Jamf Integration Kit

Configuring an adapter instance

Configure the Jamf IdP Adapter to determine how PingFederate communicates with Jamf Pro.

Steps

  1. In the PingFederate administrative console, create a new IdP adapter instance:

    Choose from:

    • For PingFederate 10.1 or later: go to Authentication → Integration → IdP Adapters. Click Create New Instance.

    • For PingFederate 10.0 or earlier: go to Identity Provider → Adapters. Click Create New Instance.

  2. On the Type tab, set the basic adapter instance attributes.

    1. In the Instance Name field, enter a name for the adapter instance.

    2. In the Instance ID field, enter a unique identifier for the adapter instance.

    3. From the Type list, select Jamf IdP Adapter. Click Next.

  3. Optional: On the IdP Adapter tab, in the Jamf API Response Mappings section, map attributes from the Jamf Pro response to the attribute contract. These attributes become available in your PingFederate authentication policy.

    If you use Computer Extension Attributes or Mobile Device Extension Attributes in Jamf Pro, use this table to include your extension attributes in the PingFederate attribute contract.

    The isManaged and isMDMCapable attributes are already included in the core contract.

    1. Click Add a new row to 'Jamf API Response Mappings'.

    2. In the Local Attribute field, enter a name for the new attribute.

    3. In the Jamf API Response Mapping field, enter the JSON Pointer syntax for the value of the matching PingOne Verify attribute. For help, see JSON Pointer syntax reference.

    4. In the Action column, click Update.

    5. To add more attributes, repeat steps a-d.

  4. On the IdP Adapter tab, configure the adapter instance by referring to Jamf IdP Adapter settings reference. Click Next.

  5. On the Actions tab, test your connection to Jamf Pro. Resolve any issues that are reported, and then click Next.

  6. On the Extended Contract tab, add any local attributes that mapped in the the Jamf API Attribute Mappings section. Click Next.

  7. On the Adapter Attributes tab, set pseudonym and masking options as shown in Set pseudonym and masking options in the PingFederate documentation. Click Next.

  8. On the Adapter Contract Mapping tab, configure the contract fulfillment details for the adapter as shown in Define the IdP adapter contract in the PingFederate documentation. Click Next.

  9. On the Summary tab, check and save your configuration:

    Choose from:

    • For PingFederate 10.1 or later: click Save.

    • For PingFederate 10.0 or earlier: click Done. On the Manage IdP Adapter Instances tab, click Save.