How to Configure SAML Authentication for Jamf Pro

Item

Details

Prerequisites

  • Advance configuration is required in Jamf Pro.

  • You must create an account in Jamf Pro using the same email address as in TrustLogin.

  • If you want to enable SSO for device enrollment by users, please refer to the manual here.
  • For the latest configuration steps, please check the manual provided by Jamf Pro.

Name ID

Email address

Custom attribute Note: For instructions on how to configure custom attributes, click here

SP-side settings

Configured by the administrator

Request the SP to configure

Provisioning

Supports provisioning via API (accounts can be managed in TrustLogin)

Supports SAML JIT provisioning (accounts can be managed in TrustLogin; user deletion not supported)

None (accounts are created in each system)
Note: For instructions on how to configure provisioning, click here

Access method

SP-Initiated SSO

IdP-Initiated SSO

Verified operation status by device

PC - Browser

PC - Desktop app

iOS - Standard browser (Safari)

iOS - TrustLogin mobile app internal browser

iOS - Native app

Android - Standard browser (Chrome)

Android - TrustLogin mobile app internal browser

Android - Native app

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. On the "Register Enterprise App" screen, search and select "Jamf Pro (SAML)."
    JamfPro01.png

  3. Download the metadata from the "Download Metadata" button under "Identity Provider Information."
    03.png

  4. Configure the "Service Provider Settings" as follows.
    Redirect URL after successful SP authentication

    If you want users to be redirected to the Jamf Pro profile distribution screen after SSO login, enter "https://xxxxxx.jamfcloud.com/enroll".

    Note: "xxxxxx" is your Jamf Pro subdomain name.

    Note: This is an optional setting item. Leave it blank if you want users to be redirected to the dashboard screen.

    Entity ID Enter your Jamf Pro subdomain name.
    Note: If your Jamf Pro URL is "https://xxxxxx.jamfcloud.com", enter "xxxxxx".
    ACS URL for service Enter your Jamf Pro subdomain name.

    JamfPro.png

  5. Click the "Register" button to save.

Jamf Pro Settings

  1. Open "Settings (gear icon in the upper right) > Single Sign-On."
    05.png

  2. After clicking "Edit," switch the Single Sign-On Authentication toggle to ON.
    06.png

  3. Configure each item as follows, then click the "Save" button to save.
    Failover Login URL

    This is the URL that allows you to log in with your Jamf Pro ID/password even after SAML SSO is enabled, so copy it and keep it for your records.

    Identity Provider Select "Other..."
    Identity Provider Metadata Source Select "Metadata File," then drag the metadata downloaded from TrustLogin into the dotted box, or upload it by browsing for the file
    Override Token Expiration Specify any time (in minutes) according to your operational needs
    Identity Provider User Mapping Select "NameID"
    Jamf Pro User Mapping Select "Email"
    Identity Provider Group Attribute Name

    Enter "groups"

    Note: Do not check the optional "Enable Single Sign-On for User Enrollment."

    07.png

TrustLogin User Settings

① When a User Adds the App from My Page

  1. On "My Page," click the "Add App" button.
  2. On the "Register App" screen, select "Jamf Pro (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name," enter it, then click the "Register" button.

② When an Administrator Adds Members

  1. In the "Admin Page > Apps" menu, search for and click the "Jamf Pro (SAML)" app.
  2. Click "Add Member," select the user(s) to add from the member list, and click the "Register" button to add them.

How to Configure SAML Authentication for Jamf Pro

Item

Details

Prerequisites

  • Advance configuration is required in Jamf Pro.

  • You must create an account in Jamf Pro using the same email address as in TrustLogin.

  • If you want to enable SSO for device enrollment by users, please refer to the manual here.
  • For the latest configuration steps, please check the manual provided by Jamf Pro.

Name ID

Email address

Custom attribute Note: For instructions on how to configure custom attributes, click here

SP-side settings

Configured by the administrator

Request the SP to configure

Provisioning

Supports provisioning via API (accounts can be managed in TrustLogin)

Supports SAML JIT provisioning (accounts can be managed in TrustLogin; user deletion not supported)

None (accounts are created in each system)
Note: For instructions on how to configure provisioning, click here

Access method

SP-Initiated SSO

IdP-Initiated SSO

Verified operation status by device

PC - Browser

PC - Desktop app

iOS - Standard browser (Safari)

iOS - TrustLogin mobile app internal browser

iOS - Native app

Android - Standard browser (Chrome)

Android - TrustLogin mobile app internal browser

Android - Native app

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. On the "Register Enterprise App" screen, search and select "Jamf Pro (SAML)."
    JamfPro01.png

  3. Download the metadata from the "Download Metadata" button under "Identity Provider Information."
    03.png

  4. Configure the "Service Provider Settings" as follows.
    Redirect URL after successful SP authentication

    If you want users to be redirected to the Jamf Pro profile distribution screen after SSO login, enter "https://xxxxxx.jamfcloud.com/enroll".

    Note: "xxxxxx" is your Jamf Pro subdomain name.

    Note: This is an optional setting item. Leave it blank if you want users to be redirected to the dashboard screen.

    Entity ID Enter your Jamf Pro subdomain name.
    Note: If your Jamf Pro URL is "https://xxxxxx.jamfcloud.com", enter "xxxxxx".
    ACS URL for service Enter your Jamf Pro subdomain name.

    JamfPro.png

  5. Click the "Register" button to save.

Jamf Pro Settings

  1. Open "Settings (gear icon in the upper right) > Single Sign-On."
    05.png

  2. After clicking "Edit," switch the Single Sign-On Authentication toggle to ON.
    06.png

  3. Configure each item as follows, then click the "Save" button to save.
    Failover Login URL

    This is the URL that allows you to log in with your Jamf Pro ID/password even after SAML SSO is enabled, so copy it and keep it for your records.

    Identity Provider Select "Other..."
    Identity Provider Metadata Source Select "Metadata File," then drag the metadata downloaded from TrustLogin into the dotted box, or upload it by browsing for the file
    Override Token Expiration Specify any time (in minutes) according to your operational needs
    Identity Provider User Mapping Select "NameID"
    Jamf Pro User Mapping Select "Email"
    Identity Provider Group Attribute Name

    Enter "groups"

    Note: Do not check the optional "Enable Single Sign-On for User Enrollment."

    07.png

TrustLogin User Settings

① When a User Adds the App from My Page

  1. On "My Page," click the "Add App" button.
  2. On the "Register App" screen, select "Jamf Pro (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name," enter it, then click the "Register" button.

② When an Administrator Adds Members

  1. In the "Admin Page > Apps" menu, search for and click the "Jamf Pro (SAML)" app.
  2. Click "Add Member," select the user(s) to add from the member list, and click the "Register" button to add them.