Jamf Pro Administrator's Guide Version 10.26.0 © Copyright 2002-2020 Jamf
Total Page:16
File Type:pdf, Size:1020Kb
Jamf Pro Administrator's Guide Version 10.26.0 © copyright 2002-2020 Jamf. All rights reserved. Cisco and IOS are trademarks or registered trademarks of Cisco in the United States and Jamf has made all efforts to ensure that this other countries. guide is accurate. Intel and McAfee Endpoint Protection are either Jamf registered trademarks or trademarks of the Intel 100 Washington Ave S Suite 1100 Corporation in the United States and other Minneapolis, MN 55401-2155 countries. (612) 605-6625 Likewise is a trademark of Likewise Software. Under the copyright laws, this publication may Linux is a registered trademark of Linus Torvalds not be copied, in whole or in part, without the in the United States and other countries. written consent of Jamf. Microsoft, Microsoft Edge, Microsoft Intune, The CASPER SUITE, COMPOSER®, Active Directory, Azure, Excel, OneNote, Outlook, the COMPOSER Logo®, Jamf, the Jamf Logo, PowerPoint, Silverlight, Windows, Windows JAMF SOFTWARE®, the JAMF SOFTWARE Logo®, Server, and all references to Microsoft software RECON®, and the RECON Logo® are registered or are either registered trademarks or trademarks common law trademarks of JAMF SOFTWARE, of Microsoft Corporation in the United States LLC in the U.S. and other countries. and/or other countries. ADmitMac is a registered trademark of Thursby Mozilla and Firefox are registered trademarks of Software Systems, Inc. the Mozilla Foundation. Adobe, Adobe AIR, Adobe Bridge, Adobe NetIQ is a trademark or registered trademark of Premier Pro, Acrobat, After Effects, Creative NetIQ Corporation in the United States. Suite, Dreamweaver, Fireworks, Flash Player, Illustrator, InDesign, Lightroom, Photoshop, Java, MySQL, and all references to Oracle Prelude, Shockwave, and all references to Adobe software are either registered trademarks or software are either registered trademarks or trademarks of Oracle and/or its affiliates. Other trademarks of Adobe Systems Incorporated in names may be trademarks of their respective the United States and/or other countries. owners. Amazon, Amazon CloudFront, Amazon RDS, The Skype name, associated trademarks and Amazon S3, and Amazon Web Services are logos, and the "S" logo are trademarks of Skype trademarks of Amazon.com, Inc. or its affiliates in or related entities. the United States and/or other countries. Sophos is a trademark or registered trademark of Apple, the Apple logo, Apple Configurator 2, Sophos Ltd. Apple Remote Desktop, Apple TV, AirPlay, Finder, FileVault, FireWire, iBeacon, iBooks, iPad, Tomcat is a trademark of the Apache Software iPhone, iPod touch, iTunes, Keychain, Mac, Foundation. MacBook, MacBook Pro, MacBook Air, macOS, OS X, and Safari are trademarks of Apple Inc., Ubuntu is a registered trademark of Canonical registered in the United States and other Ltd. countries. AppleCare, App Store, iBooks Store, All other product and service names mentioned iCloud, and iTunes Store are service marks of herein are either registered trademarks or Apple Inc., registered in the United States and trademarks of their respective companies. other countries. Centrify is a registered trademark of Centrify Corporation in the United States and/or other countries. Chrome and Google are trademarks or registered trademarks of Google Inc. Contents Contents 13 Preface 14 About This Guide 15 Additional Resources 15 Jamf Nation 16 Other Resources 17 Overview of Technologies 18 Applications and Utilities 18 Administrator Applications 20 Client Applications 22 Utilities 24 Security 24 Passwords 24 Communication Protocols 24 Public Key Infrastructure 26 Signed Applications 26 Related Information 27 Jamf Pro System Requirements 28 Computer Management Capabilities 28 Management Capabilities for Computers 32 Components Installed on Managed Computers 32 Jamf Components Installed on Computers 34 Removing Jamf Components from Computers 36 Mobile Device Management Capabilities 36 Management Capabilities for Mobile Devices 40 Management Capabilities for tvOS Devices 41 Related Information 42 Components Installed on Mobile Devices 43 Before You Begin 44 Setting Up Jamf Pro 44 Related Information 45 The Jamf Pro Dashboard 46 Adding Items to the Jamf Pro Dashboard 47 Jamf Pro Objects 47 Cloning a Jamf Pro Object 47 Editing a Jamf Pro Object 47 Deleting a Jamf Pro Object 47 Viewing the History of a Jamf Pro Object 49 Jamf Pro System Settings 50 Jamf Pro User Accounts and Groups 3 50 Jamf Pro User Accounts and Groups 50 General Requirements 51 Creating a Jamf Pro User Group 51 Creating a Jamf Pro User Account 52 Configuring Account Preferences 52 Configuring the Password Policy 53 Unlocking a Jamf Pro User Account 54 Related Information 55 Integrating with LDAP Directory Services 56 Adding an LDAP Server Using the LDAP Server Assistant 56 Manually Adding an LDAP Server 56 Testing LDAP Attribute Mappings 57 Related Information 59 Integrating with Cloud Identity Providers 59 Adding a Google Identity Provider Instance 60 Testing Cloud Identity Provider Attribute Mappings 61 Related Information 62 Single Sign-On 62 Single Sign-On and LDAP 62 Single Logout 63 Identity Provider Configuration Settings 63 Enabling Single Sign-On in Jamf Pro 66 Related Information 67 Integrating with an SMTP Server 67 Configuring the SMTP Server Settings 67 Testing the SMTP Server Settings 68 Related Information 69 Email Notifications 70 Enabling Email Notifications 71 Related Information 72 Activation Code 72 Updating the Activation Code 73 Change Management 73 General Requirements 73 Configuring the Change Management Settings for On-Premise Environments 74 Viewing Change Management Logs in Jamf Pro 75 SSL Certificate 75 Creating or Uploading an SSL Certificate 75 Related Information 76 Flushing Logs 76 Scheduling Log Flushing 77 Manually Flushing Logs 77 Related Information 78 Maintenance Pages 4 78 Creating a Maintenance Page Configuration 79 Jamf Pro Summary 80 Viewing the Jamf Pro Summary 80 Sending the Jamf Pro Summary to Jamf 80 Related Information 82 Jamf Pro Server Logs 82 Viewing and Downloading the Jamf Pro Server Log 82 Related Information 83 Jamf Pro Health Check Page 83 Using the Jamf Pro Health Check Page 84 Global Management Settings 85 Push Certificates 85 Requirements 85 Creating a Push Certificate 86 Uploading a Push Certificate (.p12) 86 Renewing the Push Certificate 87 Deleting the Push Certificate 87 Related Information 88 Jamf Push Proxy 88 Requirements 89 Requesting and Uploading a Proxy Server Token 89 Renewing the Proxy Server Token 89 Related Information 90 GSX Connection 90 Configuring the GSX Connection Settings 91 Testing the GSX Connection 92 Renewing the Apple Certificate 92 Related Information 94 Inventory Preload 96 Example Workflow 96 Validation 97 Users 97 When Data is Applied 98 Extension Attributes 98 Uploading a CSV File Using Inventory Preload 101 User-Initiated Enrollment Settings 101 Enrollment of Personally Owned Mobile Devices 102 General Requirements 102 Configuring the User-Initiated Enrollment Settings 104 Related Information 105 Integrating with Automated Device Enrollment 105 Downloading a Public Key 105 Obtaining the Server Token File 5 106 Uploading the Server Token File to Configure Automated Device Enrollment 107 Replacing a Server Token File to Renew an Automated Device Enrollment Instance 107 Related Information 109 Enrollment Customization Settings 109 PreStage Panes 112 Settings for Branding 112 General Requirements 113 Creating an Enrollment Customization Configuration 114 Related Information 115 Apple Education Support Settings 115 General Requirements 116 Shared iPad and Apple's Classroom App Support 116 User Images 118 Related Information 119 Integrating with Apple School Manager 119 Class Naming and Description Format 121 Apple School Manager Sync Time 122 Matching Criteria for Importing Users from Apple School Manager 122 Configuring an Instance of Apple School Manager 124 Forcing an Apple School Manager Sync 125 Related Information 126 Re-enrollment Settings 128 General Requirements 128 Configuring the Re-enrollment Settings 128 Related Information 129 Jamf Pro URL 129 Viewing or Configuring the Jamf Pro URLs 129 Related Information 130 MDM Profile Settings 130 Configuring MDM Profile Renewal for Computers or Mobile Devices 131 PKI Certificates 131 Viewing and Exporting Certificates 132 The Built-in CA 135 Third-Party CAs 136 External CAs 138 Related Information 139 Integrating with Volume Purchasing 139 Volume Purchase Location Considerations 140 Adding a Location 141 Adding Volume Purchasing Notifications 142 Related Information 143 Categories 143 Adding a Category to Jamf Admin 6 143 Adding a Category to Jamf Pro 144 Editing or Deleting a Category in Jamf Admin 144 Related Information 145 Event Logs 145 Viewing Event Logs 146 Related Information 147 Webhooks 147 Configuring a Webhook 148 AirPlay Permissions 148 Creating an AirPlay Permission 149 Conditional Access 149 General Requirements 150 Manually Configuring the macOS Intune Integration 151 Configuring the macOS Intune Integration using the Cloud Connector 152 Testing the macOS Intune Integration 153 Sending an Inventory Update to Intune 153 Related Information 154 Cloud Services Connection 154 Icon Service 154 Enabling the Cloud Services Connection 155 Related Information 156 Device Compliance 156 Requirements 157 Procedure 159 Jamf Self Service 160 Jamf Self Service for macOS 160 About Jamf Self Service for macOS 161 Jamf Self Service for macOS Installation Methods 163 Jamf Self Service for macOS User Login Settings 165 Jamf Self Service for macOS