Jamf and intune compliance setup questions

Dperk
New Contributor III

I've recently been tasked with getting intune complaince/jamf working to test if its viable to go forward with. I've been working on setting it up on our sandbox environment and was wondering if anyone's tried setting up the conditional access policy on the Microsoft side. Like what they used for testing or anything they had to tweak or change to get working. Id to know what you guys used for a test policy thats easy to see quick results. 

 

-In theory if a mac isnt compliant things like "Unable to sign into outlook" would be possible or some kind of email notification to prompt the user to update. 

-What have you guys used the integration for that you've been pleased with? 

1 REPLY 1

alicbeen
New Contributor II

@Dperk wrote:

I've recently been tasked with getting intune complaince/jamf working to test if its viable to go forward with. I've been working on setting it up on our sandbox environment and was wondering if anyone's tried setting up the conditional access policy on the Microsoft side. Like what they used for testing or anything they had to tweak or change to get working. Id to know what you guys used for a test policy thats easy to see quick results. 

 

-In theory if a mac isnt compliant things like "Unable to sign into outlook" would be possible or some kind of email notification to prompt the user to update. 

-What have you guys used the integration for that you've been pleased with? 


I've been working on integrating Intune compliance with Jamf in our sandbox environment as well. For setting up the Conditional Access policy on the Microsoft side, here are a few tips based on my experience:

  1. Test Policy Setup:

    • Policy: Create a basic Conditional Access policy that targets all users or a test group. Set conditions to require a compliant device for access to specific applications, like Outlook or Teams.
    • Compliance Check: Use Jamf to configure compliance policies that align with your Conditional Access policy. Test by intentionally creating non-compliant scenarios to verify if access restrictions (e.g., inability to sign into Outlook) are applied correctly.
  2. Testing and Notifications:

    • Testing: Use a test device and intentionally make it non-compliant to ensure the policy behaves as expected. Check for sign-in issues or access blocks.
    • Notifications: Implement notifications within Jamf or configure email alerts via Intune to inform users of compliance issues and prompt them to update their devices.
  3. Integration Benefits:

    • Pleased With: I’ve found that using this integration helps enforce security policies effectively and streamline device management. It’s great for ensuring that all devices meet compliance requirements before accessing sensitive resources.

Hope this helps! Let me know if you have any other questions.