Jamf Connect with multiple Microsoft Tenant

ekrudy
New Contributor

We have 5 different brands and each brand has its own Entra ID, I was wondering if we could setup JAMF Connect PreStage enrollment tied with the specific IdP.

Only one Entra ID worked and that is because the SSO on JAMF Pro has been configured and linked to that Microsoft tenant. I'm really confused. Help is much appreciated.

4 REPLIES 4

stevewood
Honored Contributor II
Honored Contributor II

You cannot use an Enrollment Customization with an SSO option. That will pull from the SSO settings that are configured within Jamf Pro.

If you want 5 different Jamf Connect settings, then you would need:

  • 5 different Jamf Connect configuration profiles for Jamf Connect Login
  • 5 different Jamf Connect configuration profiles for Jamf Connect Menu Bar
  • 5 different PreStages
  • 5 different Smart Groups that use a criteria looking for “Enrollment Method: PreStage Enrollment” IS and the name of the PreStage

Note: you can combine the Configuration Profiles into one for each Entra tenant instead of breaking out Jamf Connect Menu Bar and Jamf Connect Login

In the PreStage for each Entra tenant you would choose the proper Configuration Profile(s) to match that Entra tenant. You would also scope each of those Configuration Profiles using the Smart Group that corresponds to the proper PreStage.

For example, if I had Entra Tenant 1 and Entra Tenant 2 I would create the following for Entra Tenant 1:

  • ”Entra Tenant 1 - Jamf Connect Login” - configuration profile scoped to “PreStage Enrolled - Entra Tenant 1” Smart Group that is created below.
  • ”Entra Tenant 1 - Jamf Connect Menu Bar” - configuration profile scoped to “PreStage Enrolled - Entra Tenant 1” Smart Group that is created below
  • ”Entra Tenant 1” PreStage - I would select the two Configuration Profiles listed above (I would also have a license configuration profile that I would select)
  • ”PreStage Enrolled - Entra Tenant 1” Smart Group with “Enrollment Method: PreStage Enrollment” IS “Entra Tenant 1”

Doing the above will have each device get the proper Jamf Connect settings during the PreStage for their Tenant and because the Configuration Profile is scoped to that Smart Group, the profiles would stay scoped to those Tenant 1 devices.

Hopefully that all makes sense.

ekrudy
New Contributor

Hey @stevewood  thanks so much, I should be more specific about my post, I have everything configured as you recommended already but the only thing I still have configured under JAMF Pro is the Single Sign-On, should I turn this off? At this point, we won't be able to log in to JAMF Pro with our Microsoft emails correct?

Thanks again

stevewood
Honored Contributor II
Honored Contributor II

The SSO settings for Jamf Pro can only be configured to one Entra tenant at a time. So if you need to use SSO for any of the following, you will have to find some way to do a parent-child type setup in Entra (sorry, not an Entra SME so not sure if this is even possible):

  • SSO into Jamf Pro GUI
  • SSO into Self Service
  • Enrollment Customization (SSO) in a PreStage

I am sure there might be other aspects I am missing.

ekrudy
New Contributor

Hi @stevewood I was able to set up what I need and adding to what you recommended I ended up doing it through "Sites" and not Smart Group.