
- JAMF DISABLE DASHBOARD MAC OS INSTALL
- JAMF DISABLE DASHBOARD MAC OS UPGRADE
- JAMF DISABLE DASHBOARD MAC OS REGISTRATION
Shared-terminal scenarios are not supported: This Device Trust solution doesn't support shared-terminal scenarios in which multiple Okta end users log in to the same account from the same macOS workstation. This limit applies to Okta Preview and Production orgs. This is because the client certificate issued to the device is signed by the CA of a particular org. Put another way, macOS devices can't be secured by the Device Trust configuration of multiple Okta orgs simultaneously. Per-org enrollment limit: A given macOS device can only be secured by the Device Trust configuration of a single Okta org. If you reach the enrollment limit, the Syslog indicates an enrollment failure and the error message Maximum enrollment limit of 5 certificates for a device is reached appears in the JAMF log.
To avoid reaching the unbound certificate limit, ensure that users use the unbound certificates already on the device before you attempt to obtain more certificates through enrollment. As a security precaution, Okta will not issue more than five unbound certificates to a given device. Okta can issue up to five unbound certificates to the device, one each time you perform the enrollment procedure.
Per-device unbound certificate limit: A certificate becomes bound to a given user the first time that user accesses a device trust-secured application from a device trust-secured macOS device. To prevent end users from being prompted for consent when the certificate is used in the authentication flow, Okta allows the following apps.
The webview in which authentication is performed must have access to the Okta Keychain on the device. Webview must have access to the device keychain: Device Trust for managed macOS computers works with any SAML/WS-Fed-enabled app that supports authentication through a webview.
JAMF DISABLE DASHBOARD MAC OS REGISTRATION
(Note: Be aware that disabling syncing blocks all keychain transfers.) See the Add the modified Okta Device Registration Task to Jamf Pro and distribute it to macOS devices.
Prevent iCloud from transferring the Okta keychain to other Apple devices: To prevent iCloud from transferring the Okta keychain from DT-secured macOS devices to other Apple devices, Okta strongly recommends that you create a Configuration Profile in Jamf Pro that disables Allow iCloud Keychain syncing. However, it doesn't work with Microsoft Office thick client version 16.14 (build 180610). For information about securing Office 365 clients that use legacy protocols, see Office 365 Client Access Policies.ĭevice Trust isn't supported with all versions of Microsoft Office thick clients: This Device Trust solution has been tested to work with Microsoft Office thick client versions 16.13.1 and 16.15. For more information, see this Microsoft article. Modern Authentication required for securing Microsoft Office apps: To secure Microsoft Office apps with this Device Trust solution they must be enabled to support Modern Authentication. For this reason, it is recommended to issue certificates only to the devices that require access to secure resources. JAMF DISABLE DASHBOARD MAC OS INSTALL
Install Python 3 and Device Trust dependencies for additional information.ĭevice Trust deployment is not renewed on devices that are not used to access secure applications.
JAMF DISABLE DASHBOARD MAC OS UPGRADE
If you have macOS 10.14.xx (Mojave) and are currently using registration script 1.2.1 or earlier, continue to use it as-is, or upgrade to Catalina, Big Sur, or Monterey before using Python 3. If you have macOS 10.15.xx (Catalina), 11.xx (Big Sur), or 12.xx (Monterey), use registration version 1.3.3 or later, which is based on Python 3.
Depending on your OS, complete one of the following, to make sure you use the appropriate version of this script:
The Okta Device Registration Task is a Python script that completes various tasks (for example, enrollment, and registration). The following browsers and native apps capable of accessing the Okta Keychain on the managed computer when performing the federated authentication flow to Okta:. Apple computers running Supported platforms, browsers, and operating systems of macOS.