-
Notifications
You must be signed in to change notification settings - Fork 3
Update User Info
The Update User Info tool identifies and validates the correct username of the currently logged-in user, leveraging various directory integrations (LDAP and Cloud Identity Providers) associated with Jamf Pro. Once a match is confirmed, this information is sent to Jamf Pro to ensure accurate user data within the system.
Using this example setup, the tool will check for the logged-in user's username, appends possible domains, and performs a lookup on the specified LDAP server to match the username before updating Jamf Pro. In order to set this up, you will need:
- Configuration Profile
- API Role and Client
- Policy
Below is a Managed PLIST that can be deployed through a Configuration Profile to the following domain: tech.rocketman.updateUserInfo
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
<key>server</key>
<string>ldap</string>
<key>domains</key>
<array>
<string>@rocketman.tech</string>
<string>@rocketblog.tech</string>
</array>
<key>ignore</key>
<array>
<string>breakglass</string>
<string>commandcenter</string>
</array>
<key>clientId</key>
<string>ENC:...</string>
<key>clientSecret</key>
<string>ENC:...</string>
</dict>
</plist>Create an API Client with a Role that has the following permissions:
- Read LDAP Servers
- Update LDAP Servers
- Read Computers
When setting up the Launch a Tool Script in Jamf Pro, use the following script parameters:
When setting up the Launch a Tool Script in Jamf Pro, use the following script parameters:
-
Parameter 4 (Global Options and Tool Name):
UpdateUserInfo -
Parameter 5 (Tool-Specific Option):
--clientId ENC:... -
Parameter 6 (Tool-Specific Option):
--clientSecret ENC:...
Neither credential is enforced by the command line — --server none works without them — but any directory lookup needs both.
Specifies the encrypted credentials for Jamf API authentication.
- Type: string
-
Required: Depends
-
Required when
--serveris set toldap,idp, orboth. -
Not required if
--server noneis specified.
-
Required when
-
Example:
--clientId "..." OR --clientId "ENC:..."
Specifies the encrypted credentials for Jamf API authentication.
- Type: string
-
Required: Depends
-
Required when
--serveris set toldap,idp, orboth. -
Not required if
--server noneis specified.
-
Required when
-
Example:
--clientSecret "..." OR --clientSecret "ENC:..."
Defines the domain for configuration options, including plist configurations. Defaults to tech.rocketman.updateUserInfo.
- Type: string
-
Default:
tech.rocketman.updateUserInfo -
Example:
--domain "custom.domain.updateUserInfo"
Specifies the type of directory server lookup to perform before updating Jamf Pro:
-
ldap– query an LDAP directory -
idp– query an Identity Provider -
both– perform both lookups in sequence -
none– skip all directory lookups and update Jamf Pro directly with the local username and full name. Default
Example:
--server noneA list of domains to append to the username for more accurate matching in systems where users may have multiple domain associations. This is crucial when users have email-like usernames (e.g., chris@rocketman.tech).
- Type: array
- Required: No
-
Example:
--domains @rocketman.tech @support.rocketman.com
Local accounts (such as break glass admin accounts) that must never be written to Jamf.
When the logged-in user is one of these, the tool stops and exits with a non-zero status rather than continuing — so a Jamf policy shows a failure for that Mac. That is the intended signal: nothing was recorded, on purpose.
The check only runs when a directory lookup is actually performed, so with --server none, or with the credentials omitted, the list is never consulted.
- Type: array
-
Example:
--ignore admin backup
-
Accounts with a user ID of 500 or lower are never written to Jamf, whether or not they appear in
--ignore. The run stops with a non-zero status, the same as an ignored account. -
--server idpand--server ldapfall back to each other. If the requested directory returns no server, the other is tried, so the four values are preferences rather than hard restrictions. - A Mac already signed in with Jamf Connect skips the directory lookup entirely. When the Jamf Connect state matches the logged-in user, that identity is written straight to Jamf.
-
An unrecognised
--servervalue is not rejected up front — it fails once the lookup begins. Use one of the four documented values. -
If no match is found, the tool exits with a non-zero status after logging how many candidates it tried. Run with
--log debugto see the candidates themselves.
The Jamf Pro API Roles and Clients for this tool must have the following permissions to ensure proper functionality:
- Read LDAP Servers
-
Read Cloud Identity Providers — needed for
--server idpand--server both
Ensure that these permissions are assigned to your API client configuration in Jamf Pro prior to executing the tool.
rocketman UpdateUserInfo \
--domains @rocketman.tech @anotherdomain.com \
--server ldap \
--clientId "..." \
--clientSecret ...This command attempts to resolve the logged-in user’s username by checking an LDAP server, appending each specified domain until a match is found.
rocketman UpdateUserInfo \
--domains @rocketman.tech \
--server both \
--clientId "..." \
--clientSecret ...rocketman UpdateUserInfo \
--server noneThis will bypass any directory integration and internally run:
jamf recon -endUsername <localUsername> -realname <localFullName>to update the computer’s inventory record with the logged‑in user’s local information.
-
Matching happens in three passes, stopping at the first hit, and repeating for each directory server (LDAP and/or Cloud IdP):
- the bare local username;
- the username with each
--domainsvalue appended; - variations built from the account's full name —
first.last,firstlast, initials, first name only, last name only, and the same again with each domain.
-
Error Handling: If no match is found, the tool logs how many candidates it tried and exits with a non-zero status. Run with
--log debugto see the candidates themselves. -
No Directory Integration: If
--server noneis used or API credentials are omitted, the tool bypasses all directory checks and runs:jamf recon -endUsername <localUsername> -realname <localFullName>
to populate the Computer Inventory record directly with the local user’s name.
{
"title": "Update User Info (tech.rocketman.updateUserInfo)",
"description": "Resolves the logged-in user against LDAP or a Cloud Identity Provider and records the result in the Mac's Jamf Pro inventory record.",
"properties": {
"server": {
"title": "Directory Type",
"description": "Which directory to search. 'none' skips the lookup and records the local user as-is. 'idp' and 'ldap' fall back to one another when the requested type returns no server.",
"type": "string",
"enum": [
"ldap",
"idp",
"both",
"none"
],
"default": "none",
"property_order": 1
},
"clientId": {
"title": "Client ID",
"description": "Client ID for Jamf API authentication. Required for any directory lookup. It is recommended to encrypt these credentials using RCC's Encrypt tool.",
"type": "string",
"property_order": 2
},
"clientSecret": {
"title": "Client Secret",
"description": "Client secret for Jamf API authentication. Required for any directory lookup. It is highly recommended to encrypt these credentials using RCC's Encrypt tool.",
"type": "string",
"property_order": 3
},
"domains": {
"title": "Domains",
"description": "Domains appended to the username while searching, for example company.com.",
"type": "array",
"items": {
"type": "string",
"title": "Domain"
},
"property_order": 4
},
"ignore": {
"title": "Ignored Accounts",
"description": "Local accounts that must never be written to Jamf. When the logged-in user is one of these, the run stops with a non-zero status.",
"type": "array",
"items": {
"type": "string",
"title": "Username"
},
"property_order": 5
}
}
}Tip
Professional setup, custom integrations, and SLA-backed support are available.
➡️ Learn more
-
Encrypt
Encrypt any string. -
App Setup Helper
Enables Screen Recording for apps. -
Break Glass Admin
Manages emergency admin accounts. -
Change Static Group Membership
Adds or removes the Mac from a static group. -
Edit User Profile
Updates building and department info. -
Fetch Database
Reads a stored value for use in a script. -
FileVault Token Revoker
Removes FileVault tokens. -
Get Backdoor Admin Password From Keychain
Retrieves backdoor admin passwords. -
List All FileVault Enabled Users
Lists FileVault-enabled users. -
Network Migration
Moves a Mac between 802.1x profiles. -
Rapid Response
Triggers scripts immediately. -
Rename Computer
Renames Macs via Jamf. -
Reset Jamf Connect Login Screen
Switches to macOS login. -
Secure Token Sharing Tool
Grants secure tokens. -
Self Service Email
Creates pre-filled emails. -
Set Time Zone
Sets time zone and NTP server. -
Set User Icon
Sets a user's account picture. -
Super
Runs SUPER with encrypted credentials. -
Temporary Admin
Grants temporary admin rights. -
Update User Info
Syncs user data with Jamf. -
Upload Jamf Logs
Uploads log files to Jamf. -
User Privilege Management
Adjusts user roles. -
Warning Timer
Blocks with a countdown dialog.