Skip to main content

Announcing SCIM-based administrator provisioning for Jamf Account, now in Beta

  • June 10, 2026
  • 1 reply
  • 87 views

scafide
Forum|alt.badge.img+21

Hey Jamf Nation!

We're excited to announce SCIM-based provisioning and lifecycle management of administrator profiles in Jamf Account, now available in Beta.

Inbound SCIM lets your identity provider push administrator profiles directly into Jamf Account without requiring those users to sign in first. Once configured, your IdP becomes the source of truth for administrator lifecycle events in Jamf. This beta supports Microsoft Entra ID and Okta as identity providers.

Today, SCIM-provisioned profiles appear in Jamf Account, names stay current when updated in your IdP, and you can assign roles and privileges before an administrator's first login. This is the foundation for platform-wide administrator provisioning across Jamf Pro, Jamf Security Cloud, and other Jamf applications. When that work ships, your SCIM configuration carries forward with no changes required.

When configuring your SCIM connection, you can also select the groups scope. Groups sync now but do not yet drive role assignments. That capability is in development and will use the groups you configure today.

To access the feature, navigate to Organization > SSO in Jamf Account, open the menu on your IDP connection, and select "Manage SCIM." We recommend starting with a test connection before pointing this at your production environment.

What we're looking for in beta: confirm that administrator lifecycle events propagate from your IdP into Jamf Account as expected, including provisioning, updates, suspension, and deletion.

How to join the beta:

  • Enroll in the Beta Program under Product Feedback at account.jamf.com
  • Click "Join Community" to join the beta forum once enrolled
  • If you encounter an error joining the beta forum, log into Jamf Nation first and click "Join Community" again

Check out this blog post on Configuring SSO in Jamf Account, and email beta@jamf.com with questions.

The Jamf non-disclosure agreement covers this beta program. Do not share information about your testing on any public forum, including the non-beta areas of Jamf Nation. Use the Jamf Nation Beta Forum or contact beta@jamf.com with any questions. Thank you to all who participate!

1 reply

ega
Forum|alt.badge.img+17
  • Valued Contributor
  • June 12, 2026

This is something we have been waiting on so thanks for working on this.  My concern is how this will work with Sites which we will need to use it at all.  Currently we are using the Entra Cloud identity in parallel to get our groups in and they are easily as assignable at the site level.