Posted on 04-02-2024 06:29 AM
New and somewhat confused JAMF-user here, and thus: silly questions.
I'm using Entra as my Cloud Identity provider and I'm trying to create a smart user group based on membership in an Entra-group (JAMF_KLA) in order to build configurations for said usergroups. But I cannot for the life of me get it to work (nor do I know if it's actually possible).
Looked at the mapping of both the SUG and in the CIP-setup, and everything there looks like it should work. Can also do a test against various users, and it works (User that is in the Entra-group gets green checkmark, user that is not in group gets red checkmark). Which tells me that the lookup is working.
I see that I can also add users from a Directory Service from the Settings-menu. However, is that only for admins/auditors? I see that there's an option for Enrollment Only. Does this mean that the imported users do *not* have access to the JAMF-console?
Solved! Go to Solution.
Posted on 04-02-2024 09:17 AM
This should be doable, especially if your LDAP test lookups are working. It sounds like it is.
My first note would be to put a ticket in with your Jamf Support and see if you can get help there. They helped me with this...
• You could implement an EA with the Directory Service Attribute Mapping and "memberOf" to pull in group memberships.
• From there, you'd create a smart group with criteria for that EA to build configurations for the EntraID memberships.
• I look up these groups after the EA is run, and search for the membership in the computer, inventory, and extension attribute listings.
Posted on 04-02-2024 09:17 AM
This should be doable, especially if your LDAP test lookups are working. It sounds like it is.
My first note would be to put a ticket in with your Jamf Support and see if you can get help there. They helped me with this...
• You could implement an EA with the Directory Service Attribute Mapping and "memberOf" to pull in group memberships.
• From there, you'd create a smart group with criteria for that EA to build configurations for the EntraID memberships.
• I look up these groups after the EA is run, and search for the membership in the computer, inventory, and extension attribute listings.
Posted on 04-02-2024 10:41 PM
Thanks, will have a look!
Posted on 04-02-2024 11:37 PM
Had to check the box "Collect user and location information from Directory Service" under Settings - Device Management - Inventory Collection before I had the option of using the Directory Service Attribute Mapping. Will test further, but looks promising.
Thanks for the help and response!
Posted on 04-03-2024 04:54 AM
Nice catch. We had this checked already, but good to add to notes.
If it helps, I replicated this for iOS mobile devices and Macs. Should work for you if you have Macs too.
Posted on 06-26-2024 06:11 PM
@obi-k Hey Obi-K I was trying this for Directory Service Attribute Mapping and "memberOf' for Entra ID and isn't working. Could this be a mapping issue?
Any thoughts?
Posted on 06-27-2024 04:16 AM
• When you go to a computer or a device inventory tab, and Extension Attributes, are there LDAP groups listed under EA?
• Did you do an inventory update on the device/s
• When you run an LDAP "test" connection, is it successful under Settings, LDAP Server?
• Did you check the box on "Collect user and location information from Directory Service" box under Settings, Inventory Collection?
Posted on 06-27-2024 09:15 PM
Hey Obi-k
LDAP Server settings are no longer set up, though use to be.
Question if you used the same EA that we used for LDAP when it was configured and just changed the input type from LDAP to Directory Service Attribute Mapping.. could this be the problem as some devices that still showing the old ldap file paths.
Would I need to delete this original EA and reset it up?
Posted on 06-28-2024 08:28 AM
I'm trying to implement this as well after our migration to Entra (cloud identity provider) from LDAP. "memberOf" definitely does not work.
Posted on 09-19-2024 03:57 PM
Anyone figure this out?
Trying to create a mobile device Smart Group based on membership of a shared Entra group, but can't quite get it figured out.
memberOf definitely doesn't work.
Posted on 11-21-2024 07:14 AM
memberOf is also not working for me with Entra and cloud lookups.
Posted on 11-26-2024 01:50 PM
There is an open PI for this - PI103644 - PI-009562 Using the 'memberOf' attribute with Azure LDAP integrations returns no results.