Hi everyone. I'm trying to secure our Mac endpoints for ZPA access and need to use the device posture integration with Jamf.
I found the ZPA admin docs, but I'm nervous about the Terraform part for setting up the posture profile. Has anyone done this? Could you share a working example of the `zpa_policy_type` resource for Jamf? I'm stuck on the `condition` block for the Jamf query.
```hcl
resource "zpa_policy_type" "jamf_mac_posture" {
name = "jamf_mac_compliance"
description = "Checks Jamf for compliant Macs"
policy_set_id = data.zpa_policy_set.zpa_default.id
condition {
lhs = "jamf"
rhs = "true"
# Do I need an operator here for the query string?
}
}
```
Specifically, how do you format the `rhs` to match the custom search list in Jamf? Any gotchas with the API permissions? Thanks for any pointers.
The `rhs` should be the name of your Jamf Advanced Computer Search, exactly as it appears, including any spaces. The condition block typically uses the `EQUALS` operator implicitly. Your `lhs` is correct.
Here's a working snippet from a recent deployment. Note the `rhs` is wrapped in quotes.
```hcl
condition {
lhs = "jamf"
rhs = ""My Jamf Compliance Search Name""
}
```
The main gotcha isn't the Terraform syntax, it's the Jamf API permissions. The service account you configure in ZPA needs at least `Read` access to *both* `Advanced Computer Searches` and `Computers`. If it only has access to Searches, the posture check will fail silently because it can't read the device results from the search.
You'll also want to validate the search logic in Jamf itself returns the correct serial numbers before tying it to ZPA.
Garbage in, garbage out.
Good catch on the permissions detail - that's exactly the kind of silent failure that burns an afternoon. I'd also add that the Jamf search must use the `Serial Number` criterion, not `Computer Name`. ZPA matches on the hardware serial from the device certificate.
One more thing: the search refresh timing. Jamf caches search results, and ZPA polls on its own schedule. If you've just updated a device's compliance in Jamf, expect a delay of several minutes before ZPA sees it and allows access. It's not real-time.
Design for failure.
Yeah, that Terraform block was my stumbling block too. I got it working by setting the `rhs` to the exact name of my Jamf advanced search, like user517 said, but it took me a minute to realize the quotes are part of the string. So it's `rhs = ""Compliant Macs List""` if your search is named "Compliant Macs List".
The permissions gotcha is real. My posture check failed for a day because the service account could read the search, but not the individual computer records. Once I fixed that in Jamf, it just worked.
One thing I'm still figuring out is how often ZPA re-evaluates. Is it every time a device tries to connect, or on a fixed schedule?
You've got the right start, but your `rhs` is off. It needs to be the exact, case-sensitive name of your Jamf Advanced Computer Search as a string. The example `"true"` won't match anything.
To build on the permissions discussion others mentioned, the posture check fails if ZPA can't verify the device's serial number against the Jamf search results. That means your Jamf search criteria must specifically filter on `Serial Number` and your API account must have permissions to read the computer objects themselves, not just the saved search list.
Have you validated the serial numbers ZPA is presenting match the format Jamf is storing? I've seen discrepancies where Jamf had letters in lowercase but the certificate output was uppercase, causing mismatches.