Jamf Concepts
Handleidingen

Handleidingen

Simplified Setup: Identity First and Device First

~6 min read
Was dit nuttig?

Simplified Setup requires Platform SSO registration in Setup Assistant during Automated Device Enrollment on macOS 26 or later. It can also create the first local account from the user's IdP identity. Jamf Pro offers two workflow methods for Simplified Setup. Choose one in the PreStage enrollment with the Set workflow method setting.

Current name Former name Available since
Identity first Attended Jamf Pro 11.29
Device first Unattended Jamf Pro 11.20

The Jamf Pro 11.29 release notes introduced the names "attended" and "unattended." Jamf now uses "identity first" and "device first." The workflows did not change, only the names. The new names describe what happens first: the user's identity, or the device's enrollment. Both workflows require the user to sign in to the IdP in Setup Assistant.

How Each Workflow Works

Identity First

The IdP app and the Platform SSO profile install before enrollment. The user must register with the IdP before the Mac can enroll with Jamf Pro.

  1. Setup Assistant contacts Jamf Pro to enroll.
  2. Jamf Pro responds that Platform SSO registration is required.
  3. The Mac downloads and installs the IdP app and the Platform SSO profile.
  4. The user signs in to the IdP and completes MFA.
  5. Platform SSO registration completes, and macOS creates the first local account from the IdP identity.
  6. Enrollment with Jamf Pro completes.

Device First

Enrollment with Jamf Pro completes first. Setup Assistant then holds the Mac at Platform SSO registration until the user registers.

  1. Setup Assistant enrolls the Mac with Jamf Pro, including any enrollment customization.
  2. Jamf Pro installs the enrollment packages, including the IdP app, and the Platform SSO profile.
  3. Setup Assistant holds the Mac at Platform SSO registration.
  4. The user signs in to the IdP and completes MFA.
  5. Platform SSO registration completes, and macOS creates the first local account from the IdP identity.

Compare the Workflows

Identity first Device first
When the Platform SSO profile installs Before enrollment During enrollment
What gates enrollment IdP registration Nothing. Registration happens after enrollment
Minimum Jamf Pro version 11.29 (11.32.1 or later recommended) 11.20
How the IdP app installs Jamf Pro delivers it before enrollment. No enrollment package needed. Add the IdP app package to Enrollment Packages
Platform Single Sign-on App Bundle ID field Not used Required, such as com.okta.mobile or com.microsoft.CompanyPortalMac
Enrollment customization Not supported Supported
Dynamic SCEP challenges Not supported Supported
SAML SSO configured in Jamf Pro Required Not required
User sign-ins in Setup Assistant One. IdP registration replaces the enrollment sign-in. Two when you also use an enrollment customization with SSO
Unattended registration Not available Available if your IdP supports it

Choose a Workflow

Use identity first when you want IdP authentication to gate enrollment, when you want one fewer sign-in in Setup Assistant, and when you do not need an enrollment customization or dynamic SCEP challenges.

Use device first when you need an enrollment customization, when your Okta deployment uses dynamic SCEP challenges, when your IdP supports only this workflow, or when your IdP supports unattended registration.

IdP Identity first Device first
Microsoft Entra ID Supported. See the known issue on device compliance. Supported
Okta Supported. Dynamic SCEP is not supported, and reports of static SCEP failures are under investigation. Supported. Recommended for Okta Device Access SCEP.
Ping Identity Not yet tested by Ping as of June 2026 Supported

Configure Simplified Setup in Jamf Pro

Before you begin

  • Configure the Platform SSO profile with Enable Registration During Setup enabled. To create the first account, also enable Create First User During Setup.
  • For identity first, configure SAML SSO in Jamf Pro.
  • For Microsoft Entra ID, use Company Portal 5.2604.0 or later. For Okta, use Okta Verify 9.52 or later.

Steps

  1. In Jamf Pro, go to Computers > PreStage Enrollments, and create or edit a PreStage enrollment.
  2. In the General payload, select Enable Simplified Setup for Platform Single Sign-on (macOS 26 or later).
  3. Set Set workflow method to Identity first or Device first.
  4. Set Minimum required macOS version to 26.0 or later.
  5. Complete the settings for your workflow:
    • Identity first: Select the Platform SSO profile in the PreStage enrollment. Do not add an enrollment customization.
    • Device first: Set Platform Single Sign-on App Bundle ID, and add the IdP app package to Enrollment Packages.
  6. In Account Settings, do not select Do Not Create Local Accounts. Simplified Setup creates the first account at the account creation step in Setup Assistant.
  7. In Configuration Profiles, include the Platform SSO profile and any SCEP profile your IdP requires.
  8. Click Save.

Verify the Result

  1. Enroll a test Mac with the PreStage enrollment.
  2. Confirm that Setup Assistant prompts for IdP sign-in at the expected point: before enrollment for identity first, and after enrollment for device first.
  3. At the desktop, run app-sso platform -s. Confirm that createFirstUserDuringSetupEnabled is true and that the user configuration is populated. A (null) user configuration after successful device registration points to the credential handoff, such as the authentication method or MFA, rather than the profile.

Known Issues

Issue Workaround
Microsoft Entra ID does not show the Mac as compliant after identity first enrollment Have the user click Repair in System Settings > Users & Groups > Network Account Server, or use device first.
The first account is not created with the Secure Enclave key method and Microsoft Entra ID Use the Password new user authentication method for first account creation. Microsoft is investigating.
Account creation fails when Entra ID per-user MFA is set to Enforced Require MFA with a Conditional Access policy instead of per-user MFA.
Okta SCEP certificates fail with identity first Use device first with dynamic SCEP until Jamf and Okta resolve the issue.
409 "Ambiguous SSO provider" error with identity first Update to Jamf Pro 11.32.1 or later.
Account creation conflicts when Jamf Connect runs in Jamf Setup Manager Remove Jamf Connect from the Setup Manager workflow for Macs that use Simplified Setup.

Resources

Was dit nuttig?