Jamf AAD not prompting after registration in self-service portal

tyson983
New Contributor

Hey everyone,

I having a hard time trying to get Mac Devices in Jamf Pro to integrate into Endpoint Manager (Intune). I have got at least 2 devices to register in Endpoint Manager, however, some devices are not getting the follow-up prompt ""JamfAAD" want to use "microsoftonline.com" to sign in.". Does anyone with any ideas on how to troubleshoot this issue? 

3 REPLIES 3

AJPinto
Esteemed Contributor

In my dealings with the JAMF MEM/AAD integration, I discovered it is absolute hot garbage that Microsoft has no idea how to support. Honestly it should not exist with how poor the experience is.

 

The issue you are seeing is actually what caused me to retire the JAMF MEM/AAD integration. My hunch is it had something to do with the authentication work flow that was happening within Company Portal. Sometimes authentication worked exactly as expected. Other times the authentication work flow would go down a rabbit hole and try to trigger the appstore to open to Microsoft Authenticator which does not exist for macOS but would be expected behavior for iOS/iPadOS. Microsoft could not figure out why it was doing this after 3 months of tickets so I killed it all. The best Microsoft could say for us it was something configured wrong in Azure but could not provide any more direction, we all know how complicated Azure is and I am not the Azure admin. 

 

It is also possible one of your network filters, or SSL redirection tools could be eating something.

 

pete_c
Contributor III

The Jamf/AAD connector is poorly designed and supported, for sure.  Across my entire org, nobody could tell me how to understand or change the behavior of when and why the re-registration dialog comes up. I've just started booting out the com.jamf.management.AAD.plist until the workflow is less clunky.

obi-k
Valued Contributor III

Try starting over. Remove the Company Portal app, delete the Macs from Endpoint Manager, and run this script in this thread. See if you get the prompt then.

A lot of weirdness like others mentioned. But hopefully, this gets you the result you're looking for.