Skip to main content
Question

Leveraging LDAP Groups for Scoping

  • January 23, 2024
  • 3 replies
  • 52 views

whiteb
Forum|alt.badge.img+9

So we have Google LDAP connected to Jamf. It's working great for populating User & Location information, etc. However, I'd really like to leverage 'Directory Service User Group' to scope stuff. It just doesn't seem to be working. I've tried to do some reading and I've found people saying it's unreliable. When I go to Cloud Identity Providers > Google LDAP > and do a lookup of myself or others + and also search for a group name - it correctly returns that I'm a member of ___-staff group.

There's a specific policy I want to exclude for this staff group. I can go to exclusions for this policy > Directory Service User Groups > search for the staff group I'm apart of > it finds it, and I add it. After doing that, I still see my computer as pending like it's still in the scope. User & Location info is accurate, my local account matches LDAP user name, etc.

How are people future-proofing scoping?

My other option is to hand-build Departments in Jamf that match Department values from Google/LDAP, I think that works. But I'd rather leverage existing LDAP Groups, that Jamf is correctly seeing I'm apart of.

3 replies

whiteb
Forum|alt.badge.img+9
  • Author
  • Valued Contributor
  • December 19, 2025

A year later but I got this figured out with Jamf Support after revisiting it recently. Turns out that if your Google Group has a space in the name, Jamf won’t be able to find it. Substituting a hyphen for a space works.

 

We finally have Google Group lookups working:

 


howie_isaacks
Forum|alt.badge.img+23
  • Esteemed Contributor
  • December 29, 2025

A year later but I got this figured out with Jamf Support after revisiting it recently. Turns out that if your Google Group has a space in the name, Jamf won’t be able to find it. Substituting a hyphen for a space works.

 

We finally have Google Group lookups working:

 

Interesting. We use Entra ID. One of the groups I have scoped to and excluded has a space in the name but it has worked. This is still good info.


Chubs
Forum|alt.badge.img+23
  • Jamf Heroes
  • December 29, 2025

@howie_isaacks it’s how Google sends stuff over.  Google being googly….they do stuff differently (seemingly to just do things differently 😖).