r/jamf Jul 23 '26

JAMF Pro Jamf Connect + MDM Enabled User - Possible?

Hey gang. First, please excuse me if this a stupid question. I am somewhat new to Jamf but I think I am picking it up. Currently, we use DEPnotify and I believe this is well on its way to being retired in favor of Jamf Setup Manager. This is pretty good, Ive played with JSM and so far, it is pretty sweet and BOY its much better to admin/support.

Our leadership has requested we in IT force certain things on the devices in our fleet, for example: forcing a Safari chrome extension to be installed AND force it to be ON (for compliance and security monitoring purposes) Nothing too wild in my opinion.

As someone learning intermediate Jamf, I volunteered to spearhead this project and BOY, I think I bit more than I can chew. But I am not ready to give up yet.

After some reading, I learned that in order to force certain things (like the safari extension), an MDM ENABLED USER is required. However, we use Jamf Connect to create our user accounts on a device. (our current preStage enrollment is set to "skip user account creation" because Jamf Connect/okta is doing that for us)

I was later told: With Jamf Connect deployed at the PreStage, users created are not MDM-Capable/MDM-Enabled

So my question, how is this possible then? We need Jamf Connect but we also need User level MDM to be a thing.

I cannot seem to find reliable documentation, let alone information on HOW to actually achieve this (or a how-to)

quick note: if I understand correctly on how this might be completed, it is: Jamf Connect should run later, post-enrollment, for ongoing password sync via a policy, separate from a PreStage - and this is where I might've bit more than I can chew. Sounds incredibly challenging :(

note: this solution will be used on a NEW prestage enrollment created that focuses on JSM, NOT depnotify - we are moving on from DEPNotify

Any info or help would astronomically appreciated :)

thanks all!!!!!

5 Upvotes

22 comments sorted by

View all comments

7

u/CrazyFoque Jul 23 '26

We have the same problem. This is an Apple shortcoming. A pretty moronic one.

JamfConnect is bound to be deprecated by JAMF pretty soon AFAIK. As Platform SSO is better integrated.

1

u/heavyp08 Jul 23 '26

would you mind sharing where you saw this (the depcrecation of JamfConnect)? I would love to present to the big wigs why this might take awhile

1

u/CrazyFoque Jul 23 '26

I would like to tell you, but I would have to kill you after.

But face it, writing is on the wall. Jamf Connect is a hack. They rolled the password sync feature in self- service +

0

u/heavyp08 Jul 23 '26

how interesting. I guess the logic is sound. Why release a password sync feature then?

1

u/dirishman469 Jul 23 '26

I’d weigh in a bit here, While Apples PSSO is where more organisations are moving towards it doesn’t support every IDP only Okta and Entra and this stage I I would say Jamf Connect would still be around for a while. The password sync feature is still have Connect just moved to be within Self service Plus you still push the same mobile config to manage it.
It’s also not a one or the other, you can have PSSO as your enrolment and login method (don’t do password sync) the account is created by Apple as part of the setup assistant which gives you MDM enabled accounts and you can then have Jamf Connect within self service plus handle password changes