Skip to content

Update User Info

bcerciliar-rocketman edited this page Sep 13, 2026 · 7 revisions

The Update User Info tool identifies and validates the correct username of the currently logged-in user, leveraging various directory integrations (LDAP and Cloud Identity Providers) associated with Jamf Pro. Once a match is confirmed, this information is sent to Jamf Pro to ensure accurate user data within the system.

Quick Start

Using this example setup, the tool will check for the logged-in user's username, appends possible domains, and performs a lookup on the specified LDAP server to match the username before updating Jamf Pro. In order to set this up, you will need:

  • Configuration Profile
  • API Role and Client
  • Policy

Example Configuration Profile

Below is a Managed PLIST that can be deployed through a Configuration Profile to the following domain: tech.rocketman.updateUserInfo

<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
  <dict>
    <key>server</key>
    <string>ldap</string>
    <key>domains</key>
    <array>
      <string>@rocketman.tech</string>
      <string>@rocketblog.tech</string>
    </array>
    <key>ignore</key>
    <array>
      <string>breakglass</string>
      <string>commandcenter</string>
    </array>
    <key>clientId</key>
    <string>ENC:...</string>
    <key>clientSecret</key>
    <string>ENC:...</string>
  </dict>
</plist>

Example API Role and Client

Create an API Client with a Role that has the following permissions:

  • Read LDAP Servers
  • Update LDAP Servers
  • Read Computers

Example Policy

When setting up the Launch a Tool Script in Jamf Pro, use the following script parameters:

Jamf Pro Script Parameters

When setting up the Launch a Tool Script in Jamf Pro, use the following script parameters:

  • Parameter 4 (Global Options and Tool Name): UpdateUserInfo
  • Parameter 5 (Tool-Specific Option): --clientId ENC:...
  • Parameter 6 (Tool-Specific Option): --clientSecret ENC:...

Command Options

Key Parameters

Neither credential is enforced by the command line — --server none works without them — but any directory lookup needs both.

--clientId [string]

Specifies the encrypted credentials for Jamf API authentication.

  • Type: string
  • Required: Depends
    • Required when --server is set to ldap, idp, or both.
    • Not required if --server none is specified.
  • Example:
    --clientId "..." OR --clientId "ENC:..."

--clientSecret [string]

Specifies the encrypted credentials for Jamf API authentication.

  • Type: string
  • Required: Depends
    • Required when --server is set to ldap, idp, or both.
    • Not required if --server none is specified.
  • Example:
    --clientSecret "..." OR --clientSecret "ENC:..."

Optional Parameters

--domain [string]

Defines the domain for configuration options, including plist configurations. Defaults to tech.rocketman.updateUserInfo.

  • Type: string
  • Default: tech.rocketman.updateUserInfo
  • Example:
    --domain "custom.domain.updateUserInfo"

--server [ldap | idp | both | none]

Specifies the type of directory server lookup to perform before updating Jamf Pro:

  • ldap – query an LDAP directory
  • idp – query an Identity Provider
  • both – perform both lookups in sequence
  • none – skip all directory lookups and update Jamf Pro directly with the local username and full name. Default

Example:

--server none

--domains [list of strings]

A list of domains to append to the username for more accurate matching in systems where users may have multiple domain associations. This is crucial when users have email-like usernames (e.g., chris@rocketman.tech).

  • Type: array
  • Required: No
  • Example:
    --domains @rocketman.tech @support.rocketman.com

--ignore [list of strings]

Local accounts (such as break glass admin accounts) that must never be written to Jamf.

When the logged-in user is one of these, the tool stops and exits with a non-zero status rather than continuing — so a Jamf policy shows a failure for that Mac. That is the intended signal: nothing was recorded, on purpose.

The check only runs when a directory lookup is actually performed, so with --server none, or with the credentials omitted, the list is never consulted.

  • Type: array
  • Example:
    --ignore admin backup

Behaviour worth knowing

  • Accounts with a user ID of 500 or lower are never written to Jamf, whether or not they appear in --ignore. The run stops with a non-zero status, the same as an ignored account.
  • --server idp and --server ldap fall back to each other. If the requested directory returns no server, the other is tried, so the four values are preferences rather than hard restrictions.
  • A Mac already signed in with Jamf Connect skips the directory lookup entirely. When the Jamf Connect state matches the logged-in user, that identity is written straight to Jamf.
  • An unrecognised --server value is not rejected up front — it fails once the lookup begins. Use one of the four documented values.
  • If no match is found, the tool exits with a non-zero status after logging how many candidates it tried. Run with --log debug to see the candidates themselves.

Required API Permissions

The Jamf Pro API Roles and Clients for this tool must have the following permissions to ensure proper functionality:

  • Read LDAP Servers
  • Read Cloud Identity Providers — needed for --server idp and --server both

Ensure that these permissions are assigned to your API client configuration in Jamf Pro prior to executing the tool.

Examples

Example 1: Basic Update with Domain List and Server Type

rocketman UpdateUserInfo \
  --domains @rocketman.tech @anotherdomain.com \
  --server ldap \
  --clientId "..." \
  --clientSecret ...

This command attempts to resolve the logged-in user’s username by checking an LDAP server, appending each specified domain until a match is found.

rocketman UpdateUserInfo \
  --domains @rocketman.tech \
  --server both \
  --clientId "..." \
  --clientSecret ...

Example 3: Local Recon without API Credentials

rocketman UpdateUserInfo \
  --server none

This will bypass any directory integration and internally run:

jamf recon -endUsername <localUsername> -realname <localFullName>

to update the computer’s inventory record with the logged‑in user’s local information.

Important Notes

  • Matching happens in three passes, stopping at the first hit, and repeating for each directory server (LDAP and/or Cloud IdP):

    1. the bare local username;
    2. the username with each --domains value appended;
    3. variations built from the account's full name — first.last, firstlast, initials, first name only, last name only, and the same again with each domain.
  • Error Handling: If no match is found, the tool logs how many candidates it tried and exits with a non-zero status. Run with --log debug to see the candidates themselves.

  • No Directory Integration: If --server none is used or API credentials are omitted, the tool bypasses all directory checks and runs:

    jamf recon -endUsername <localUsername> -realname <localFullName>

    to populate the Computer Inventory record directly with the local user’s name.

JSON Scheme

{
  "title": "Update User Info (tech.rocketman.updateUserInfo)",
  "description": "Resolves the logged-in user against LDAP or a Cloud Identity Provider and records the result in the Mac's Jamf Pro inventory record.",
  "properties": {
    "server": {
      "title": "Directory Type",
      "description": "Which directory to search. 'none' skips the lookup and records the local user as-is. 'idp' and 'ldap' fall back to one another when the requested type returns no server.",
      "type": "string",
      "enum": [
        "ldap",
        "idp",
        "both",
        "none"
      ],
      "default": "none",
      "property_order": 1
    },
    "clientId": {
      "title": "Client ID",
      "description": "Client ID for Jamf API authentication. Required for any directory lookup. It is recommended to encrypt these credentials using RCC's Encrypt tool.",
      "type": "string",
      "property_order": 2
    },
    "clientSecret": {
      "title": "Client Secret",
      "description": "Client secret for Jamf API authentication. Required for any directory lookup. It is highly recommended to encrypt these credentials using RCC's Encrypt tool.",
      "type": "string",
      "property_order": 3
    },
    "domains": {
      "title": "Domains",
      "description": "Domains appended to the username while searching, for example company.com.",
      "type": "array",
      "items": {
        "type": "string",
        "title": "Domain"
      },
      "property_order": 4
    },
    "ignore": {
      "title": "Ignored Accounts",
      "description": "Local accounts that must never be written to Jamf. When the logged-in user is one of these, the run stops with a non-zero status.",
      "type": "array",
      "items": {
        "type": "string",
        "title": "Username"
      },
      "property_order": 5
    }
  }
}

Introduction

Resources

Tools

Misc

Pipeline

Submit an Issue

Clone this wiki locally