Our Story

Who we are and how we solve complex IT challenges.

Our Certifications

Microsoft certifications and partnerships validating our technical expertise.

Leadership

Meet the Experienced Leadership Team Driving WME’s Success

Advisory Updates

Expert guidance on Microsoft, security, and compliance developments.

Case Studies

Real-world outcomes from complex Microsoft-focused IT engagements.

Financial Industry

Secure technology solutions for regulated banks and financial institutions.

Healthcare

Secure Microsoft solutions for compliant, connected, and modern healthcare organizations.

Manufacturing

Cloud and security solutions supporting modern manufacturing operations.

Non-Profit

Cost-efficient Microsoft solutions for mission-driven organizations.

Public Sector

Microsoft-based IT services for secure public sector modernization.

High Tech

Scalable cloud, security, and staffing for fast-growing technology companies.

SMBs

Scalable cloud, security, and staffing for fast-growing technology companies.

Cloud Migration Services

Transition your workloads to the cloud securely for greater scalability and performance.

Data Migration Services

Securely transfer your business data with minimal downtime and maximum integrity.

Application Migration Services

Move your applications seamlessly to modern platforms with minimal business disruption.

Identity & Security Migration Services

Strengthen identity management and security while transitioning to modern Microsoft solutions.

IT Staffing

Connect with skilled IT professionals to strengthen your team and accelerate project delivery.

Accounting & Finance

Connect with experienced accounting and finance professionals to support your business goals.

Licensing Support

Discover the benefits of both CSP and On-premises licensing options and find the best fit for your unique business needs. From cost savings to flexibility, we’ve got you covered.

Power Platform

Unlock the full potential of the Microsoft Power Platform Suite to streamline operations, automate repetitive tasks, and gain real-time insights that drive business growth.

Sharepoint Solutions

Supercharge your business productivity and enhance visibility through our proven SharePoint expertise.

Security Solutions

Protect your business with proactive cybersecurity, compliance, and risk management solutions.

Endpoint Management

Secure, manage, and monitor every device with modern endpoint management solutions.

Integrate Jamf Pro with Entra ID Conditional Access

October 30, 2025

A lot of organizations use Jamf Pro to manage their Apple devices. Let’s face it, Jamf is just better at managing Apple devices than Intune. That isn’t to say that Intune doesn’t do a good job, but Jamf is just better at it. Apple device adoption is growing rapidly within enterprises, as evidenced by Apple’s investment in technologies such as platform SSO. We are seeing more companies invest in an Apple-first management platform like Jamf to provide the same level of management that is available on Windows from tools like ConfigMgr and Intune.

For organizations that rely on endpoint management services this integration strengthens unified device compliance and security across both Apple and Windows ecosystems.

This blog post will walk you through the benefits of integrating the two so that you can use device state information from Jamf to determine compliance for Entra ID Conditional Access (CA). In essence, this allows a lot of the same conceptual behavior that you get from compliance policies within Intune.

How Does the Integration Work?

Jamf uses the Partner Compliance Management API to send compliance state to Intune, which then sends the compliance state to Entra ID. The device never shows up in Intune – it only shows up in Entra ID as a registered device object with a compliance state.

Smart Groups

Jamf evaluates compliance based on two smart groups. The first smart group (called the applicable group in Jamf’s documentation) should be all devices that are eligible to access the resources protected by Entra ID Conditional Access. For most environments, this is probably all devices, but you might split out personal devices if you allow those to be enrolled into your Jamf environment.

The second smart group (called the compliance group in Jamf’s documentation) has criteria set to match your compliance settings, such as operating system version, FileVault status, security patch level, or any other criteria for smart groups. If the computer is in this group, it is marked as compliant. If the computer is in the Applicable Group, but not in this group, it marked as non-compliant.

Just as hint, one of the criteria for the compliance group should be membership in the applicable group.

Configuration

During the configuration of device compliance in Jamf, you will provide the two smart groups discussed above. Once this is configured, you will configure a partner connection in Intune. This will require the creation of an Entra ID app registration. This app will need admin consent granted for the Intune API permission update_device_attributes and the Graph API permission Application.Read.All. These are application permissions.

Once the compliance configuration is set up, you can now use the compliance data in conditional access policies to restrict or grant access to resource control by Entra ID. If the Apple device falls out of the compliance group, it will be automatically marked as non-compliant by Entra ID and the CA policy will prevent access from that device.

You can read all the details for setting up the integration here: View Details

Final Thoughts

Integrating Jamf Pro with Entra ID Conditional Access gives organizations the best of both worlds: Apple-first management with Jamf and enterprise-wide compliance enforcement. By leveraging Jamf’s smart groups to define compliance and Intune’s Partner Compliance Management API to share that state, you can enforce zero-trust principles without compromising the Apple user experience.

Configuring this integration, especially when managed under comprehensive endpoint management services ensures that only trusted users on compliant devices gain access to sensitive resources, while still allowing you to manage Apple devices with the depth and precision Jamf provides.

As Apple adoption continues to grow in the enterprise, the partnership between Jamf and Microsoft will remain a cornerstone for organizations that want to balance user choice with strong security.

Start your hybrid management strategy

with a free consultation.

Talk to our experts

Share:

Facebook
Twitter
LinkedIn

Get Microsoft Updates Before They Cost You Downtime

Retirement dates, licensing changes, and security updates from a Microsoft-exclusive team, sent when they matter, not on a filler schedule.

More Posts

Copilot Cowork: Credit-Based Billing

Until now, Copilot Cowork has been included with M365 Copilot Premium licenses. Now that Cowork has moved out of public preview, Cowork is introducing a ...
Read Full Article
SharePoint OTP Retirement Is Coming in July 2026

SharePoint OTP Retirement Is Coming in July 2026 — What IT Admins Need to Do Before Access Breaks

Starting July 2026, external users who access OneDrive and SharePoint files through legacy SPO OTP links will start receiving access denied — silently, with no ...
Read Full Article
Power Virtual Agents Is Gone. Here's What Replaced It and Why It Matters.

Power Virtual Agents Is Gone. Here’s What Replaced It and Why It Matters.

If someone on your team still calls it “Power Virtual Agents,” they’re working from an outdated map. Microsoft retired the product on November 15, 2023 ...
Read Full Article

Get Microsoft Updates Before They Cost You Downtime

Retirement dates, licensing changes, and security updates from a Microsoft-exclusive team, sent when they matter, not on a filler schedule.
Subscription Form email