Jamf Pro Administrator's Guide Version 10.19.0 © Copyright 2002-2020 Jamf
Total Page:16
File Type:pdf, Size:1020Kb
Jamf Pro Administrator's Guide Version 10.19.0 © copyright 2002-2020 Jamf. All rights reserved. Cisco and IOS are trademarks or registered trademarks of Cisco in the United States and Jamf has made all efforts to ensure that this other countries. guide is accurate. Intel and McAfee Endpoint Protection are either Jamf registered trademarks or trademarks of the Intel 100 Washington Ave S Suite 1100 Corporation in the United States and other Minneapolis, MN 55401-2155 countries. (612) 605-6625 Likewise is a trademark of Likewise Software. Under the copyright laws, this publication may Linux is a registered trademark of Linus Torvalds not be copied, in whole or in part, without the in the United States and other countries. written consent of Jamf. Microsoft, Microsoft Edge, Microsoft Intune, The CASPER SUITE, COMPOSER®, Active Directory, Azure, Excel, OneNote, Outlook, the COMPOSER Logo®, Jamf, the Jamf Logo, PowerPoint, Silverlight, Windows, Windows JAMF SOFTWARE®, the JAMF SOFTWARE Logo®, Server, and all references to Microsoft software RECON®, and the RECON Logo® are registered or are either registered trademarks or trademarks common law trademarks of JAMF SOFTWARE, of Microsoft Corporation in the United States LLC in the U.S. and other countries. and/or other countries. ADmitMac is a registered trademark of Thursby Mozilla and Firefox are registered trademarks of Software Systems, Inc. the Mozilla Foundation. Adobe, Adobe AIR, Adobe Bridge, Adobe NetIQ is a trademark or registered trademark of Premier Pro, Acrobat, After Effects, Creative NetIQ Corporation in the United States. Suite, Dreamweaver, Fireworks, Flash Player, Illustrator, InDesign, Lightroom, Photoshop, Java, MySQL, and all references to Oracle Prelude, Shockwave, and all references to Adobe software are either registered trademarks or software are either registered trademarks or trademarks of Oracle and/or its affiliates. Other trademarks of Adobe Systems Incorporated in names may be trademarks of their respective the United States and/or other countries. owners. Amazon, Amazon CloudFront, Amazon RDS, The Skype name, associated trademarks and Amazon S3, and Amazon Web Services are logos, and the "S" logo are trademarks of Skype trademarks of Amazon.com, Inc. or its affiliates in or related entities. the United States and/or other countries. Sophos is a trademark or registered trademark of Apple, the Apple logo, Apple Configurator 2, Sophos Ltd. Apple Remote Desktop, Apple TV, AirPlay, Finder, FileVault, FireWire, iBeacon, iBooks, iPad, Tomcat is a trademark of the Apache Software iPhone, iPod touch, iTunes, Keychain, Mac, Foundation. MacBook, MacBook Pro, MacBook Air, macOS, OS X, and Safari are trademarks of Apple Inc., Ubuntu is a registered trademark of Canonical registered in the United States and other Ltd. countries. AppleCare, App Store, iBooks Store, All other product and service names mentioned iCloud, and iTunes Store are service marks of herein are either registered trademarks or Apple Inc., registered in the United States and trademarks of their respective companies. other countries. Centrify is a registered trademark of Centrify Corporation in the United States and/or other countries. Chrome and Google are trademarks or registered trademarks of Google Inc. Contents Contents 14 Preface 15 About This Guide 16 Additional Resources 16 Jamf Nation 17 Other Resources 18 Overview of Technologies 19 Applications and Utilities 19 Composer 19 Jamf Admin 19 jamf agent 19 Jamf Application Bundle 20 jamf binary 20 Jamf Helper 20 Jamf Imaging 20 Jamf Management Action 20 Jamf Pro Server 21 Jamf Remote 21 Recon 21 Jamf Self Service for macOS 21 Jamf Self Service for iOS 22 Jamf Pro Server Tools 23 Security 23 Passwords 23 Communication Protocols 23 Public Key Infrastructure 25 Signed Applications 25 Related Information 26 Jamf Pro System Requirements 27 Computer Management Capabilities 27 Management Capabilities for Computers 30 Mobile Device Management Capabilities 30 Management Capabilities for Mobile Devices 34 Management Capabilities for tvOS Devices 35 Related Information 36 Before You Begin 37 Setting Up Jamf Pro 37 Related Information 38 The Jamf Pro Dashboard 39 Adding Items to the Jamf Pro Dashboard 40 Jamf Pro Objects 3 40 Jamf Pro Objects 40 Cloning a Jamf Pro Object 40 Editing a Jamf Pro Object 40 Deleting a Jamf Pro Object 41 Viewing the History of a Jamf Pro Object 42 Jamf Pro System Settings 43 Jamf Pro User Accounts and Groups 43 Requirements 44 Creating a Jamf Pro User Group 44 Creating a Jamf Pro User Account 45 Configuring Account Preferences 45 Configuring the Password Policy 46 Unlocking a Jamf Pro User Account 47 Related Information 48 Integrating with LDAP Directory Services 48 Adding an LDAP Server Using the LDAP Server Assistant 49 Manually Adding an LDAP Server 49 Testing LDAP Attribute Mappings 50 Related Information 51 Integrating with Cloud Identity Providers 51 Adding a Google Identity Provider Instance 53 Testing Cloud Identity Provider Attribute Mappings 53 Related Information 55 Single Sign-On 55 Requirements 55 Single Sign-On Settings 59 Configuring Single Sign-On Settings to Work with an Identity Provider 59 Further Considerations 59 Authentication Using Single Sign-On 61 Single Logout 61 Related Information 62 Integrating with an SMTP Server 62 Configuring the SMTP Server Settings 62 Testing the SMTP Server Settings 63 Related Information 64 Email Notifications 65 Requirements 65 Enabling Email Notifications 65 Related Information 66 Activation Code 66 Updating the Activation Code 67 Change Management 67 Requirements 67 Configuring the Change Management Settings 68 Viewing Change Management Logs in Jamf Pro 4 69 SSL Certificate 69 Requirements 69 Creating or Uploading an SSL Certificate 69 Related Information 70 Flushing Logs 70 Scheduling Log Flushing 71 Manually Flushing Logs 71 Related Information 72 Maintenance Pages 72 Creating a Maintenance Page Configuration 73 Jamf Pro Summary 73 Requirements 74 Viewing the Jamf Pro Summary 74 Sending the Jamf Pro Summary to Jamf 74 Related Information 75 Jamf Pro Server Logs 75 Viewing and Downloading the Jamf Pro Server Log 75 Related Information 76 Jamf Pro Health Check Page 76 Using the Jamf Pro Health Check Page 77 Global Management Settings 78 Push Certificates 78 Requirements 78 Creating a Push Certificate 79 Uploading a Push Certificate (.p12) 79 Renewing the Push Certificate 80 Deleting the Push Certificate 80 Related Information 81 Jamf Push Proxy 81 Requirements 82 Requesting and Uploading a Proxy Server Token 82 Renewing the Proxy Server Token 83 GSX Connection 83 Requirements 83 Configuring the GSX Connection Settings 84 Testing the GSX Connection 84 Renewing the Apple Certificate 85 Related Information 86 Inventory Preload 88 Requirements 88 Example Workflow 88 Validation 89 Users 89 When Data is Applied 5 90 Extension Attributes 90 Further Considerations 90 Uploading a CSV File Using Inventory Preload 90 Viewing and Downloading Active Data 91 Deleting Active Data 92 Viewing Upload History 92 Related Information 93 User-Initiated Enrollment Settings 93 Enrollment of Personally Owned Mobile Devices 94 General Settings 94 Messaging Settings 97 Platform-Specific Settings 98 Access Settings by LDAP Group 98 Configuring the User-Initiated Enrollment Settings 99 Related Information 100 Integrating with Automated Device Enrollment 100 Requirements 100 Downloading a Public Key 100 Obtaining the Server Token File 101 Uploading the Server Token File to Configure Automated Device Enrollment 102 Replacing a Server Token File to Renew an Automated Device Enrollment Instance 102 Further Considerations 103 Related Information 104 Enrollment Customization Settings 104 PreStage Panes 107 Requirements 107 Creating an Enrollment Customization Configuration 108 Further Considerations 109 Related Information 110 Apple Education Support Settings 110 Requirements 110 Shared iPad and Apple's Classroom App Support 111 User Images 112 Related Information 114 Integrating with Apple School Manager 114 Class Naming and Description Format 116 Apple School Manager Sync Time 116 Matching Criteria for Importing Users from Apple School Manager 117 Requirements 117 Configuring an Instance of Apple School Manager 118 Forcing an Apple School Manager Sync 119 Further Considerations 120 Related Information 121 Re-enrollment Settings 6 123 Configuring the Re-enrollment Settings 123 Related Information 124 Jamf Pro URL 124 Viewing or Configuring the Jamf Pro URLs 124 Related Information 125 PKI Certificates 125 Using the Built-in CA 128 Integrating with a Trusted Third-Party CA 133 Integrating with an External CA 136 Related Information 137 Integrating with Volume Purchasing 137 Volume Purchase Location Considerations 138 Managed Distribution Types 139 Requirements 139 Adding a Location 140 Adding Volume Purchasing Notifications 141 Related Information 142 Categories 142 Adding a Category to Jamf Admin 142 Adding a Category to Jamf Pro 143 Editing or Deleting a Category in Jamf Admin 143 Related Information 144 Event Logs 144 Requirements 144 Viewing Event Logs 145 Related Information 146 Webhooks 146 Configuring a Webhook 147 AirPlay Permissions 147 Mobile Device Inventory Field Mapping 147 Requirements 147 Creating an AirPlay Permission 148 Integrating with Microsoft Intune 148 Requirements 149 Manually Configuring the macOS Intune Integration 150 Configuring the macOS Intune Integration using the Cloud Connector 151 Testing the macOS Intune Integration 152 Sending an Update of Inventory to Intune 152 Related