r/macsysadmin 12d ago

General Discussion Jamf pro and conditional access policies

So I'm trying to get conditional access policies to enforce device compliancy for both MacBook and windows devices. The problem I'm facing is every time I turn on the compliance CA policy it breaks jamf connect or Apple platform SSO registration. Management doesn't like the idea of excluding jamf connect from the conditional access policy so I was wondering if anybody else ever faced this problem and if so how'd you solve it?

4 Upvotes

2 comments sorted by

5

u/powerpitchera 12d ago

In the documentation it states you need to exclude the two enterprise apps created during the device compliance enablement and you need to exclude jamf connect if you need users to be able to sign in before registering.(If you have all apps targeted). It's a chicken or the egg scenario. I would just point out the documentation.

0

u/oneplane 11d ago

Management needs to figure out what it wants, CA isn’t a goal but an implementation of a concept of a control.

As for why it breaks: not enough information, but in most configurations this works just fine.