • New Contributor
  • December 20, 2023

Are you using a cloud IdP?  We pass through Entra MFA or SecureAuth through our login screen.


how have you setup Entra MFA , i cant find anything about securing the portal you would think jamf would be pushing MFA on the portals 


Forum|alt.badge.img+19
  • Honored Contributor
  • December 20, 2023

You can not use MFA on Jamf Pro unless you set up Single Sign-On and use your SSO providers MFA. 

https://learn.jamf.com/bundle/jamf-pro-documentation-current/page/Single_Sign-On.html


Forum|alt.badge.img+3
  • Author
  • New Contributor
  • December 20, 2023

You can not use MFA on Jamf Pro unless you set up Single Sign-On and use your SSO providers MFA. 

https://learn.jamf.com/bundle/jamf-pro-documentation-current/page/Single_Sign-On.html


Thanks :) am really shocked this is not built in for the amounts we are paying this is a basic security feature for most platforms. 


wildfrog
Forum|alt.badge.img+11
  • Valued Contributor
  • December 20, 2023

@uber99 I agree. It's disappointing. On the one hand, I appreciate that I can bring my own IdP to get MFA. But I think it's ridiculous that I have to bring my own IdP to get MFA - which every other SaaS vendor just bakes in. My gut tells me this is due to tech debt in Jamf Pro, but I have no real evidence of this.

 

That said, we're using JumpCloud for this. Seems to work well enough. 


Chubs
Forum|alt.badge.img+21
  • Jamf Heroes
  • December 22, 2023

how have you setup Entra MFA , i cant find anything about securing the portal you would think jamf would be pushing MFA on the portals 


The worst thing about this is that there are a lot of things that can't happen once this is done - like using MUT or API calls via user (salted of course).

You have to create a generic "standard" user for these items.