Posted on 10-16-2024 02:46 AM
Guys,
Since Jamf introduced Compliance Benchmarks which helps admin to manage and report security compliance on macOS. If that's the case, then Intune integration is mainly for conditional access and no need to check for compliance status as Jamf itself let us know the device compliance status. Is my understanding being correct?
Posted on 10-16-2024 05:09 AM
Jamf retired the Compliance Reporter last month, and "replaced" it with Jamf Protect Offline Mode. Im not sure if there is a licensing cost to this Jamf Protect Offline Mode, but it can be deployed by any MDM. With how new this tool is I don't know much more about it, but I put the link to the documentation below.
https://learn.jamf.com/en-US/bundle/jamf-protect-offline-deployment/page/Protect_Offline_Mode.html
Posted on 10-16-2024 05:21 AM
@ks25 In essence yes. The old Conditional Access integration where Jamf provided inventory data to Intune for compliance evaluation is deprecated and soon to be disabled. With the replacement Device Compliance integration Jamf Pro itself determines device compliance and simply provides two lists of devices to Intune:
There are additional Compliance Benchmark capabilities for reporting on device compliance coming to Jamf Pro that Jamf announced recently at JNUC 2024.
Posted on 10-16-2024 09:04 AM
Yes, the primary purpose of this is for conditional access. JAMF Sends the Compliance status of the Device to Azure based on the Smart group you created. If the device is in the Smart group, its compliance status is sent to Azure.