fleetdm / fleet

Open-source platform for IT, security, and infrastructure teams. (Linux, macOS, Chrome, Windows, cloud, data center)
https://fleetdm.com
Other
2.93k stars 409 forks source link

Integration with IdP / LDAP for combining end user data/attributes into the host record in the Fleet UI #21028

Open Patagonia121 opened 1 month ago

Patagonia121 commented 1 month ago

Customer user story: As an admin, I want the MDM to integrate with Okta to synchronize attributes like department and role to the host’s device record based on the assigned user, dynamically scoping applications and configuration data to user personas.

As of July 2024, this is unsolved, due to the inability to set host attributes arbitrarily based on IdP data.

Additional feedback from customer: Something more like SimpleMDM's custom attributes: https://simplemdm.pdq.com/hc/en-us/articles/9355313240347-Attributes-Custom-Attributes Or very specifically Jamf Pro's https://learn.jamf.com/en-US/bundle/jamf-pro-documentation-10.39.0/page/Computer_Extension_Attributes.html

From Fleet CSA: When a device in Jamf updates its inventory (like refetch in Fleet) it refreshes the end user data via an integration with an organization's "directory" service which can be AD or a cloud IdP.

noahtalerman commented 1 month ago

Hey @dherder, ignoring the sync part, how did we solve this (w/o sync) w/ customer-rosner?

Are they using the Tines story you created?

cc @Patagonia121