Skip to main content
Question

"Username directory service group" criteria - Any joy?

  • September 22, 2026
  • 2 replies
  • 20 views

SteveWalker
Forum|alt.badge.img+4

I was excited to hear at Jamf Nation Live about this criteria “Username directory service group” for smart groups.

We’re already Entra ID integrated so I was hoping it would be a breeze to put into practice. Our mappings are standard setup as per the doco. The username field in Jamf populated for at least some devices but I still get 0 results when using this criteria in a Smart Group.

Has anyone had any luck using this criteria for scoping or did I get my hopes up a little prematurely? 

2 replies

Forum|alt.badge.img+8
  • Valued Contributor
  • September 22, 2026

I’ve been using this with pretty good results for our products with account-based licensing. When the  request for a product license is approved the user is assigned to the license group. The user then populates into the smart group and the software is automatically deployed to their assigned Mac. It works pretty well with mobile device apps as well.


Steebie
Forum|alt.badge.img+1
  • New Contributor
  • September 22, 2026

I use an extension attribute that pulls down and lists the device owner’s Entra groups as an extension attribute associated with the device.  From there, I can create smart groups based on what’s listed in that extension attribute of the user’s groups.

 

We’ve got an Intune for Windows and Jamf for Macs environment, with Entra Device Compliance setup between the two products.  I’m sure there are plenty of us who are in a majority Windows environment, with a handful of Macs managed through Jamf by one or two folks.  

 

Something I ended up doing to make managing the Jamf macs for the team very similar to Intune Windows devices was...

1 - Create Entra group named “AAD - [AppName] - MacOS - User Install”

2.1 - Create Smart group with the same name of “AAD - [AppName] - MacOS - User Install”

2.2 - The dynamic criteria is [Entra ID Groups] [Has] [“AAD - [AppName] - MacOS - User Install”]

3 - Create a Mac App deployment scoped to “AAD - [AppName] - MacOS - User Install” for automatic installation.

 

This setup allows someone to add a user to a Microsoft 365 security group, and once the two products sync up (about every 20-30m), it will automatically deploy the software/policy/whatever to the jamf managed MacOS device.

 

This got some of the workload off of strictly me and allowed folks who didn’t know how to manage Macs to also be able to deploy software and policies using tools they were already familiar with.  More workload up front, but long term support isn’t strictly done by one or two people anymore.