Posted on 10-28-2024 02:03 AM
During integration of Jamf Pro with Entra, a Global Administrator account is needed and this account must exist on the Entra tenant. Often, we use the same account to set up the app registrations for Jamf Connect and to create the various changes for conditional access exemptions, etc.
Once these are set up, can this Global Administrator account be safely removed from Entra without affecting any of the integrations or applications created?
Solved! Go to Solution.
Posted on 10-30-2024 12:57 AM
Confirmed with Jamf Support that once the integrations have been set up, the account is no longer needed.
Posted on 10-28-2024 03:12 AM
The global administrator account used for setup must remain active. In most cases, with SSO using Entra, deactivating this account will cause unauthorized access issues during sync. A generic admin account can be used instead of a named account.
Posted on 10-29-2024 02:37 AM
Thank you. Is this documented somewhere?
Posted on 10-30-2024 12:57 AM
Confirmed with Jamf Support that once the integrations have been set up, the account is no longer needed.