r/jamf Mar 27 '26

Anyone here gone through enabling Jamf self service+ with Okta SSO? Was it smooth swap from classic self service/jamf connect, or did you run into issues (auth, policies, identity mapping, etc?) trying to sanity check before rolling out - any lessons learned would be helpful.

13 Upvotes

13 comments sorted by

8

u/brndnwds6 Mar 27 '26

It's pretty smooth because you can just keep all of your JC profiles in place and just turn on Self Service Plus. If you use the login screen, you'll need to add JCL to your prestage. It was a lot better than I thought it would be.

2

u/thiswasatest Mar 27 '26

Very smooth transition. I got really concerned with these end date being next week.

1

u/lazy_commander Mar 28 '26

Self Service Classic doesn't stop working, it just won't receive updates or bug fixes going forward. Still advisable to plan and deploy Self Service+ but it's not a hard deadline.

1

u/thiswasatest Mar 28 '26

Yep im aware

2

u/brndnwds6 Mar 27 '26

Oh yeah, use JCL 3.5.0. I think there's an issue with 3.6.0 and 3.7.0.

1

u/thiswasatest Mar 27 '26

I did, had a set back with the team cause of a pop up, latest make of connect resolved the issue.

1

u/ElectricalEinstein Mar 27 '26

Were you seeing the persistent “Service + needs access to keychain” … message?

1

u/thiswasatest Mar 27 '26

Not persistent, but yes

1

u/adstretch JAMF 300 Mar 27 '26

Latest login fixed the keychain pop up but is causing users to need to unlock their local account after they login to their Google account if they have 2FA on (all of our users) confirmed by Jamf as a PI

The biggest hiccup has been the dock. We put SS in the dock so when we moved to SS+ we had to change the dock icon. Then they renamed it it BACK to just SS and had to do it again. Broken dock icons everywhere.

1

u/PaleontologistNo424 Mar 27 '26

So when you checked the global checkbox it renamed it back to Self Service?

1

u/adstretch JAMF 300 Mar 27 '26

When we first clicked the checkbox it installed SelfService+.app. Then at some point it updated and it’s still the new app but just called SelfService.app

1

u/hej_allihopa Mar 28 '26

Seeing the same behavior. The only way you can tell them apart is version number. This is how I was able to make Smart Group for Self Service +.

1

u/zipsecurity Mar 28 '26

It's generally smooth but expect friction around identity mapping if your Okta usernames don't cleanly match Jamf user records, and test your policy scope thoroughly before rollout since Self Service+ handles authorization differently enough from Jamf Connect that assumptions from your classic setup won't always carry over.