13 Easy Automations for iOS and macOS
Ready to transform your iOS and macOS management from repetitive clicks to automated magic? Join us for an action-packed session where we'll show you how to leverage Jamf's powerful no-code and low-code automation tools. From Smart Groups to Jamf Routines, we'll explore real-world examples that turn time-consuming tasks into efficient workflows. Whether you're managing ten devices or ten thousand, you'll learn how to harness the power of Smart Groups, Extension Attributes, Jamf Routines and blueprints to create automated workflows. Plus, discover how AI can be your sidekick with Jamf Assistant helping to craft scripts and regex. Leave this session with practical automation strategies you can implement immediately — no computer science degree required!
5 Methods for Effective Collaboration Between IT Teams and School-Level Leadership for Successful Classroom Technology Implementation
Are you interested in learning about how IT teams can collaborate effectively with school-level leadership to create a successful learning environment in classrooms? If so, here are five effective methods that a technology team implemented to work with school-level leadership in making classroom technology successful.
90% in 30 days: Cisco's Journey to Rapid macOS Adoption
One of the most crucial ways to maintain the security of your macOS environment is by ensuring that your fleet is up to date. However, accomplishing this task at scale in an enterprise environment is not an easy feat. In this session, we will discuss how Cisco was able to achieve 90% adoption in 30 days by utilizing Jamf Pro, open-source tools, QA and user testing, as well as our partnership with Help@Cisco to establish a culture of software update compliance and N-1 enforcement.
Accelerate Generative AI Innovation With Cloud-Based Macs and Jamf
Builders, are you ready to revolutionize how you develop and deploy generative AI applications at cloud scale? In this session, you'll learn how to harness the combined superpowers of AWS EC2 Mac instances running on blazing-fast Apple silicon and Jamf to unlock new frontiers of AI innovation. You'll discover tips for architecting highly-scalable, secure AI workflows by deeply integrating cutting-edge generative models from Amazon Bedrock with your applications. We'll dive into zero-touch provisioning workflows to streamline enrollment of your EC2 Mac build farms building your apps into Jamf Pro. We'll also show you how to level-up your AI app security posture through seamless integration of Amazon Verified Access with Jamf Trust. Whether you're an AI trailblazer, a cloud guru or an IT hero, this is your opportunity to be among the first to reimagine what's possible with generative AI on Apple with AWS and Jamf.
Join us and be inspired to build!
Achieving Tailored Event Monitoring and Implementing Behavioral Baselines
Are you already using Jamf Protect on your macOS devices or considering deploying it? If you want to enhance your macOS endpoint security with your own expertise or threat research, this session is perfect for you.
In this session, we’ll explore how to implement behavioral baselines to detect threats or unwanted activity in an early stage. To achieve tailored event monitoring on macOS, we’ll also demonstrate how to craft custom analytics to identify activities that deviate from your organization’s typical user behavior or leverage telemetry data at scale using an SIEM solution.
If you are an experienced researcher, security analyst or device administrator or this is all new to you, don’t worry — we’ve got you covered. We’ll be sharing resources after the session to help you get started.
This session will cover:
- The importance of implementing behavioral baselines.
- Monitoring your organization’s use of native binaries or third-party software for notifications and reporting unexpected activity
- Tracking user privilege elevations and filtering out suspicious activity
- The differences between custom analytics, unified logging and telemetry data
- Determining the best method for gathering specific activities or data
- Building custom analytics based on real-life scenarios
- Tools that help you build predicate filters
- Tips and tricks to preserve system performance and how to best write predicates
- Insights into using Jamf Protect’s new telemetry data for macOS and its relevance
- How to integrate this Apple-specific telemetry data within a SIEM solution
- The importance of consuming Apple-specific telemetry data
Admin Rights in a Jam: Safeguarding Devices by Revoking Admin Rights with Jamf Connect
At Toast, we are continuously improving our security posture without compromising our users’ ability to innovate and deliver. Toast’s quick growth is pushing our teams to find scalable and affordable solutions to mature the security of our IT environment. This presentation will focus on our urgent need to revoke admin rights from our laptop users and provide them with a single holistic solution to temporarily elevate their access.
The issue: Our laptop environment allowed open administrative access for all users, and our IT and Security teams used multiple Endpoint Detection and Response tools, Mobile Device Management (MDM) systems, and other systems to monitor and detect security incidents. We needed to come up with a holistic, auditable, low cost and low-impact solution to revoke admin rights and allow users to temporarily elevate.
The process: We decided we had two paths forward: 1. build an in-house solution using our existing tools, or 2. purchase, learn, implement and integrate, and support a new tool. Our project team demoed multiple admin rights management tools that were overly robust, very high cost and required a learning curve to implement. We spoke to Jamf to understand if we could utilize MDM to fill our needs, and we were excited to find they were in beta with an administrative rights access feature.
The solution: In house — we implemented Privilege Elevation using Jamf Connect to disable administrative rights and provide a solution to temporarily escalate and revoke administrative rights. We were able to deliver under budget, under timeline and with only a reported 1% impact rate to our users.
Relevance: Our presentation will talk through our project, from conception to completion; it will touch on our use of the new Jamf Connect Privilege Elevation feature and some roadblocks that we encountered along the way, allowing everyone the ability to learn from our process.
A Ferrari is Fast, but Kiko Milano is Faster…
In this session, Kiko Milano’s CIO, Kaveh Vahabi, Ross Croasdell from Streamline Digital and Jamf business development executive Chris Diaz will share the Kiko Milano digital transformation story. We will talk about how this started as a concept, to meeting at NRF 2023, to deployment in mid-2023 to early 2024. We will explain how MSP Streamline, Jamf Marketplace partners and Jamf helped Kiko Milano standardize on the Apple Platform and go from 0 to 8,000 devices deployed in 6.5 months. The discussion will address what it took to accomplish this goal with Jamf, Streamline, IPort and New Black. The Kiko Milano and Streamline teams leverage the Jamf platform to optimize store processes and simplify work for their in-store associates and IT teams with internal solutions they call Smart Support and Site Manager. These tools help store leaders support tier-zero tickets and basic needs, so they can get back to the work only they can do.
AI Agents for IT: How Serval Automates 80% of Tickets in 24 Hours
Serval’s AI agents transform IT operations, automating help desk tickets, access requests, password resets, and onboarding/offboarding. This session explores how to quickly and safely deploy agentic AI for IT. We’ll demonstrate building workflows that automate any action in any application, with airtight controls to satisfy the most rigorous security teams. You’ll learn how innovative organizations like Perplexity, Verkada, and Together AI automate their help desk and more without complicated configurations or compromised security.
AI and Data Science at Jamf: Progress and Pathways
Over the past year, Jamf’s AI and Data Science teams have collaborated closely to drive innovation and deliver real-world solutions. This session will provide a comprehensive overview of their joint efforts, highlighting key developments and future directions. We’ll showcase how the teams have strengthened security products, expanded into new areas and leveraged AI to enhance device management. Join us to learn about the exciting outcomes of this synergy and what lies ahead for AI and Data Science at Jamf.
AI and Privacy and Cybersecurity - Oh My!
Each of these topics by themselves will undoubtedly have sessions dedicated to them and the relevance for commercial, healthcare, and education organizations. In this session, we will be digging into the Venn diagram of where they all come together. AI: What is your organizations and your departments role in your AI policy adoption? This could be a purely IT technical conversation, but we will be discussing it from the lens of an instructional interaction, and how IT can support instruction in making AI work for everyone: students, staff, parents and your community. Privacy: We'll discuss privacy in an AI-enabled world where information is much easier to find and associate. We'll talk about IT controls for internal information and making sure you are AI-ready, and what it might mean if you're not. We'll also explore user policies and data practices you should look for when evaluating AI tools both for staff use and instructional student facing tools. Cybersecurity: We'll discuss how AI and privacy impact our cybersecurity posture. We're seeing rapid change in these two BIG areas and school IT teams are already strapped for staffing and funding. The intersection of these three are where we'll dig in and discuss reasonable, actionable steps you can take to help make sure your organization is well positioned to understand and respond to all of these changing areas.
AI at Your Service: An Elevated Look at Jamf’s AI Assistant
Gain an inside look at how Jamf’s AI Assistant is transforming Apple device management. In this session, we’ll present real-world examples showcasing how natural language can improve your comprehension and control over your Jamf Pro and Jamf Protect environments. Whether you’re managing alerts, building workflows or just looking to save time, you’ll learn how Jamf’s AI Assistant’s new tools in Jamf Pro and Protect help you get more done — with less effort.
AI-dentifying Methods to Manage Apple Intelligence with Jamf Pro
Apple Session - As organizations integrate more Apple devices into their workflows, Jamf Admins face the challenge of managing new Apple Intelligence features while ensuring security, productivity and compliance. These AI-driven capabilities can enhance user experience, but may also require careful management to meet organizational policies. In this session, we will show you how to leverage Jamf Pro to efficiently manage and restrict Apple Intelligence features across your organization’s devices, helping you strike the perfect balance between innovation and security. By the end of the session, you will have a complete toolkit for managing Apple Intelligence restrictions with Jamf Pro. You will be able to streamline device management, enhance security and ensure that Apple devices remain in compliance with your organization’s policies, all while working smarter, not harder. Whether you are new to Jamf Pro or an experienced admin, this session will equip you with the knowledge and skills to manage Apple Intelligence features efficiently and securely.
AI-Powered & Human-Activated: Amplify Secure User Productivity with Smarter Mac Compliance
Learn how Oscar Health uses a system that uses AI to automate user engagement, drive remediation, and close security gaps for Mac devices in real time. By turning users into part of the fix, not just the risk, Amplifier reduced the burden on Oscar’s Security and IT teams while improving user and endpoint hygiene. Instead of chasing users for tasks, Amplifier activates end users directly, making them part of the security workflows without disrupting productivity. We'll share how users closed Jamf Smart Group actions faster to update, patch, remove unapproved software and fix endpoint issues without disrupting their work. See a real world example of how Jamf, its customer and a Jamf Marketplace partner collaborated using API integrations of AI with Jamf smart groups, webhooks and policies. Learn best practices and insights of how you can reduce user security risk by slashing response time from days to minutes and cut IT security workload by 50%. Learn how you can truly harness the power of AI and your workforce to secure your business. Why now? Most companies struggle to identify and engage their riskiest users when it comes to endpoint security. Pending user security tasks often get ignored and delayed, and incumbent tools rely on compliance snapshots to satisfy audits, missing the steady drift in user behavior. AI now accelerates the speed and precision of attacks to identify and exploit vulnerable users and their devices. With over 50% of breaches linked to poor user and endpoint security hygiene, businesses are even more vulnerable unless they act proactively.
A LAPS in Security
The good, the bad and the ugly of LAPS management. This session will go over how LAPS can help safeguard your organization’s security and discuss best practices in the field.
The session will cover:
- The need for LAPS and why it won’t go away - Understand why LAPS is an industry standard of modern security and why it's here to stay.
- Updates to my LAPS solution - Hear the latest details on my LAPS solution, first unveiled at JNUC 2023.
- The improvements in JAMF LAPS - Learn about the recent improvements to JAMF LAPS and how you can effectively implement and utilize this tool.
- Empowering end users - Exploring some of the tools I've created to help your end-users get the most out of JAMF LAPS.
Session goers should leave the session with valuable knowledge of the need for LAPS, how to implement and utilize JAMF LAPS or my LAPS tool, and valuable insights into the world of LAPS and the many solutions out there.
Always Connected, Always at Risk: How AI is Reshaping Mobile Security
Let’s be honest—most of us practically live on our phones. They’re always on, always connected and always on the move. That makes them prime targets, and the bad actors know it. Using AI, they’re crafting smarter scams, fake networks and apps that look real but are designed to steal your data. In this session, we’ll explore how mobile security is evolving; it's no longer just about securing the device, but also what it connects to. Verizon is leading the charge by embedding protection directly into the network, blocking threats and suspicious connections before they ever reach the device. Paired with the right solution, like Jamf, this creates a powerful layer of mobile defense. We’ll also discuss how AI is shaping the future of security—for both attackers and defenders—and how network-level protection combined with endpoint security can proactively stop threats. This isn’t a sales pitch—it’s a real look at where mobile security is headed and how we’re helping lead the way. If you're looking to stay ahead of mobile threats, especially on iPhones and iPads, this session is for you.
…And Suddenly There Was iOS. How to Prepare for a Successful Mobile Deployment.
Looking to add iOS and iPadOS devices to your macOS fleet? This session shows you how you can confidently manage both with Jamf. Using Jamf Pro features you are likely already heard of, we will walk through how to deploy apps, apply security tools and create scalable workflows for the mobile devices in your organization. Many organizations have long managed and secured Macs as a work device. Now, an increasingly mobile workforce is also using iPhones and iPads for work, while using the same work apps and containing much of the same sensitive company data. If you are expected to manage and secure mobile devices alongside your macOS fleet, this session will help you make that leap with confidence. We’ll walk through what a foundational iOS setup in Jamf Pro looks like, including app deployment, Managed App Configuration, Smart Groups and Self Service. You’ll also learn what’s required to roll out Jamf’s iOS security tools and how the setup process differs from macOS, highlighting shared concepts like Blueprints and Smart Groups, and introducing iOS-specific workflows such as Configuration Profiles and the Jamf Trust app. Whether you’re preparing for a wave of new iPhones, introducing a BYOD program or just looking to take control of privately owned phones used for work, you'll walk out with key takeaways with which you can deliver the same level of automation and security for iOS as you do for macOS.
A New Hope: Providing Apple Devices to All Students on Campus
In a perfect world, we could inspire innovation and create digital equity for every student — regardless of family means — and fully equip them with the tools and opportunities to learn and lead in a digital world. That starts today. In this session, we will talk about Bowdoin College’s groundbreaking Digital Excellence Commitment that provides every current student and all future students with a suite of the latest Apple technology. Students also gain access to a full range of course-specific software designed to advance learning, inspire innovative teaching and create digital equity.
Some highlights include: strategies, lessons learned, transitioning away from computer labs, faculty adoption, Platform SSO, zero-touch deployment, device management, security and the various tools used to make this a success. We look forward to sharing our story and helping you provide A New Hope for your students too.
API Defense Tactics: Credential Protection Essentials for Jamf Admins
The session aims to address the critical issue of securely passing credentials within scripts for API calls in Jamf environments. Participants will learn about the risks associated with credential exposure and the best practices for mitigating these risks to enhance security in device management.
We will discuss the challenges of encrypting credentials and the potential vulnerabilities that can be exploited by attackers. The session will cover the use of Jamf Pro webhooks, AWS API Gateway, AWS Secrets Manager, AWS EventBridge and credential storage solutions like HashiCorp Vault/CyberArk. We will also explore the implementation of Lambda functions for secure API authentication.
In an era where security breaches are increasingly common, it's crucial to safeguard API credentials effectively. This session is timely as it provides practical solutions to a pressing problem, ensuring that device management within Jamf environments remains secure against potential attacks.
Attendees will leave with a clear understanding of:
-
1. The risks associated with improper credential handling in API calls
2. The architecture and flow of a secure API integration using modern cloud services and security tools
3. Step-by-step guidance on setting up a secure environment for handling credentials
4. Strategies for using webhooks, credentials management and serverless functions to enhance security
5. The ability to assess and improve their current Jamf environment's security posture with respect to API credential management
App Auto-Patch: Hands-Off Application Updates
In the ever-evolving landscape of Apple device management, staying ahead in the application update game is crucial. Enter App Auto-Patch: our innovative solution designed to streamline the update process and enhance overall device management. This session will delve into how App Auto-Patch automates the application updating process, ensuring that devices remain secure and up to date with minimal administrative effort.
We'll explore the challenges of managing application updates in diverse environments and demonstrate how App Auto-Patch addresses these issues by providing a scalable, automated, and flexible solution. Attendees will gain insights into the architecture of App Auto-Patch, its integration with existing management frameworks, and how it can be customized to fit various organizational needs.
By attending this session, you will learn how to:
- Automate and manage application updates efficiently.
- Reduce the workload on IT departments while increasing compliance and security.
- Implement App Auto-Patch in your environment, with practical tips and best practices.
Join us to discover how App Auto-Patch is redefining application updates and making Apple device management more efficient and reliable than ever before.
Apple + Jamf: Device Security From the Silicon Up
Apple's own security story is one of layers: chip architecture, cryptographically signed OS volumes, Gatekeeper, XProtect, developer app signing and sandboxing. Jamf's management and security solutions build on that foundation to both extend the native security of Apple devices and provide assurances to admins about the status of their fleets. This session will go layer by layer - starting with the literal silicon, ending with Jamf Protect and Jamf Executive Threat Protection, to explain how each component stacks up to a cohesive security solution for Mac and mobile. A security parfait, if you will. :)
Apple Platform Security
Apple devices are secure by design, helping IT admins monitor and protect devices without needing to disable core features. Join this session for foundational learning on Apple Platform Security and management capabilities, and how they work together to elevate both the user experience, and the needs of enterprise IT. Additionally, hear from Jamf about how these features are implemented in Jamf Pro and Jamf Protect. *This content is provided solely for informational purposes and is not intended for distribution, marketing, or promotional use. Recipients are required to remove and delete this content no later than 31 October 2026.
Apple’s Modern Endpoint Architecture, Powered by Jamf
Apple is re-writing the playbook for managing and securing enterprise endpoints with devices that are secure-by-design. Learn how native Apple platform technologies like ACME, Device Attestation, Platform SSO, Declarative Management, Network Relay, 5G Slicing, and more present a once-in-a-decade opportunity to “think different” about securing, connecting, and empowering Apple devices in the Enterprise.
Apple TV: A Learning Experience With UCLA
From inception to deployment, UCLA wanted to empower patients while they were in their care. Without making any infrastructure changes, UCLA deployed Apple TVs per room with shared iPads. Learn about the pitfalls of networking and firewalls, how a community helped overcome these and what it looks like in action.
Asset Recovery in a Remote World
This session highlights strategies and technologies for streamlining asset recovery in the remote work era. As the workforce shifts to remote and hybrid models, this session addresses the challenges of tracking, recovering and securing IT assets, ensuring robust lifecycle management. By integrating a CMDB, Slack, Airtable and the FedEx API, attendees will gain insights to improve efficiency and enhance the recovery experience.
Highlights
- Remote asset management challenges
- Low-code automation overview
- Automated communications
- Asset management with Airtable
- Automated returns with FedEx's API
- Automated erasures
Key Takeaways
- Adaptable strategies for scalable automated asset recovery
- Methods to enhance user compliance and engagement
- Knowledge on integrating tools like Slack, Airtable and Fedex's API
- Best practices for security and integrity through automation
- Confidence to address remote asset management challenges
Automate and Elevate: Harnessing Jamf Integrations at Cisco
The session will demonstrate all our current and planned integrations and workflows, ranging from pre-built to custom solutions. These include Mac integrations with ServiceNow, Webex, Duo, Aisera, Entra ID, Snowflake, AWS S3, GitHub and AppOmni. Automations include Mac prestage reassignment, FileVault Recovery Key bot via Aisera, Trusted Device Status on our homegrown Device Portal, Automated Mac Lock on Employee Termination, various Webex bots, and our upcoming FileVault Recovery Key Archive. Mobile integrations include Duo, Snowflake, internal support tools for end users, and a future integration with Tangoe (Managed Mobility Services). Webhooks enable automations for device events related to Enrollment, unenrollment, Device cleanup, and Employee Termination.
Automated Remediation of the CrowdStrike Falcon Sensor
If you have ever tried to uninstall a Crowdstrike Falcon Agent with tamperproof protection enabled, you have probably realized it's not user-friendly. Having to pull the maintenance token from the web console, and then using it to confirm the uninstallation locally on each device is a tedious process. Using a handful of API calls and some scripting, I have found a way to completely automate the process by pulling the Agent ID locally from the Mac, passing it to the API to request the corresponding maintenance token, and then executing the uninstall locally. Having this functionality allows for endless remediation policies and opportunities, as you now have the basis to uninstall Macs that are no longer in compliance on demand.
Automatic Mac enrollment with Prime shipping benefits
Discover how to enhance your Apple device management through Jamf AI Assistant and Apple Business Manager on Amazon Business. This session explores the practical implementation, key benefits, and future capabilities of these powerful tools. Learn how ABM on Amazon Business streamlines device procurement and automated deployment, while Jamf AI Assistant enhances management efficiency. Whether you're managing a small fleet or enterprise-scale deployment, you'll gain valuable insights into maximizing your investment in Apple device management through intelligent automation and AI-driven solutions.
Automating Apple Endpoints Management: Git, CI/CD, and Terraform for an Efficient Jamf Pro Administration
Some IT teams manage thousands of Macs on a day-to-day basis and are often faced with the following challenges: - Supporting end users and/or other administrators across multiple locations around the world - Stay in touch with what’s new in the Apple world and Jamf’s products new features, product issues and upcoming changes - Ensure Jamf Pro settings and configs are modified with change tickets and document every change that is made - Be accountable for any misconfiguration or production incident, wherever it might be coming from Additionally, MSPs and Jamf Partners as a whole might need to do this for multiple Jamf Pro instances and customer environments. One of the most helpful and straightforward ways to deal with this and keep providing a great user experience is automation. In this session, we’ll share how using Terraform and Gitlab has helped us streamline the management of thousands of Macs across 100+ Jamf Pro instances by simplifying the deployment and management on a day-to-day basis, and enhancing our decision-making about configuration changes and technical constraints. We will give an overview of how Terraform and its underlying concepts work and we’ll simplify the concept of CI/CD so you can understand how it may help you deploy and manage your Apple devices in your organization. We’ll deep dive on the versioning and Git aspects that are the foundations to allow automation and strengthening of your management processes. You’ll be able to see real-world example of: - How we configure a new Jamf Pro instance in a matter of minutes - How we deploy new versions of our configs to customers through Terraform - How everything is documented and available on Gitlab - How we use Terraform to compare a Jamf Pro deployment to our template (useful for mergers and loose administrators that don’t like processes!) We’ll also share and demonstrate a custom open-source web-based tool we created that allows you to easily customize a Git template Jamf Pro config, create a fork in your repo with these customizations, and then deploy it automatically through CI/CD and Terraform. It’s easy to deploy and you configure your IdP for authentication. Resources and projects we use for this session: Terraform Provider https://github.com/deploymenttheory/terraform-provider-jamfpro Go API SDK Jamf Pro https://github.com/deploymenttheory/go-api-sdk-jamfpro Mac Admins Slack Channel - #terraform-provider-jamfpro https://macadmins.slack.com/archives/C06R172PUV6
Automating Jamf Security Platform Configuration
In this session, we will discuss the different approaches an organization can have towards managing an API based SaaS tool. We will focus on automating the configuration of our Jamf Security platforms. Our talk will focus on Terraform as the chosen IaC platform for what we built and we will then dig into how we built a Terraform Provider to support our Jamf Security platforms. Additionally, this session will reference information discussed in the “Infrastructure as Code with Jamf” and “Automating Apple Endpoint Management” sessions. This will include referencing the Jamf Pro Provider written by Lloyd’s of London and discussing our Onboarder tool built around using that Jamf Pro Provider as well as the Provider we will be covering in this session.
Automating Secure Access Control With Device Compliance and Jamf Connect ZTNA
Ensuring device compliance stands as a fundamental pillar for organizations. Various vendors and solutions offer unique workflows and capabilities to achieve this compliance state. Organizations typically rely on cross-platform integration to exchange relevant device status information, and based on these status, they enforce compliance controls to either allow or restrict access to specific resources.
For those already engaged in aforementioned device compliance workflows, the management and enforcement of resource access can be further enhanced by incorporating Jamf Connect ZTNA. By leveraging Jamf’s inherent capabilities and technology, Zero Trust Network Access (ZTNA) not only manages per-app connections and privileged access but can also incorporate compliance requirements. This approach further secures access to SaaS or on-premises resources by ensuring devices meet organizational standards, before a successful connection is established.
During the presentation, we'll delve into the necessity of Device Compliance, discuss typical characteristics defining a compliant device and investigate the methods through which Jamf solutions enable automated network restrictions of corporate resources when a device becomes non-compliant.
Automating the Mac Lifecycle: From Tedium to Triumph with Jamf Pro, Okta and GitHub Actions
This session shares our journey to automate the developer Mac lifecycle by tackling the challenges of manual tracking, security gaps and inefficient workflows. We’ll provide a deep dive into our end-to-end solution, built using Jamf Pro, Okta, Slack and GitHub Actions. Attendees will learn how we: - Automated device refresh workflows to reduce IT intervention and improve the user experience - Integrated Okta to trigger actions like device locking for departed users, enhancing security - Used the Jamf API and GitHub Actions for custom automation, including device tagging and Slack notifications - Implemented reclamation processes to streamline replacement and boost security - Automated device retention processes, including status management, unmanaging, and removal from Jamf Pro This session highlights the measurable impact of our automation efforts—saving over four hours of manual work each week, improving our security posture and increasing IT efficiency. Attendees will leave with practical strategies for automating Mac lifecycle management in environments of any size.
A Year in the Life: Implementing Device Compliance and Conditional Access on a Global Scale
This session explores today’s evolving landscape of device compliance and security management. As the demand for secure, compliant environments grows, we’ll share our journey and the practical solutions we’ve implemented—offering insights that can be applied across a wide range of organizations. Attendees will walk away with actionable strategies for navigating Conditional Access implementations while balancing strong security with a positive user experience. Learning Objectives: - Understand the technical and non-technical challenges in implementing Microsoft Conditional Access using Jamf Pro Device Compliance. - Learn effective strategies for piloting, testing, and identifying potential issues in Conditional Access implementation. - Gain insights into documenting processes and creating self-solve options for users to enhance compliance. - Explore deployment phases and user communication strategies to ensure smooth implementation. - Discover potential issues, workarounds and solutions, including collaboration with vendor support. Methodologies: - Case study presentation - Interactive Q&A sessions - Demonstrations of custom solutions and tools - Sharing best practices and lessons learned Anticipated Outcomes: - Attendees will be equipped with practical knowledge and strategies to implement Conditional Access in their own environments. - Enhanced understanding of user communication and engagement techniques to minimize friction during implementation. - Ability to troubleshoot and resolve compliance issues independently using documented processes and self-solve options.
Behind the App: Building macOS Desktop Apps with Background Services
In modern enterprise Apple environments, security, automation and user experience must go hand-in-hand. This session provides a deep technical dive into building macOS desktop applications that integrate seamlessly with privileged background services like LaunchAgents and LaunchDaemons - bridging the gap between user-facing apps and system-level tasks. Attendees will learn: • How to architect a macOS desktop app that securely communicates with a background LaunchAgent or LaunchDaemon. • When to use LaunchAgents vs. LaunchDaemons and how to handle entitlements, sandboxing and elevated privileges. • Real-world enterprise use cases such as enforcing security policies, triggering Jamf MDM commands and notifying users based on compliance status. • Best practices for secure IPC using XPC, UNIX sockets or the new SMAppService API. • How to navigate notarization, the hardened runtime and minimize user fatigue from privacy/TCC prompts. • How to deploy and manage the app and agent via Jamf Pro, including auto-updates and compliance enforcement workflows.
Beyond the Classroom: Enhancing Security and Productivity with Jamf Safe Internet
Allowing Apple devices to be used both in school and at home introduces a unique set of challenges for the IT team. IT professionals attending this session will leave equipped with actionable techniques to enhance security and seamlessly extend device usability beyond classroom hours. Additionally, attendees will gain insights into how Jamf utilizes AI and Apple’s built-in CoreML Framework for advanced, privacy-preserving and on-device phishing detection.
Binary Insight: Opening Up Jamf Threat Labs Scanning to Customers
In today's evolving threat landscape, security teams need efficient ways to validate files without compromising endpoint security. Jamf Threat Labs binary scanning service addresses this challenge by providing a cloud-based interface to Jamf Protect's detection capabilities. This session covers how this service got built, the problems it solved internally at Jamf, and how organizations can use this service to submit file hashes or binaries for analysis against Jamf Protect's detection engine without requiring local execution or endpoint deployment. We'll explore real-world applications, from validating internal applications before deployment to investigating suspicious files in a secure environment. Security professionals will learn how this service integrates into existing workflows, enhancing threat hunting capabilities while reducing risk. The session includes live demonstrations of the service, practical examples, and best practices for incorporating this tool into security operations. Whether you're a security administrator, developer, or IT professional, this session will demonstrate how cloud-based binary scanning can strengthen your security posture while streamlining validation processes.
Break Glass: How to Securely Administer Computers Using Jamf Pro LAPS
LAPS is Jamf Pro's new Local Administrator Password Solution, designed to solve a security problem found in many environments today:
- Your fleet shares the same administrator username and password across every computer.
- You can't be sure who knows these credentials.
- You can't easily change their passwords quickly.
Let's talk about why all Jamf Pro customers should be using LAPS for shared IT admin accounts and how to implement Jamf Pro's version of LAPS in your environment. If you're coming from a Windows administrator background, it's managed differently, but the outcome is the same.
We'll cover Jamf Pro's two available LAPS implementations and which is right for you. We'll discuss how to turn it on and how to use it. And finally, we'll offer some best practices for a few situations customers may see in their environment.
If you haven't yet implemented a LAPS solution in your environment, Jamf Pro LAPS is the best security tool you can put into action this year.
Breaking Up With Spreadsheets: A Comedy of Errors in Device Deployment, Starring Jamf Class Assigner
When deploying devices at scale, school districts often pre-enroll and configure devices before they necessarily know who will be using which device. This often creates a logistical dance of spreadsheets, the need for complex usernames and passwords, and a ton of printouts and stickers. None of those are ideal, especially when working with our younger learners and a busy startup of school. Jamf Class Assigner aims to provide a better experience for IT, teachers and students. It is a new way to easily and securely empower teachers to assign iPad devices to their students on the fly when it is convenient for them in their busy days. Listen to Auburn City Schools and Pulaski Community School District as they describe how they leverage Jamf Class Assigner to deploy iPads in their schools. Then we'll take a peek behind the curtain to see how easy it is to leverage Class Assigner for both Jamf Pro and Jamf School.
Bridging the Gap: Preparing Students for Career Success with the Jamf 200 Internship Program
Mesa Community College (MCC), in collaboration with Jamf, has developed a comprehensive and scalable model for preparing the next generation of Apple IT professionals. The partnership is built on three foundational pillars: accessible training, real-world experience and career placement. The first pillar focuses on creating accessible, industry-recognized training pathways through the integration of Jamf certification into MCC’s Computer Information Systems (CIS) program. This collaboration formalized a model where community college students can pursue Jamf credentials at a significantly reduced cost through a streamlined, bootcamp-style structure. The entry-level course is delivered as an eight-week intensive designed specifically for students with little to no prior IT experience. This instructional model increases retention by focusing on foundational Apple ecosystem skills, while simultaneously preparing students for certifications such as Jamf 100 and Jamf 170. Upon completion, students are equipped with the technical knowledge and confidence to pursue the more advanced Jamf 200 certification. The second pillar of the program is the JAMF 200 Enterprise Internship. Students who successfully pass the JAMF 200 certification are given the opportunity to participate in a ten-week internship led by a JAMF Engineer. The internship is designed to replicate a fully functional enterprise IT environment, exposing students to the types of workflows and technical responsibilities that Apple administrators encounter daily. During the internship, students gain hands-on experience with packaging applications, executing JAMF binary command-line tools, creating and managing Extension Attributes, leveraging the JAMF Pro App Catalog, configuring automated enrollment, and interpreting scripts. This experience reinforces their academic learning and certification training by applying those concepts in real-world scenarios, further developing their problem-solving skills and technical fluency in Apple device management. The final pillar, currently in development, centers on job placement and paid internship opportunities. MCC and JAMF are working closely with industry partners to build employment pathways for students who complete the certification and internship experience. Employers across sectors—including education, healthcare, and enterprise IT—have identified JAMF certification as a critical skill for managing Apple devices in modern IT infrastructures. The partnership’s long-term vision is to bridge the gap between education and employment, offering students not just training, but also access to meaningful, career-building opportunities. Together, MCC and JAMF are setting a new standard for community college IT programs—one that is built on accessibility, applied learning, and workforce alignment. This model not only addresses the skills gap in Apple device management but also creates a pipeline of highly capable professionals ready to contribute to the evolving technology landscape.
Building Security Remediation Workflows for Beginners
Compromised devices can be scary but responding to those threats doesn't have to be manual or complex. Building Security Remediation Workflows for Beginners is an enterprise-focused, beginner-friendly session, delivered to help Jamf admins and security professionals learn how to leverage the magic of Jamf to design and implement automated response workflows. By leveraging Jamf Pro, Jamf Protect, the Jamf Security Cloud and Jamf Connect's Zero Trust Network Access (ZTNA) capability, this presentation demonstrates how attendees can use Jamf to detect potentially malicious activity on iOS and macOS devices, quickly isolate them, and contain threats, along with automatically reversing applied restrictions once the threat has been eliminated. This session is ideal for enterprise IT and security teams seeking to integrate Jamf's suite of products into a unified response strategy that minimizes risk, reduces time-to-containment, and avoids adding operational overhead. Key discussion points: • Designing scalable, automated remediation workflows for Apple devices in enterprise environments. • Leveraging Jamf Protect and the Jamf Security Cloud for rapid threat detection. • Using Jamf Pro, Jamf Protect and the Jamf Security Cloud to isolate devices. • Securing corporate resources using Jamf Connect’s ZTNA capability. Learning outcomes: • Understand the foundational components of an enterprise-grade remediation workflow using Jamf tools. • Learn how to automate detection, containment and recovery actions across macOS and iOS fleets. • Explore how Jamf integrates into your security response. • See how Jamf empowers security teams to operate efficiently at scale.
Build the Best Onboarding Experience
First impressions are crucial when it comes to onboarding. The moment an end user interacts with IT, it sets the tone for the entire relationship. A smooth, transparent and efficient onboarding process not only helps build trust with IT and the organization but also ensures that security and best practices are implemented from the start. In this session, we’ll explore how to make that first interaction a great user experience, making your endusers fall in love with IT. We’ll begin by discussing the key tools you’ll use to streamline the onboarding process, including Automated Device Enrollment, Configuration Profiles, Jamf Setup Manager and macOS Onboarding. These tools will empower you to automate the majority of the onboarding workflow. The session will cover various onboarding workflows, from zero-touch to single-touch deployments, and explore the distinction between user-driven and IT-driven processes. You’ll learn how to handle user creation and understanding the difference between user and machine configurations. Lastly, we’ll discuss how to ensure your users are fully supported and ready to get to work. We’ll explore current solutions like old fashion PDFs manuals or swiftDialog workflows, and show you a new solution we (Jamf) are currently working on with customers to guide their end users with helpful prompts, messages and instructions during the setup process. By the end of this session, you'll have the knowledge and confidence to create the best onboarding experience that will help your end-users hit the ground running while maintaining security and compliance and build the trust with your IT department and organization.
But Why?! A Security-Focused, User-Experience-Forward Plan is Required in K-12 Education
In this session, we will discuss the imperative for K-12 educational institutions to protect student data and other personally identifiable information. We'll discuss the challenges of a small staff and low funding along with simple steps you can do to make your site more secure by using Apple and Jamf.
Bypassing the Gate: A Deep Dive Into Gatekeeper Flaws in macOS
Gatekeeper is an essential component of macOS security, ensuring that only trusted software runs on the system by verifying code signing and notarization information. Over the years, we have observed macOS malware bypassing Gatekeeper controls, overriding them or even leveraging valid developer IDs to achieve unauthorized code execution. It is crucial for defenders to understand the techniques attackers use to deploy malware on macOS.
In this talk, we will introduce Gatekeeper and delve into some of its internals to better understand its functionality. We'll examine Gatekeeper's role concerning various malware strains found on macOS. We will also share insights from our discovery process for some of these vulnerabilities. We plan to analyze three specific Gatekeeper bypasses that we've reported to Apple:
- CVE-2022-22616: A flaw in the BOM framework and Safari
- CVE-2022-32910: A flaw in Archive Utility
- CVE-2023-41067: A flaw in Launch Services
As a bonus, we will also examine Gatekeeper bypasses in third-party software, including CVE-2023-46270 and CVE-2024-22405.
Join us as we explore the internals of macOS and unveil several unique Gatekeeper vulnerabilities. Our findings demonstrate the execution of entirely unsigned and un-notarized applications, effectively bypassing Gatekeeper’s checks. To conclude, we will provide high-level detection strategies to counter these threats, utilizing Apple’s Endpoint Security API.
Cloud With a Chance of Jamf
From December 2022 to June 2024, dataJAR migrated the 200 or so Jamf Pro instances it hosted to Jamf Cloud. With near 10% of those instances having been hosted with dataJAR for over 8 years.
This talk will give an overview on how to prepare yourselves to migrate to Jamf Cloud, the options available, lessons learnt, post-migration steps and test plans.
With a smattering of real-world experience sprinkled in.
Collaboration Over Configuration: Building Tech Solutions With Educators, Not for Them
As more schools adopt 1:1 devices and increasingly complex technology, making these tools accessible and user-friendly remains a major challenge. Educators are overworked, student needs are growing and technology is evolving faster than ever. Our goal is to bridge this gap—helping schools save money, enhance classroom innovation, and better support instructional practices with smart, sustainable solutions. In this session, we aim to highlight the following aspects of our recent deployment of iPad Stands to replace old document cameras and how the use of Jamf (and other tools) allowed us to create engaging documentation to generate excitement and drive innovation in the classroom. In this session, we’ll explore: - How project management tools strengthen collaboration between the tech team and educators. - How Jamf and integrated services streamline workflows and boost efficiency. - How cross-departmental stakeholder feedback shapes more holistic, effective solutions.
Collaborative Governance: Aligning IT and Security Goals for Effective Risk Management
In today's evolving threat landscape, protecting information and assets requires something not usually seen: forged partnerships between IT and Infosec. This session explores communication barriers and common obstacles that may hinder effective collaboration, as well as some ways to leverage Jamf Pro and Jamf Protect to strengthen partnerships and enhance security.
Commercial & Security State of the Union (with American Sign Language)
This session will provide a deeper dive into the updates you heard during the keynote. Tailored for any commercial organization managing and securing their fleets from manufacturing to financial to government to healthcare or higher education, the audience will walk away from the State of the Union with a clear understanding of how Jamf is supporting businesses and gain ideas of how to transform their Apple ecosystem. Doors will open at 10:30am and the livestream will start at 10:40am. The session will begin at 10:45am.
Commercial & Security State of the Union (with American Sign Language)
This session will provide a high-level picture of all things past, present and future for commercial organizations managing and securing their environments with Jamf. With a combination of market trend reports, vision for commercial organization, product updates, etc. users will gain a high-level picture of everything Jamf is doing to support businesses.
Doors will open at 10:30am and the livestream will start at 10:40am. The session will begin at 10:45am.
Commercial & Security State of the Union
This session will provide a deeper dive into the updates you heard during the keynote. Tailored for any commercial organization managing and securing their fleets from manufacturing to financial to government to healthcare or higher education, the audience will walk away from the State of the Union with a clear understanding of how Jamf is supporting businesses and gain ideas of how to transform their Apple ecosystem. Doors will open at 10:30am and the livestream will start at 10:40am. The session will begin at 10:45am.
Commercial & Security State of the Union
This session will provide a high-level picture of all things past, present and future for commercial organizations managing and securing their environments with Jamf. With a combination of market trend reports, vision for commercial organization, product updates, etc. users will gain a high-level picture of everything Jamf is doing to support businesses.
Compliance Benchmarks in Jamf Pro: From Complex Scripts to Simple Clicks
In today's rapidly evolving cybersecurity landscape, maintaining compliance with security benchmarks is no longer optional - it's a critical business requirement. Organizations face increasing pressure to demonstrate adherence to industry standards while efficiently managing their Apple fleet. This session showcases Jamf Pro's revolutionary compliance benchmarks feature, which transforms complex security compliance management from labor-intensive, manual scripting to streamlined automation. Through detailed technical demonstrations and real-world implementation examples, you'll discover how organizations can efficiently implement, monitor, and validate CIS benchmarks while maintaining continuous compliance across their macOS fleet. We'll explore the journey from traditional approaches using manual mSCP scripts and Jamf Compliance Editor to the seamless integration now available in Jamf Pro. A featured customer success story will illustrate the transformative impact of this evolution, sharing concrete metrics on time savings, security posture improvements and operational efficiency gains. Whether you're currently managing compliance through scripts or want to strengthen your security stance, this session provides actionable insights for organizations of all sizes. You'll learn: - How to assess your current compliance state and plan your implementation. - Step-by-step workflow for deploying CIS benchmarks. - Strategies for continuous monitoring and reporting. - Real-world migration patterns and lessons learned from successful implementations. - Methods to demonstrate compliance to auditors and stakeholders. This technical session bridges the gap between security requirements and practical implementation, offering both strategic insights and hands-on technical guidance for achieving and maintaining compliance in your environment.