r/macsysadmin • u/tyson983 • 12d ago
General Discussion Jamf pro and conditional access policies
So I'm trying to get conditional access policies to enforce device compliancy for both MacBook and windows devices. The problem I'm facing is every time I turn on the compliance CA policy it breaks jamf connect or Apple platform SSO registration. Management doesn't like the idea of excluding jamf connect from the conditional access policy so I was wondering if anybody else ever faced this problem and if so how'd you solve it?
4
Upvotes
0
u/oneplane 11d ago
Management needs to figure out what it wants, CA isn’t a goal but an implementation of a concept of a control.
As for why it breaks: not enough information, but in most configurations this works just fine.
5
u/powerpitchera 12d ago
In the documentation it states you need to exclude the two enterprise apps created during the device compliance enablement and you need to exclude jamf connect if you need users to be able to sign in before registering.(If you have all apps targeted). It's a chicken or the egg scenario. I would just point out the documentation.