|
Item |
Details |
|
|---|---|---|
|
Prior Confirmation |
|
|
|
Name ID |
〇 |
Email address |
|
Custom attribute Note: For instructions on how to configure a custom attribute, click here |
||
|
SP-side Configuration |
〇 |
Configured by the administrator |
|
Request configuration from the SP |
||
|
Provisioning |
API-based Provisioning supported (account management possible in TrustLogin) |
|
| 〇 |
SAML JIT Provisioning supported (account management possible in TrustLogin; user deletion not supported) |
|
|
|
None (accounts created in each system) |
|
|
Access Method |
〇 |
SP-Initiated SSO |
|
〇 |
IdP-Initiated SSO |
|
|
Verified Operation by Device |
〇 |
PC - Browser |
|
ー |
PC - Desktop App |
|
|
〇 |
iOS - Standard Browser (Safari) |
|
|
〇 |
iOS - TrustLogin Mobile App In-App Browser |
|
|
ー |
iOS - Native App |
|
|
〇 |
Android - Standard Browser (Chrome) |
|
|
〇 |
Android - TrustLogin Mobile App In-App Browser |
|
|
ー |
Android - Native App |
|
Prerequisites
Create a Group and Assign Members
Create a group in TrustLogin with the same name as the Jamf Pro user group, and assign members to it. (If you can operate using an existing group, you may use an existing group instead.)
[Jamf Pro Configuration Example]
[TrustLogin Configuration Example]
- Add users to whom you want to assign the "Administrator" permission in Jamf Pro to the "Administrator" group
- Add users to whom you want to assign the "Enrollment Only" permission in Jamf Pro to the "Enrollment Only" group
For instructions on how to create groups and assign members, please refer to the following page.
Register a Group
Users who do not belong to any of the configured groups will not be able to SSO into Jamf Pro.
TrustLogin Admin Page Settings
-
Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register SAML App" button in the upper right of the screen.
- Register the "Application Name" and "Icon" (optional).
- Download the metadata from the "Download Metadata" button under "Identity Provider Information".
-
Configure "Service Provider Settings" as follows.
Redirect URL after successful SP authentication If you want to redirect to the Jamf Pro profile distribution screen upon SSO login, enter "https://xxxxxx.jamfcloud.com/enroll".
Note: "xxxxxx" is your Jamf Pro subdomain name.
Note: This is an optional setting. If you want to redirect to the dashboard screen, leave this field blank.
Entity ID https://your Jamf Pro subdomain.jamfcloud.com/saml/metadata Name ID Format emailAddress ACS URL to Service https://your Jamf Pro subdomain.jamfcloud.com/saml/SSO
-
Click the "Specify Custom Attribute" button in "SAML Attribute Settings", then add a row (attribute) using the "Add SAML Attribute" button and configure it as follows. For the group attribute value, select the group name from the dropdown; you can add multiple groups using the "+" mark on the right.
Service Provider Attribute TrustLogin (IdP) Attribute Attribute Name Attribute Type Attribute Name Attribute Value NameID Basic NameID Member
Member - Email Address
groups Basic groups Group Select the configured group name and add all of them using the "+" button
- Save by clicking the "Register" button.
Jamf Pro Settings
- Open "Settings (gear icon in the upper right) > Single Sign-On".
- After clicking "Edit", switch the Single Sign-On Authentication toggle to ON.
- Configure each item as follows, and finally save by clicking the "Save" button.
Failover Login URL This is the URL that allows you to log in with your Jamf Pro ID/password even after SAML SSO is enabled, so copy it and keep a record of it.
Identity Provider Select "Other..." Identity Provider Metadata Source Select "Metadata File", and either drag the metadata downloaded from TrustLogin into the dotted-line box or upload it by browsing for the file Override Token Expiration Specify any time (in minutes) according to your operational needs Identity Provider User Mapping Select "NameID" Jamf Pro User Mapping Select "Email" Identity Provider Group Attribute Name Enter "groups"
Options Check "Jamf Pro Single Sign-On (SSO) Options", and also check "Enable Single Sign-On for User-Initiated Enrollment".
TrustLogin User Settings
① When a User Adds the App from My Page
- Click the "Add App" button on "My Page".
- On the "Register App" screen, select the custom SAML app you created, and click the "Next" button in the upper right of the screen.
- If you want to change the "Display Name", enter it and click the "Register" button.
- Click the app on "My Page" or in the "Browser Extension", and confirm that login succeeds.
②When an Administrator Adds Members
- Search for and click the custom SAML app you created in the "Admin Page > App" menu.
- Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.