Jamf Pro SAML JIT Setup Guide

Item

Details

Prior Confirmation

  • Prior configuration in Jamf Pro is required.

  • If a user not yet registered in Jamf Pro logs in via SAML JIT, authentication will succeed, but the user will not be created in Jamf Pro.
  • If a user already registered in Jamf Pro has their group changed in TrustLogin, this will not be reflected in their permissions in Jamf Pro.
  • For the latest setup instructions, please check the manual provided by Jamf Pro.

Name ID

Email address

Custom attribute Note: For instructions on how to configure a custom attribute, click here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

API-based Provisioning supported (account management possible in TrustLogin)

SAML JIT Provisioning supported (account management possible in TrustLogin; user deletion not supported)
Note: For setup instructions when provisioning is not required, see here

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

Prerequisites

Create a Group and Assign Members

Create a group in TrustLogin with the same name as the Jamf Pro user group, and assign members to it. (If you can operate using an existing group, you may use an existing group instead.)

[Jamf Pro Configuration Example]

00.png

[TrustLogin Configuration Example]

  • Add users to whom you want to assign the "Administrator" permission in Jamf Pro to the "Administrator" group
  • Add users to whom you want to assign the "Enrollment Only" permission in Jamf Pro to the "Enrollment Only" group

002.png

For instructions on how to create groups and assign members, please refer to the following page.
Register a Group

Users who do not belong to any of the configured groups will not be able to SSO into Jamf Pro.


TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register SAML App" button in the upper right of the screen.
    jit01.png

  2. Register the "Application Name" and "Icon" (optional).
    JamfPro02.png

  3. Download the metadata from the "Download Metadata" button under "Identity Provider Information".
    03.png
  4. Configure "Service Provider Settings" as follows.
    Redirect URL after successful SP authentication

    If you want to redirect to the Jamf Pro profile distribution screen upon SSO login, enter "https://xxxxxx.jamfcloud.com/enroll".

    Note: "xxxxxx" is your Jamf Pro subdomain name.

    Note: This is an optional setting. If you want to redirect to the dashboard screen, leave this field blank.

    Entity ID https://your Jamf Pro subdomain.jamfcloud.com/saml/metadata
    Name ID Format emailAddress
    ACS URL to Service https://your Jamf Pro subdomain.jamfcloud.com/saml/SSO

    jit04__1_.png

  5. Click the "Specify Custom Attribute" button in "SAML Attribute Settings", then add a row (attribute) using the "Add SAML Attribute" button and configure it as follows. For the group attribute value, select the group name from the dropdown; you can add multiple groups using the "+" mark on the right.
    Service Provider Attribute TrustLogin (IdP) Attribute
    Attribute Name Attribute Type Attribute Name Attribute Value
    NameID Basic NameID

    Member

    Member - Email Address

    groups Basic groups Group Select the configured group name and add all of them using the "+" button

    jit05.png

  6. Save by clicking the "Register" button.

Jamf Pro Settings

  1. Open "Settings (gear icon in the upper right) > Single Sign-On".
    05.png

  2. After clicking "Edit", switch the Single Sign-On Authentication toggle to ON.
    06.png

  3. Configure each item as follows, and finally save by clicking the "Save" button.
    Failover Login URL

    This is the URL that allows you to log in with your Jamf Pro ID/password even after SAML SSO is enabled, so copy it and keep a record of it.

    Identity Provider Select "Other..."
    Identity Provider Metadata Source Select "Metadata File", and either drag the metadata downloaded from TrustLogin into the dotted-line box or upload it by browsing for the file
    Override Token Expiration Specify any time (in minutes) according to your operational needs
    Identity Provider User Mapping Select "NameID"
    Jamf Pro User Mapping Select "Email"
    Identity Provider Group Attribute Name

    Enter "groups"

    Options

    Check "Jamf Pro Single Sign-On (SSO) Options", and also check "Enable Single Sign-On for User-Initiated Enrollment".


    jit07.png

TrustLogin User Settings

① When a User Adds the App from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select the custom SAML app you created, and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Register" button.
  4. Click the app on "My Page" or in the "Browser Extension", and confirm that login succeeds.

②When an Administrator Adds Members

  1. Search for and click the custom SAML app you created in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

Jamf Pro SAML JIT Setup Guide

Item

Details

Prior Confirmation

  • Prior configuration in Jamf Pro is required.

  • If a user not yet registered in Jamf Pro logs in via SAML JIT, authentication will succeed, but the user will not be created in Jamf Pro.
  • If a user already registered in Jamf Pro has their group changed in TrustLogin, this will not be reflected in their permissions in Jamf Pro.
  • For the latest setup instructions, please check the manual provided by Jamf Pro.

Name ID

Email address

Custom attribute Note: For instructions on how to configure a custom attribute, click here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

API-based Provisioning supported (account management possible in TrustLogin)

SAML JIT Provisioning supported (account management possible in TrustLogin; user deletion not supported)
Note: For setup instructions when provisioning is not required, see here

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

Prerequisites

Create a Group and Assign Members

Create a group in TrustLogin with the same name as the Jamf Pro user group, and assign members to it. (If you can operate using an existing group, you may use an existing group instead.)

[Jamf Pro Configuration Example]

00.png

[TrustLogin Configuration Example]

  • Add users to whom you want to assign the "Administrator" permission in Jamf Pro to the "Administrator" group
  • Add users to whom you want to assign the "Enrollment Only" permission in Jamf Pro to the "Enrollment Only" group

002.png

For instructions on how to create groups and assign members, please refer to the following page.
Register a Group

Users who do not belong to any of the configured groups will not be able to SSO into Jamf Pro.


TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register SAML App" button in the upper right of the screen.
    jit01.png

  2. Register the "Application Name" and "Icon" (optional).
    JamfPro02.png

  3. Download the metadata from the "Download Metadata" button under "Identity Provider Information".
    03.png
  4. Configure "Service Provider Settings" as follows.
    Redirect URL after successful SP authentication

    If you want to redirect to the Jamf Pro profile distribution screen upon SSO login, enter "https://xxxxxx.jamfcloud.com/enroll".

    Note: "xxxxxx" is your Jamf Pro subdomain name.

    Note: This is an optional setting. If you want to redirect to the dashboard screen, leave this field blank.

    Entity ID https://your Jamf Pro subdomain.jamfcloud.com/saml/metadata
    Name ID Format emailAddress
    ACS URL to Service https://your Jamf Pro subdomain.jamfcloud.com/saml/SSO

    jit04__1_.png

  5. Click the "Specify Custom Attribute" button in "SAML Attribute Settings", then add a row (attribute) using the "Add SAML Attribute" button and configure it as follows. For the group attribute value, select the group name from the dropdown; you can add multiple groups using the "+" mark on the right.
    Service Provider Attribute TrustLogin (IdP) Attribute
    Attribute Name Attribute Type Attribute Name Attribute Value
    NameID Basic NameID

    Member

    Member - Email Address

    groups Basic groups Group Select the configured group name and add all of them using the "+" button

    jit05.png

  6. Save by clicking the "Register" button.

Jamf Pro Settings

  1. Open "Settings (gear icon in the upper right) > Single Sign-On".
    05.png

  2. After clicking "Edit", switch the Single Sign-On Authentication toggle to ON.
    06.png

  3. Configure each item as follows, and finally save by clicking the "Save" button.
    Failover Login URL

    This is the URL that allows you to log in with your Jamf Pro ID/password even after SAML SSO is enabled, so copy it and keep a record of it.

    Identity Provider Select "Other..."
    Identity Provider Metadata Source Select "Metadata File", and either drag the metadata downloaded from TrustLogin into the dotted-line box or upload it by browsing for the file
    Override Token Expiration Specify any time (in minutes) according to your operational needs
    Identity Provider User Mapping Select "NameID"
    Jamf Pro User Mapping Select "Email"
    Identity Provider Group Attribute Name

    Enter "groups"

    Options

    Check "Jamf Pro Single Sign-On (SSO) Options", and also check "Enable Single Sign-On for User-Initiated Enrollment".


    jit07.png

TrustLogin User Settings

① When a User Adds the App from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select the custom SAML app you created, and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Register" button.
  4. Click the app on "My Page" or in the "Browser Extension", and confirm that login succeeds.

②When an Administrator Adds Members

  1. Search for and click the custom SAML app you created in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.