Skip to main content
Question

Jamf Connect Login and on premises AD


Forum|alt.badge.img+2
  • New Contributor
  • 1 reply

hello,

We had a question from a customer evaluating Jamf Connect Login, if it can work with on premises AD (they have a hybrid environment). Essentially, they would like to mimic NoMAD and NoLOAD behavior (local account, remaining days of password appearance, native macOS login screen).

I am aware that JCL works only with Entra.

 

Best regards

K

5 replies

AJPinto
Forum|alt.badge.img+26
  • Legendary Contributor
  • 2706 replies
  • July 23, 2024

Jamf Connect works with modern IDPs such as Entra, Okta, and Google Identity. Jamf Connect does not work with legacy identity providers such as On Prem AD.

 

Jamf Connect can be used with Entra, and you can have the Microsoft Entra Connect setup with your AD instance to sync Entra with AD and have AD as your principal identity management tool. However, to answer your question, no Jamf Connect will not work directly with AD.


easyedc
Forum|alt.badge.img+16
  • Esteemed Contributor
  • 623 replies
  • July 23, 2024

You probably want to check into Kerberos SSO. It's specifically designed to work with an on-prem AD and not Entra.  It's native to Apple and part of the OS (used to be Enterprise Connect).


Forum|alt.badge.img+2
  • Author
  • New Contributor
  • 1 reply
  • July 23, 2024

Thank you both, 

@easyedc I am aware of that, but it requires an MDM connected device, they (still) dont have an MDM solution, they just wanted to use the JCL.

 

Best regards

 

K


AJPinto
Forum|alt.badge.img+26
  • Legendary Contributor
  • 2706 replies
  • July 23, 2024
co22 wrote:

Thank you both, 

@easyedc I am aware of that, but it requires an MDM connected device, they (still) dont have an MDM solution, they just wanted to use the JCL.

 

Best regards

 

K


The 1st thing you want to get is an MDM, all the other stuff comes after. Without an MDM you have no way to deploy Jamf Connect, or its Configuration Profiles (the license key needs to be updated annually so manually loading with Apple Configurator won't work).


easyedc
Forum|alt.badge.img+16
  • Esteemed Contributor
  • 623 replies
  • July 23, 2024

How do they intend to touch every system to install it without an MDM?  the config profile would be able to be manually installed just like the software. 


Reply


Cookie policy

We use cookies to enhance and personalize your experience. If you accept you agree to our full cookie policy. Learn more about our cookies.

 
Cookie settings