Jamf Pro Server
Total Page:16
File Type:pdf, Size:1020Kb
Jamf Pro Administrator's Guide Version 10.1.0 © copyright 2002-2017 Jamf. All rights reserved. Divide is a trademark or registered trademark of Divide, Inc. Jamf has made all efforts to ensure that this guide is accurate. eDirectory is a trademark of Novell, Inc. in the United States and other countries. Jamf 100 Washington Ave S Suite 1100 Google, Android, Google Chrome, and Google Minneapolis, MN 55401-2155 Play are trademarks or registered trademarks of (612) 605-6625 Google Inc. Intel and McAfee Endpoint Protection are either Under the copyright laws, this publication may registered trademarks or trademarks of the Intel not be copied, in whole or in part, without the Corporation in the United States and other written consent of Jamf. countries. The CASPER SUITE, COMPOSER®, Likewise is a trademark of Likewise Software. the COMPOSER Logo®, Jamf, the Jamf Logo, JAMF SOFTWARE®, the JAMF SOFTWARE Logo®, Linux is a registered trademark of Linus Torvalds RECON®, and the RECON Logo® are registered or in the United States and other countries. common law trademarks of JAMF SOFTWARE, LLC in the U.S. and other countries. Microsoft, Microsoft Intune, Active Directory, Azure, Excel, OneNote, Outlook, PowerPoint, ADmitMac is a registered trademark of Thursby Silverlight, Windows, Windows Server, and all Software Systems, Inc. references to Microsoft software are either registered trademarks or trademarks of Adobe, Adobe AIR, Adobe Bridge, Adobe Microsoft Corporation in the United States Premier Pro, Acrobat, After Effects, Creative and/or other countries. Suite, Dreamweaver, Fireworks, Flash Player, Illustrator, InDesign, Lightroom, Photoshop, Mozilla and Firefox are registered trademarks of Prelude, Shockwave, and all references to Adobe the Mozilla Foundation. software are either registered trademarks or trademarks of Adobe Systems Incorporated in Java, MySQL, and all references to Oracle the United States and/or other countries. software are either registered trademarks or trademarks of Oracle and/or its affiliates. Other Apple, the Apple logo, Apple Configurator 2, names may be trademarks of their respective Apple Remote Desktop, Apple TV, AirPlay, owners. Finder, FileVault, FireWire, iBeacon, iBooks, iPad, iPhone, iPod touch, iTunes, Keychain, Mac, The Skype name, associated trademarks and MacBook, MacBook Pro, MacBook Air, macOS, logos, and the "S" logo are trademarks of Skype OS X, and Safari are trademarks of Apple Inc., or related entities. registered in the United States and other countries. Apple Care, App Store, iBooks Store, Sophos is a trademark or registered trademark of iCloud, and iTunes Store are service marks of Sophos Ltd. Apple Inc., registered in the United States and Tomcat is a trademark of the Apache Software other countries. Foundation. Centrify is a registered trademark of Centrify Ubuntu is a registered trademark of Canonical Corporation in the United States Ltd. and/or other countries. All other product and service names mentioned Cisco and IOS are trademarks or registered herein are either registered trademarks or trademarks of Cisco in the United States and trademarks of their respective companies. other countries. Contents Contents 13 Preface 14 About This Guide 15 Additional Resources 15 Jamf Nation 16 Other Resources 17 Overview of Technologies 18 Applications and Utilities 18 Composer 18 Jamf Admin 18 jamf agent 18 jamf binary 18 Jamf Helper 18 Jamf Imaging 19 Jamf Management Action 19 Jamf Pro Server 19 Jamf Remote 19 Recon 19 Jamf Self Service for macOS 20 Self Service Mobile for iOS 20 Self Service Mobile for Android 21 Security 21 Passwords 21 Communication Protocols 22 Public Key Infrastructure 23 Signed Applications 23 Related Information 24 Requirements 24 Jamf Pro Server 25 Package Building 25 Inventory 26 Imaging 26 Remote Management 27 Jamf Self Service for macOS 27 Managing Mobile Devices 27 Casper Focus 28 Self Service Mobile for iOS 29 Computer Management Capabilities 29 Management Capabilities for Computers 33 Mobile Device Management Capabilities 3 33 Management Capabilities for Institutionally Owned Devices 36 Management Capabilities for Personally Owned Devices 38 Management Capabilities for Apple TV 40 Before You Begin 41 Setting Up Jamf Pro 41 Related Information 42 The Jamf Pro Dashboard 42 Adding Items to the Jamf Pro Dashboard 44 Jamf Pro Objects 44 Cloning a Jamf Pro Object 44 Editing a Jamf Pro Object 44 Deleting a Jamf Pro Object 45 Viewing the History of a Jamf Pro Object 46 Jamf Pro System Settings 47 Jamf Pro User Accounts and Groups 47 Requirements 47 Creating a Jamf Pro User Group 48 Creating a Jamf Pro User Account 49 Configuring Account Preferences 49 Configuring the Password Policy 50 Unlocking a Jamf Pro User Account 50 Related Information 51 Integrating with LDAP Directory Services 51 Adding an LDAP Server Using the LDAP Server Assistant 52 Manually Adding an LDAP Server 52 Testing LDAP Attribute Mappings 52 Related Information 54 Single Sign-On 54 Identity Providers 54 Single Sign-On Settings 56 Authentication Using Single Sign-On 58 Single Logout 58 Requirements 58 Configuring Single Sign-On Settings to Work with an Identity Provider 59 Further Considerations 59 Related Information 60 Integrating with an SMTP Server 60 Configuring the SMTP Server Settings 60 Testing the SMTP Server Settings 61 Related Information 62 Email Notifications 62 Requirements 63 Enabling Email Notifications 63 Related Information 4 64 Activation Code 64 Updating the Activation Code 65 Change Management 65 Requirements 65 Configuring the Change Management Settings 66 Viewing Change Management Logs in Jamf Pro 66 Related Information 67 SSL Certificate 67 Requirements 67 Creating or Uploading an SSL Certificate 67 Related Information 68 Flushing Logs 68 Scheduling Log Flushing 69 Manually Flushing Logs 69 Related Information 70 Maintenance Pages 70 Creating a Maintenance Page Configuration 71 Jamf Pro Summary 71 Requirements 72 Viewing the Jamf Pro Summary 72 Sending the Jamf Pro Summary to Jamf 72 Related Information 73 Jamf Pro Server Logs 73 Viewing and Downloading the Jamf Pro Server Log 73 Related Information 74 Jamf Pro Health Check Page 74 Using the Jamf Pro Health Check Page 75 Global Management Settings 76 Push Certificates 76 Requirements 76 Creating a Push Certificate 77 Uploading a Push Certificate (.p12) 77 Renewing the Push Certificate 78 Deleting the Push Certificate 78 Related Information 79 Jamf Push Proxy 79 Requirements 79 Requesting and Uploading a Proxy Server Token 80 Renewing the Proxy Server Token 81 Integrating with GSX 81 Requirements 81 Configuring the GSX Connection Settings 82 Testing the GSX Connection 82 Renewing the Apple Certificate 5 83 Related Information 84 User-Initiated Enrollment Settings 85 Customizing the User-Initiated Enrollment Experience 86 Configuring the User-Initiated Enrollment Settings 87 Related Information 88 Integrating with the Device Enrollment Program 88 Requirements 88 Downloading a Public Key 89 Obtaining the Server Token File 89 Uploading the Server Token File to Configure an Instance of DEP 90 Refreshing DEP Instance Information 90 Further Considerations 90 Related Information 92 Re-enrollment Settings 93 Configuring the Re-enrollment Settings 94 Related Information 95 Jamf Pro URL 95 Viewing or Configuring the Jamf Pro URLs 95 Related Information 96 PKI Certificates 96 Using the Built-in CA 99 Integrating with a Symantec CA 101 Integrating with an External CA 104 Related Information 105 Integrating with VPP 105 VPP Accounts Considerations 106 VPP-Managed Distribution Types 107 Requirements 107 Adding a VPP Account 108 VPP Accounts Notifications 108 Related Information 109 Categories 109 Adding a Category to Jamf Admin 109 Adding a Category to Jamf Pro 110 Editing or Deleting a Category in Jamf Admin 110 Related Information 111 Event Logs 111 Requirements 111 Viewing Event Logs 112 Related Information 113 Webhooks 113 Configuring a Webhook 114 AirPlay Permissions 114 Mobile Device Inventory Field Mapping 114 Requirements 6 114 Creating an AirPlay Permission 115 Microsoft Intune Integration 115 Requirements 115 Configuring Microsoft Intune Integration Settings 116 Testing the Microsoft Intune Integration 117 Server Infrastructure 118 About Distribution Points 120 Related Information 121 File Share Distribution Points 121 Adding a File Share Distribution Point 121 Replicating Files to a File Share Distribution Point 122 Related Information 123 Cloud Distribution Point 123 Requirements 124 Configuring the Cloud Distribution Point 124 Testing the Cloud Distribution Point 125 Replicating Files to the Cloud Distribution Point 125 Related Information 126 Jamf Distribution Server Instances 126 Configuring a JDS Instance 127 Replicating Files to the Root JDS Instance 127 Viewing the Progress of File Replication 127 Viewing Inventory Information for a JDS Instance 128 Related Information 129 Software Update Servers 129 Adding a Software Update Server 129 Related Information 130 NetBoot Servers 130 Adding a NetBoot Server 130 Related Information 131 Jamf Infrastructure Manager Instances 131 Viewing Inventory Information for a Jamf Infrastructure Manager Instance 131 Further Considerations 132 Related Information 133 Healthcare Listener 133 Healthcare Listener Rules 135 Requirements 135 Setting up the Healthcare Listener 136 Adding a Healthcare Listener Rule 137 Further Considerations 137 Related Information 138 LDAP Proxy 138 Network Communication 138 Requirements 7 139 Configuring the LDAP Proxy 140 Organizing Your Network 141 Buildings