Integration with Jamf Pro
|
Note - Harmony Mobile does not support integration with Jamf Now. |
Preparing the UEM Platform for Integration
Introduction
Harmony Mobile service integrates with Jamf Pro through the existing API. To enable the integration, you must first create a Jamf Pro API account. Harmony Mobile uses API for the device records synchronization, device apps list retrieve, and for reporting device risk level to Jamf Pro. Jamf Pro deploys Harmony Mobile Protect App on a device to streamline the device enrollment.
General Workflow
-
Create a Jamf Pro account. See Creating an API Account.
-
Configure the account privileges. See Configuring Privileges for API Account.
-
Configure Jamf Pro to Deploy the Harmony Mobile Protect App. See Configuring Jamf to Deploy the Harmony Mobile Protect App.
Creating an API Account
You must create a dedicated API account user in your Jamf Pro.
To create an API account:
Log in to Jamf Pro.
Go to Settings > System Settings > Jamf Pro User Accounts & Groups.
Click New.
Go to Choose an Action > Create Standard Account.
Click Next.
The New Account window appears.
Enter all relevant information in the required fields.
Configuring Privileges for API Account
![]() | Note - To configure a POC or demo, set Privilege Set to Admin. |
For a production and testing environment, we highly recommend that you use an API account with limited permissions, as described below.
To configure privileges for an API account:
Go to the Account > Privileges section.
Verify that Access Status is set to Enabled.
Configure the API account:
Configure Basic Privileges.
In the Jamf Pro Server Objects section, check the Read option for all the settings.
Configure Mitigation Privileges.
In the Jamf Pro Server Objects section, create a custom set of Mitigation Privileges for Mobile Device Extension Attributes and for Mobile Devices.
Click OK.
Configuring Jamf to Deploy the Harmony Mobile Protect App
This configuration simplifies the Harmony Mobile Protect App deployment and activation on managed devices.
![]() | Note - If you configured Jamf Pro for Whitelisting Apps, you must add the Harmony Mobile Protect App to the allowed list. |
To configure Jamf Pro to deploy the Harmony Mobile Protect App:
Add the Harmony Mobile Protect App to your App Catalog. See Adding the Harmony Mobile Protect App to App Catalog.
Connect the app to your devices. See Adding Configuration to Harmony Mobile Application.
Configure the distribution method for the app. See Configuring Distribution Method.
Assign the app to the selected groups of users or devices. See Assigning Harmony Mobile Application to Groups of Users or Devices.
Adding the Harmony Mobile Protect App to App Catalog
![]() | Note - As you create the Harmony Mobile Protect App for your catalog, change the name from New Mobile Device App to Harmony Mobile Protect App. |
To add the Harmony Mobile Protect App to your App Catalog:
Go to Devices > Mobile Device Apps > New.
Select the type of the App:
In Choose an App Type section, verify that App Store app or apps purchased in volume is selected.
Click Next.
Search for the Harmony Mobile in the App store:
In the Search or Upload text field, enter Harmony Mobile Protect App.
Select the app store in the relevant country.
Click Next.
In the Add an App > iPhone & iPod touch Apps > Harmony Mobile Protect App row, click Add.
Note - To set the App parameters, see Setting Parameters for the Harmony Mobile Protect App in your App Catalog.
Click Save.
Setting Parameters for the Harmony Mobile Protect App in your App Catalog
Adding Configuration to Harmony Mobile Application
In the Devices window, go to Mobile Device Apps.
Go to the App Configuration section and in the Preferences field, add this text:
<dict> <key>Lacoon Server Address</key> <string>gw</string> <key>Device Serial Number</key> <string>$SERIALNUMBER</string> <key>token</key> <string>hash_tenant_id</string> </dict>
hash_tenant_id
is the SHA-256 value of the Dashboard Management ID. You must use the token configured in the Deployment section. For more information, see Configuring Jamf Pro Integration Settings.Click Done.
Configuring Distribution Method
In the Devices window, go to the Harmony Mobile Protect App > General section.
Go to the Distribution Method section and select Install Automatically/Prompt Users to Install.
Select these checkboxes:
Schedule Jamf Pro to automatically check iTunes for app updates
Automatically Force App Updates
Make app managed if currently installed as unmanaged
Assigning Harmony Mobile Application to Groups of Users or Devices
In the Devices window, go to the Harmony Mobile Protect App > Scope section.
For Selected Deployment Targets, click Add.
Select the specific mobile device and /or specific user groups to deploy.
Click Done.