fleetdm / fleet

Open-source platform for IT, security, and infrastructure teams. (Linux, macOS, Chrome, Windows, cloud, data center)
https://fleetdm.com
Other
3.16k stars 433 forks source link

Use host vitals from IdP to create labels and variable for configuration profiles #21028

Open Patagonia121 opened 3 months ago

Patagonia121 commented 3 months ago

User stories

noahtalerman commented 3 months ago

Hey @dherder, ignoring the sync part, how did we solve this (w/o sync) w/ customer-rosner?

Are they using the Tines story you created?

cc @Patagonia121

harrisonravazzolo commented 2 months ago

Hey @noahtalerman - Resurfacing this one as customer-pingali considers an integration with their IdP and being able to tie users to a device(s) is a must-have in order to consider Fleet MDM.

nonpunctual commented 2 months ago

Related: https://github.com/fleetdm/fleet/issues/21849 Use WebClip profile for MyDevice page on iOS/iPadOS

noahtalerman commented 2 months ago

Hey @Patagonia121 and @harrisonravazzolo when you get the chance, can you please add the Gong snippet from the respective customers to the top of the issue description? Thanks :)

harrisonravazzolo commented 1 month ago

@noahtalerman hey Noah, Added comments, use case and Gong to the body of the issue.

noahtalerman commented 1 month ago

Moved the original issue description here for safekeeping:

Customer user story: As an admin, I want the MDM to integrate with Okta to synchronize attributes like department and role to the host’s device record based on the assigned user, dynamically scoping applications and configuration data to user personas.

As of July 2024, this is unsolved, due to the inability to set host attributes arbitrarily based on IdP data.

Additional feedback from customer: Something more like SimpleMDM's custom attributes: https://simplemdm.pdq.com/hc/en-us/articles/9355313240347-Attributes-Custom-Attributes Or very specifically Jamf Pro's https://learn.jamf.com/en-US/bundle/jamf-pro-documentation-10.39.0/page/Computer_Extension_Attributes.html

From Fleet CSA: When a device in Jamf updates its inventory (like refetch in Fleet) it refreshes the end user data via an integration with an organization's "directory" service which can be AD or a cloud IdP.

noahtalerman commented 1 month ago

@pintomi1989 @allenhouchins @phtardif1 can you please add Gong snippets for sarahwu, ramzel, and flacourtia? Thanks!

nonpunctual commented 1 month ago

@noahtalerman added gong snippets for customer-flacourtia & customer-sarahwu. @harrisonravazzolo could not find a reference in Gong for prospect-ramzel on this topic. Maybe in a doc?

noahtalerman commented 1 month ago

Hey @Patagonia121 and @harrisonravazzolo heads up, we peeled this user story off this request and brought it into the current design sprint.

Keep in mind that they user story will likely not address all aspects of this request. It's a small iterative piece.