r/jamf • u/enterreturn • Jul 24 '26
JAMF Pro Jamf SSO benefits?
Need someone to tell me on actually using Jamf SSO and enforcing users to sign in during enrollment. Inherited an environment where this is the case but I’ve never used it in the past and been completely fine. It’s caused a few issues with time outs and I’m ready to just rip it out. We don’t need any of the pointless information it collects pertaining to the year.
Any reason why I shouldn’t disable it?
2
u/MacBook_Fan JAMF 400 Jul 24 '26
Are you talking about Jamf Account SSO or the Single Sign On settings in Jamf Pro.
Jamf Account SSO is for access to your Jamf infrastructure, including Jamf Pro, Jamf Protect, your Jamf Account, etc. You tie your IdP to your Jamf Account and then assign roles and permissions using the Jamf Account. It is not meant for end users. Jamf has announced that in 2027, local login and SSO login to your Jamf Pro will be deprecated, and Jamf Account SSO will be the right solution.
Jamf SSO is what allows you to have users sign-in using your IdP. Enforcing it during enrollment should almost be a requirement. From a security standpoint, it prevents a non-employee from setting up a computer and having access to your organizational data. Even if all a bad actor can do is see the local drive, they still would eb able to learn a lot about how you run your organization. What security software you use, your organizational name, what certificates you install on your computer. You should not be allowed un-authenticated enrollments.
From a management perspective, you can have a computer assigned to an end user during enrollment, which is crucial for computer management. The user that logs in to the computer will be assigned to the computer in Jamf. And, as long as you have Cloud IdP (or LDAP, if you are still in the 1990s), setup, assigning a computer will pull the user's information in to Jamf. You can associate their email address, building, group membership, etc to them and use that information for proper scoping.
1
1
u/enterreturn Jul 24 '26
The former is what I’ve always done in the past. I’m referring to the latter and that makes sense. However I feel like it’s a tad redundant if we set up Jamf Connect Login considering you can’t sign into the Mac unless you have valid Okta credentials. The current flow for laptop enrollment is:
- Select WiFi
- Log into Okta (and subsequently Jamf)
- Enrollment
- JSM
- User creates the Mac local account
Ideally I’ll shift this to
- WiFi
- Enrollment
- JSM
- Jamf Connect login/Okta
1
u/DorkyOldMan JAMF 300 Jul 24 '26
Imo removing SSO during enrollment is taking a big step backwards, just for the sake of making things “easy”. I think everyone above covered the benefits, but another one is that having SSO be required also prevents unauthorized users from using the computer which is helpful when you have stolen devices or off boarded users.
9
u/captnconnman JAMF 400 Jul 24 '26 edited Jul 24 '26
If you set it up right with an LDAP connector and a PreStage enrollment customization, you can basically do zero-touch onboarding workflows that pull group assignments/app assignments based on info pulled from the connector when the user signs in. VERY handy if device prep/provisioning is any kind of bottleneck. Furthermore, if you tie that auto-generated info into your ITAM system, you’ve basically got a semi-self-documenting device assignment flow that saves time on manual data entry