# Start Jamf device registration from Self Service, not Company Portal

> Which user-facing entry point should register a Jamf-managed Mac for the current Device Compliance integration?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-590-start-jamf-device-registration-from-self-service-not-company-portal/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:22:06+00:00
- Modified: 2026-09-10T02:14:32+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, IT
- Reading time: 2 minutes

## What you need to know

Which user-facing entry point should register a Jamf-managed Mac for the current Device Compliance integration?

## Potentially affected

Use this distinction for Jamf Pro Device Compliance integration, not the older Conditional Access integration. Confirm the intended registration policy, applicable users, connector assignment, and compliance smart group before sending onboarding instructions.

## DSE recommendation

Write the user handoff around the exact Self Service policy and its approved description.

## Article

## Source facts

Microsoft’s Jamf Device Compliance guidance directs users to the registration policy in Jamf Self Service. Starting registration through the deployed Company Portal app instead produces AccountNotOnboarded. Jamf-managed devices in this integration do not appear in Intune’s device list. After registration, their initial Entra state is noncompliant; Jamf’s configured compliance smart group supplies the subsequent status through the connector. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/device-security/compliance/jamf-entra-id).

## Applicability

Use this distinction for Jamf Pro Device Compliance integration, not the older Conditional Access integration. Confirm the intended registration policy, applicable users, connector assignment, and compliance smart group before sending onboarding instructions.

## DSE recommendation

Write the user handoff around the exact Self Service policy and its approved description. Treat Company Portal installation as a separate preparation item, not the instruction to launch registration. Give the support desk a decision path that distinguishes a wrong entry point from an incomplete registration or missing compliance-group membership. Avoid directing users through repeated registration attempts without identifying which path they used.

## Verification

On an approved pilot Mac, follow the documented Self Service policy and inspect the resulting Entra device record. Check the user’s connector-scoped group and the device’s compliance smart-group membership when the expected state does not arrive. Record the entry point and observed status transitions. Do not search only the Intune device list or infer a failed integration solely from the initial noncompliant state.

## Official references

[Microsoft Learn: Jamf Managed Device Compliance with Microsoft Entra ID](https://learn.microsoft.com/en-us/intune/device-security/compliance/jamf-entra-id).

## Primary reference

- Name: Jamf Managed Device Compliance with Microsoft Entra ID - Microsoft Intune | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/intune/device-security/compliance/jamf-entra-id
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Start Jamf device registration from Self Service, not Company Portal,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-590-start-jamf-device-registration-from-self-service-not-company-portal/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
