Skip to main content

Create a Smart Group in Jamf Pro for LDAP Group Attributes

Updated over 2 weeks ago

Description

This article provides steps for creating a Jamf Pro Smart Group for device level scoping to directory group as an alternate to using limitations.

Pre-requisites:

  • Have LDAP or cloud IdP configured in Jamf Pro

  • Have LDAP or cloud IdP user assigned to device or computer

Creating a Smart Group with LDAP Attributes

  1. Check the box to collect user and location information in Jamf Pro under Settings > Computer management > Inventory collection.

  2. Go to Settings > Computer management > Extension attributes or Settings > Device management > Extension attributes and click +New.

  3. Configure display name and add a Description and Inventory Display if desired.

  4. In the Input Type dropdown select Directory service attribute mapping.

  5. Add the Directory Service Attribute in the box.

    • If wanting to gather groups the 'memberOf' attribute is usually the one to use but it may be different depending on the directory service provider. The 'memberOf' attribute would yield multiple values so check the box to allow multiple attribute values.

    • Please note that depending on the size and complexity of the environment, this could result in a lot of data being added to device records, some directory service providers might also have data caps that this could affect.

  6. Build a smart group that would be looking for groups that the director service user would be a part of.


Did this answer your question?