90% in 30 days: Cisco's Journey to Rapid macOS Adoption
One of the most crucial ways to maintain the security of your macOS environment is by ensuring that your fleet is up to date. However, accomplishing this task at scale in an enterprise environment is not an easy feat. In this session, we will discuss how Cisco was able to achieve 90% adoption in 30 days by utilizing Jamf Pro, open-source tools, QA and user testing, as well as our partnership with Help@Cisco to establish a culture of software update compliance and N-1 enforcement.
Accelerate Generative AI Innovation With Cloud-Based Macs and Jamf
Builders, are you ready to revolutionize how you develop and deploy generative AI applications at cloud scale? In this session, you'll learn how to harness the combined superpowers of AWS EC2 Mac instances running on blazing-fast Apple silicon and Jamf to unlock new frontiers of AI innovation. You'll discover tips for architecting highly-scalable, secure AI workflows by deeply integrating cutting-edge generative models from Amazon Bedrock with your applications. We'll dive into zero-touch provisioning workflows to streamline enrollment of your EC2 Mac build farms building your apps into Jamf Pro. We'll also show you how to level-up your AI app security posture through seamless integration of Amazon Verified Access with Jamf Trust. Whether you're an AI trailblazer, a cloud guru or an IT hero, this is your opportunity to be among the first to reimagine what's possible with generative AI on Apple with AWS and Jamf.
Join us and be inspired to build!
Achieving Tailored Event Monitoring and Implementing Behavioral Baselines
Are you already using Jamf Protect on your macOS devices or considering deploying it? If you want to enhance your macOS endpoint security with your own expertise or threat research, this session is perfect for you.
In this session, we’ll explore how to implement behavioral baselines to detect threats or unwanted activity in an early stage. To achieve tailored event monitoring on macOS, we’ll also demonstrate how to craft custom analytics to identify activities that deviate from your organization’s typical user behavior or leverage telemetry data at scale using an SIEM solution.
If you are an experienced researcher, security analyst or device administrator or this is all new to you, don’t worry — we’ve got you covered. We’ll be sharing resources after the session to help you get started.
This session will cover:
- The importance of implementing behavioral baselines.
- Monitoring your organization’s use of native binaries or third-party software for notifications and reporting unexpected activity
- Tracking user privilege elevations and filtering out suspicious activity
- The differences between custom analytics, unified logging and telemetry data
- Determining the best method for gathering specific activities or data
- Building custom analytics based on real-life scenarios
- Tools that help you build predicate filters
- Tips and tricks to preserve system performance and how to best write predicates
- Insights into using Jamf Protect’s new telemetry data for macOS and its relevance
- How to integrate this Apple-specific telemetry data within a SIEM solution
- The importance of consuming Apple-specific telemetry data
Admin Rights in a Jam: Safeguarding Devices by Revoking Admin Rights with Jamf Connect
At Toast, we are continuously improving our security posture without compromising our users’ ability to innovate and deliver. Toast’s quick growth is pushing our teams to find scalable and affordable solutions to mature the security of our IT environment. This presentation will focus on our urgent need to revoke admin rights from our laptop users and provide them with a single holistic solution to temporarily elevate their access.
The issue: Our laptop environment allowed open administrative access for all users, and our IT and Security teams used multiple Endpoint Detection and Response tools, Mobile Device Management (MDM) systems, and other systems to monitor and detect security incidents. We needed to come up with a holistic, auditable, low cost and low-impact solution to revoke admin rights and allow users to temporarily elevate.
The process: We decided we had two paths forward: 1. build an in-house solution using our existing tools, or 2. purchase, learn, implement and integrate, and support a new tool. Our project team demoed multiple admin rights management tools that were overly robust, very high cost and required a learning curve to implement. We spoke to Jamf to understand if we could utilize MDM to fill our needs, and we were excited to find they were in beta with an administrative rights access feature.
The solution: In house — we implemented Privilege Elevation using Jamf Connect to disable administrative rights and provide a solution to temporarily escalate and revoke administrative rights. We were able to deliver under budget, under timeline and with only a reported 1% impact rate to our users.
Relevance: Our presentation will talk through our project, from conception to completion; it will touch on our use of the new Jamf Connect Privilege Elevation feature and some roadblocks that we encountered along the way, allowing everyone the ability to learn from our process.
AI at Your Service: An Elevated Look at Jamf’s AI Assistant
Gain an inside look at how Jamf’s AI Assistant is transforming Apple device management. In this session, we’ll present real-world examples showcasing how natural language can improve your comprehension and control over your Jamf Pro and Jamf Protect environments. Whether you’re managing alerts, building workflows or just looking to save time, you’ll learn how Jamf’s AI Assistant’s new tools in Jamf Pro and Protect help you get more done — with less effort.
A LAPS in Security
The good, the bad and the ugly of LAPS management. This session will go over how LAPS can help safeguard your organization’s security and discuss best practices in the field.
The session will cover:
- The need for LAPS and why it won’t go away - Understand why LAPS is an industry standard of modern security and why it's here to stay.
- Updates to my LAPS solution - Hear the latest details on my LAPS solution, first unveiled at JNUC 2023.
- The improvements in JAMF LAPS - Learn about the recent improvements to JAMF LAPS and how you can effectively implement and utilize this tool.
- Empowering end users - Exploring some of the tools I've created to help your end-users get the most out of JAMF LAPS.
Session goers should leave the session with valuable knowledge of the need for LAPS, how to implement and utilize JAMF LAPS or my LAPS tool, and valuable insights into the world of LAPS and the many solutions out there.
A New Hope: Providing Apple Devices to All Students on Campus
In a perfect world, we could inspire innovation and create digital equity for every student — regardless of family means — and fully equip them with the tools and opportunities to learn and lead in a digital world. That starts today. In this session, we will talk about Bowdoin College’s groundbreaking Digital Excellence Commitment that provides every current student and all future students with a suite of the latest Apple technology. Students also gain access to a full range of course-specific software designed to advance learning, inspire innovative teaching and create digital equity.
Some highlights include: strategies, lessons learned, transitioning away from computer labs, faculty adoption, Platform SSO, zero-touch deployment, device management, security and the various tools used to make this a success. We look forward to sharing our story and helping you provide A New Hope for your students too.
API Defense Tactics: Credential Protection Essentials for Jamf Admins
The session aims to address the critical issue of securely passing credentials within scripts for API calls in Jamf environments. Participants will learn about the risks associated with credential exposure and the best practices for mitigating these risks to enhance security in device management.
We will discuss the challenges of encrypting credentials and the potential vulnerabilities that can be exploited by attackers. The session will cover the use of Jamf Pro webhooks, AWS API Gateway, AWS Secrets Manager, AWS EventBridge and credential storage solutions like HashiCorp Vault/CyberArk. We will also explore the implementation of Lambda functions for secure API authentication.
In an era where security breaches are increasingly common, it's crucial to safeguard API credentials effectively. This session is timely as it provides practical solutions to a pressing problem, ensuring that device management within Jamf environments remains secure against potential attacks.
Attendees will leave with a clear understanding of:
-
1. The risks associated with improper credential handling in API calls
2. The architecture and flow of a secure API integration using modern cloud services and security tools
3. Step-by-step guidance on setting up a secure environment for handling credentials
4. Strategies for using webhooks, credentials management and serverless functions to enhance security
5. The ability to assess and improve their current Jamf environment's security posture with respect to API credential management
App Auto-Patch: Hands-Off Application Updates
In the ever-evolving landscape of Apple device management, staying ahead in the application update game is crucial. Enter App Auto-Patch: our innovative solution designed to streamline the update process and enhance overall device management. This session will delve into how App Auto-Patch automates the application updating process, ensuring that devices remain secure and up to date with minimal administrative effort.
We'll explore the challenges of managing application updates in diverse environments and demonstrate how App Auto-Patch addresses these issues by providing a scalable, automated, and flexible solution. Attendees will gain insights into the architecture of App Auto-Patch, its integration with existing management frameworks, and how it can be customized to fit various organizational needs.
By attending this session, you will learn how to:
- Automate and manage application updates efficiently.
- Reduce the workload on IT departments while increasing compliance and security.
- Implement App Auto-Patch in your environment, with practical tips and best practices.
Join us to discover how App Auto-Patch is redefining application updates and making Apple device management more efficient and reliable than ever before.
Apple + Jamf: Device Security From the Silicon Up
Apple's own security story is one of layers: chip architecture, cryptographically signed OS volumes, Gatekeeper, XProtect, developer app signing and sandboxing. Jamf's management and security solutions build on that foundation to both extend the native security of Apple devices and provide assurances to admins about the status of their fleets. This session will go layer by layer - starting with the literal silicon, ending with Jamf Protect and Jamf Executive Threat Protection, to explain how each component stacks up to a cohesive security solution for Mac and mobile. A security parfait, if you will. :)
Asset Recovery in a Remote World
This session highlights strategies and technologies for streamlining asset recovery in the remote work era. As the workforce shifts to remote and hybrid models, this session addresses the challenges of tracking, recovering and securing IT assets, ensuring robust lifecycle management. By integrating a CMDB, Slack, Airtable and the FedEx API, attendees will gain insights to improve efficiency and enhance the recovery experience.
Highlights
- Remote asset management challenges
- Low-code automation overview
- Automated communications
- Asset management with Airtable
- Automated returns with FedEx's API
- Automated erasures
Key Takeaways
- Adaptable strategies for scalable automated asset recovery
- Methods to enhance user compliance and engagement
- Knowledge on integrating tools like Slack, Airtable and Fedex's API
- Best practices for security and integrity through automation
- Confidence to address remote asset management challenges
Automated Remediation of the CrowdStrike Falcon Sensor
If you have ever tried to uninstall a Crowdstrike Falcon Agent with tamperproof protection enabled, you have probably realized it's not user-friendly. Having to pull the maintenance token from the web console, and then using it to confirm the uninstallation locally on each device is a tedious process. Using a handful of API calls and some scripting, I have found a way to completely automate the process by pulling the Agent ID locally from the Mac, passing it to the API to request the corresponding maintenance token, and then executing the uninstall locally. Having this functionality allows for endless remediation policies and opportunities, as you now have the basis to uninstall Macs that are no longer in compliance on demand.
Automating Apple Endpoints Management: Git, CI/CD, and Terraform for an Efficient Jamf Pro Administration
Some IT teams manage thousands of Macs on a day-to-day basis and are often faced with the following challenges: - Supporting end users and/or other administrators across multiple locations around the world - Stay in touch with what’s new in the Apple world and Jamf’s products new features, product issues and upcoming changes - Ensure Jamf Pro settings and configs are modified with change tickets and document every change that is made - Be accountable for any misconfiguration or production incident, wherever it might be coming from Additionally, MSPs and Jamf Partners as a whole might need to do this for multiple Jamf Pro instances and customer environments. One of the most helpful and straightforward ways to deal with this and keep providing a great user experience is automation. In this session, we’ll share how using Terraform and Gitlab has helped us streamline the management of thousands of Macs across 100+ Jamf Pro instances by simplifying the deployment and management on a day-to-day basis, and enhancing our decision-making about configuration changes and technical constraints. We will give an overview of how Terraform and its underlying concepts work and we’ll simplify the concept of CI/CD so you can understand how it may help you deploy and manage your Apple devices in your organization. We’ll deep dive on the versioning and Git aspects that are the foundations to allow automation and strengthening of your management processes. You’ll be able to see real-world example of: - How we configure a new Jamf Pro instance in a matter of minutes - How we deploy new versions of our configs to customers through Terraform - How everything is documented and available on Gitlab - How we use Terraform to compare a Jamf Pro deployment to our template (useful for mergers and loose administrators that don’t like processes!) We’ll also share and demonstrate a custom open-source web-based tool we created that allows you to easily customize a Git template Jamf Pro config, create a fork in your repo with these customizations, and then deploy it automatically through CI/CD and Terraform. It’s easy to deploy and you configure your IdP for authentication. Resources and projects we use for this session: Terraform Provider https://github.com/deploymenttheory/terraform-provider-jamfpro Go API SDK Jamf Pro https://github.com/deploymenttheory/go-api-sdk-jamfpro Mac Admins Slack Channel - #terraform-provider-jamfpro https://macadmins.slack.com/archives/C06R172PUV6
Automating the Mac Lifecycle: From Tedium to Triumph with Jamf Pro, Okta and GitHub Actions
This session shares our journey to automate the developer Mac lifecycle by tackling the challenges of manual tracking, security gaps and inefficient workflows. We’ll provide a deep dive into our end-to-end solution, built using Jamf Pro, Okta, Slack and GitHub Actions. Attendees will learn how we: - Automated device refresh workflows to reduce IT intervention and improve the user experience - Integrated Okta to trigger actions like device locking for departed users, enhancing security - Used the Jamf API and GitHub Actions for custom automation, including device tagging and Slack notifications - Implemented reclamation processes to streamline replacement and boost security - Automated device retention processes, including status management, unmanaging, and removal from Jamf Pro This session highlights the measurable impact of our automation efforts—saving over four hours of manual work each week, improving our security posture and increasing IT efficiency. Attendees will leave with practical strategies for automating Mac lifecycle management in environments of any size.
A Year in the Life: Implementing Device Compliance and Conditional Access on a Global Scale
This session explores today’s evolving landscape of device compliance and security management. As the demand for secure, compliant environments grows, we’ll share our journey and the practical solutions we’ve implemented—offering insights that can be applied across a wide range of organizations. Attendees will walk away with actionable strategies for navigating Conditional Access implementations while balancing strong security with a positive user experience. Learning Objectives: - Understand the technical and non-technical challenges in implementing Microsoft Conditional Access using Jamf Pro Device Compliance. - Learn effective strategies for piloting, testing, and identifying potential issues in Conditional Access implementation. - Gain insights into documenting processes and creating self-solve options for users to enhance compliance. - Explore deployment phases and user communication strategies to ensure smooth implementation. - Discover potential issues, workarounds and solutions, including collaboration with vendor support. Methodologies: - Case study presentation - Interactive Q&A sessions - Demonstrations of custom solutions and tools - Sharing best practices and lessons learned Anticipated Outcomes: - Attendees will be equipped with practical knowledge and strategies to implement Conditional Access in their own environments. - Enhanced understanding of user communication and engagement techniques to minimize friction during implementation. - Ability to troubleshoot and resolve compliance issues independently using documented processes and self-solve options.
Behind the App: Building macOS Desktop Apps with Background Services
In modern enterprise Apple environments, security, automation and user experience must go hand-in-hand. This session provides a deep technical dive into building macOS desktop applications that integrate seamlessly with privileged background services like LaunchAgents and LaunchDaemons - bridging the gap between user-facing apps and system-level tasks. Attendees will learn: • How to architect a macOS desktop app that securely communicates with a background LaunchAgent or LaunchDaemon. • When to use LaunchAgents vs. LaunchDaemons and how to handle entitlements, sandboxing and elevated privileges. • Real-world enterprise use cases such as enforcing security policies, triggering Jamf MDM commands and notifying users based on compliance status. • Best practices for secure IPC using XPC, UNIX sockets or the new SMAppService API. • How to navigate notarization, the hardened runtime and minimize user fatigue from privacy/TCC prompts. • How to deploy and manage the app and agent via Jamf Pro, including auto-updates and compliance enforcement workflows.
Building Security Remediation Workflows for Beginners
Compromised devices can be scary but responding to those threats doesn't have to be manual or complex. Building Security Remediation Workflows for Beginners is an enterprise-focused, beginner-friendly session, delivered to help Jamf admins and security professionals learn how to leverage the magic of Jamf to design and implement automated response workflows. By leveraging Jamf Pro, Jamf Protect, the Jamf Security Cloud and Jamf Connect's Zero Trust Network Access (ZTNA) capability, this presentation demonstrates how attendees can use Jamf to detect potentially malicious activity on iOS and macOS devices, quickly isolate them, and contain threats, along with automatically reversing applied restrictions once the threat has been eliminated. This session is ideal for enterprise IT and security teams seeking to integrate Jamf's suite of products into a unified response strategy that minimizes risk, reduces time-to-containment, and avoids adding operational overhead. Key discussion points: • Designing scalable, automated remediation workflows for Apple devices in enterprise environments. • Leveraging Jamf Protect and the Jamf Security Cloud for rapid threat detection. • Using Jamf Pro, Jamf Protect and the Jamf Security Cloud to isolate devices. • Securing corporate resources using Jamf Connect’s ZTNA capability. Learning outcomes: • Understand the foundational components of an enterprise-grade remediation workflow using Jamf tools. • Learn how to automate detection, containment and recovery actions across macOS and iOS fleets. • Explore how Jamf integrates into your security response. • See how Jamf empowers security teams to operate efficiently at scale.
Build the Best Onboarding Experience
First impressions are crucial when it comes to onboarding. The moment an end user interacts with IT, it sets the tone for the entire relationship. A smooth, transparent and efficient onboarding process not only helps build trust with IT and the organization but also ensures that security and best practices are implemented from the start. In this session, we’ll explore how to make that first interaction a great user experience, making your endusers fall in love with IT. We’ll begin by discussing the key tools you’ll use to streamline the onboarding process, including Automated Device Enrollment, Configuration Profiles, Jamf Setup Manager and macOS Onboarding. These tools will empower you to automate the majority of the onboarding workflow. The session will cover various onboarding workflows, from zero-touch to single-touch deployments, and explore the distinction between user-driven and IT-driven processes. You’ll learn how to handle user creation and understanding the difference between user and machine configurations. Lastly, we’ll discuss how to ensure your users are fully supported and ready to get to work. We’ll explore current solutions like old fashion PDFs manuals or swiftDialog workflows, and show you a new solution we (Jamf) are currently working on with customers to guide their end users with helpful prompts, messages and instructions during the setup process. By the end of this session, you'll have the knowledge and confidence to create the best onboarding experience that will help your end-users hit the ground running while maintaining security and compliance and build the trust with your IT department and organization.
But Why?! A Security-Focused, User-Experience-Forward Plan is Required in K-12 Education
In this session, we will discuss the imperative for K-12 educational institutions to protect student data and other personally identifiable information. We'll discuss the challenges of a small staff and low funding along with simple steps you can do to make your site more secure by using Apple and Jamf.
Collaborative Governance: Aligning IT and Security Goals for Effective Risk Management
In today's evolving threat landscape, protecting information and assets requires something not usually seen: forged partnerships between IT and Infosec. This session explores communication barriers and common obstacles that may hinder effective collaboration, as well as some ways to leverage Jamf Pro and Jamf Protect to strengthen partnerships and enhance security.
Compliance Benchmarks in Jamf Pro: From Complex Scripts to Simple Clicks
In today's rapidly evolving cybersecurity landscape, maintaining compliance with security benchmarks is no longer optional - it's a critical business requirement. Organizations face increasing pressure to demonstrate adherence to industry standards while efficiently managing their Apple fleet. This session showcases Jamf Pro's revolutionary compliance benchmarks feature, which transforms complex security compliance management from labor-intensive, manual scripting to streamlined automation. Through detailed technical demonstrations and real-world implementation examples, you'll discover how organizations can efficiently implement, monitor, and validate CIS benchmarks while maintaining continuous compliance across their macOS fleet. We'll explore the journey from traditional approaches using manual mSCP scripts and Jamf Compliance Editor to the seamless integration now available in Jamf Pro. A featured customer success story will illustrate the transformative impact of this evolution, sharing concrete metrics on time savings, security posture improvements and operational efficiency gains. Whether you're currently managing compliance through scripts or want to strengthen your security stance, this session provides actionable insights for organizations of all sizes. You'll learn: - How to assess your current compliance state and plan your implementation. - Step-by-step workflow for deploying CIS benchmarks. - Strategies for continuous monitoring and reporting. - Real-world migration patterns and lessons learned from successful implementations. - Methods to demonstrate compliance to auditors and stakeholders. This technical session bridges the gap between security requirements and practical implementation, offering both strategic insights and hands-on technical guidance for achieving and maintaining compliance in your environment.
Configuration Profiles 3.0: Everything Everywhere All at Once
This session introduces the motivation behind and future direction of Configuration Profiles 3.0—a revolutionary new Blueprint component and a key advancement in modern MDM. This solution builds on familiar tools like MDM configuration profiles and combines them with new capabilities such as declarative management and Blueprints. Designed to address some of the biggest challenges faced by Mac admins, Configuration Profiles 3.0 enables a faster, more efficient “sooner than same-day” approach to device management. As one of Jamf’s bottom-up innovations, this project has evolved into a core part of our Modern MDM strategy. Led by the project’s founder and tech lead, this session offers a behind-the-scenes look at how Configuration Profiles 3.0 came to be, what it means for the future of device management, and how all customer segments can benefit by adopting this new approach. Time will be reserved for audience questions.
Connect People and IT Even More With Support App and Advanced Jamf Workflows
What is the Support App? It is a free and open-source macOS menu bar app built for organizations to:
- Help users and IT to see basic diagnostic information at a glance and proactively notify them to easily fix small issues.
- Offer shortcuts to easily access support channels, other company resources such as a website, file server or more, and run advanced workflows with elevated privileges
- Give users a modern, native and easy-to-use macOS app with your corporate identity
This session is follow-up session for the following session from JNUC 2021: Support App, quick access to IT and resources, easily integrated with Jamf | JNUC 2021. Link to session: https://www.youtube.com/watch?v=LijCmR6gQAM. The session from 2021 was an entry-level session introducing the Support App and how to configure it easily using a Jamf JSON manifest.
This new session is a deep-dive into the more advanced options and new features introduced in the last couple of versions. It will be mostly targeted to existing Support App users, but a general overview of the app will also be included — so it is also great for new users exploring the app. Root3 is using the Support App in many Jamf environments and it is used by many others all over the world. The Support App is proven to be very successful in connecting people with IT. We’d like to demonstrate new ways and ideas from the community about how the app can be leveraged to close the gap between people and IT and provide relevant information and actions. Some examples are:
- Obtaining information about Jamf
- Allowing easy check-ins
- Reporting compliance using the macOS Security Compliance Project
- Declarative Device Management update information
- Temporary privilege elevation with Jamf Connect
- Showing Jamf Pro payload variables
- Generating logs with one click
- Updating apps with the Root3 App Catalog
All this is driven by the Support App and Jamf Pro.
Key topics are focused on advanced use cases together with Jamf to enhance the user experience. The presentation will start with some basics about the app and summarizing recently introduced (major) features. As we expect most people attending the session already know the app, the main focus will be more advanced usage where the app will be used together with scripting and elevated privileges by the built-in privileged helper tool.
We feel the Support App enhances the user experience with the help of Jamf products. It’s more important than ever to provide a great experience to have happy and productive users in organizations. For example, a choose-your-own-device program can benefit from a tool like the Support App, which is also part of the Jamf Marketplace.
We'll share real-world examples, inspiration and experiences you can take back, tailor and use within your own organization. You can implement some of the presented ideas as those will be shared on GitHub or use them to create new ideas. It will also highlight Jamf features that you may be unfamiliar with, such as Jamf JSON manifest files, payload variables for Configuration Profiles, temporary elevated privileges using Jamf Connect and macOS update scheduling using Declarative Device Management.
Crowning Achievements: How Jamf Helps Power Innovation at ECU SoDM
Managing Apple devices in a clinical and educational environment presents unique challenges. At ECU School of Dental Medicine (SoDM), Jamf is more than just an MDM—it’s a key tool for streamlining support, enforcing security and enhancing the user experience. This session will explore how SoDM leverages Jamf to manage Apple devices, integrates with tools, automates workflows and improves IT efficiency. We will explore how we develop and apply policies for faculty, staff and students and the impact these have on their day-to-day experience. We’ll discuss how these policies impact SoDM, share strategies for balancing compliance and usability, and highlight real-world automation and reporting examples that maximize the value of Jamf.
Demystifying Custom Analytics for Jamf Protect
Jamf Protect (macOS portal) comes with a multitude of Jamf-managed analytics. However, there are times when customers need to monitor activity that is specific to their security requirements or individual circumstances.
-
This talk aims to demystify how to create, test and deploy custom analytics. In this session, we will:
- Understand what an analytic is by looking at some existing ones
- Look at event types and their capabilities, including attributes available
- Look at analytic chains
- Deep dive into predicates, using various examples
- Look at some of the tools we can use to get information that the predicate may require
- Go over examples of using ‘and’ and ‘or’ boolean logic in the predicate
Employee Engagement and Operations: The Automated Way
By leveraging Jamf Pro, Microsoft Logic Apps, ServiceNow and internally-developed applications, we have automated numerous tasks. During the session, we will delve into topics such as setting up Jamf Pro with Smart Groups, webhooks, and API roles and clients. We'll explore how we utilize Microsoft Logic Apps as our automation platform. Additionally, we'll discuss strategies for engaging employees using email, Teams, and ServiceNow action items. At the end of our session, we hope that the audience will depart with a mindset focused on the art of possibility, asking themselves, "What can we do?"
Enterprise Security Standards in Action: The future of identity integrations with SSF and CAEP
In this session, we'll walk through how Jamf and partner platforms like Okta, SGNL, and SailPoint work together using SSF/CAEP to enforce policy based on real-time compliance — all without complex custom integrations. Whether you're looking to reduce risk, improve automation or meet modern compliance requirements, this session will show you how a standards-first approach is making it easier than ever for the industry to build secure, adaptive access experiences.
Exploring Serialized Data Formats for Fun and Profit
There are many serialized data formats, but three of them, XML, PLIST and JSON, stand out against the background when managing Apple operating systems. In this session, we will explore these formats, from their simple specifications to more complex examples, helping to build up our mental models. We will also compare their similarities and differences and get to know the tooling that comes preinstalled on our Macs, using them to manipulate and extract data from these formats.
Extension Attributes: A Year in the Life of an Admin
Last year, we introduced Extension Attributes through the lens of our admin, Jill. A lot has changed for Jill's organization over the last year, and we will explore how the versatility of Extension Attributes allowed Jill to better manage and secure all the devices in her fleet. While Mac is still a focus of Jill's department, a recent acquisition by her organization has introduced a large number of mobile devices into her environment. Jill is now managing Macs, iPhones and iPads, and Extension Attributes allow her to track the most important information for her organization fully. Come join us to learn all the ways Extension Attributes help Jill.
Flawless MDM Communication
Do you ever feel like your computers are not checking in as regularly as they should be? Are inventory reports inconsistent with devices checking in while at the same time not updating their inventory? Do you have policies and configuration profiles scoped to devices that are not applying as timely as you’d expect? How about your security posture/compliance reports; do they ever hit 100%?
We get it, and we feel your pain. As a Managed Service Provider, managing numerous Jamf instances encompassing thousands of devices, we’ve spent countless hours diagnosing communication issues.
Join Mann Consulting as we share our workflows to detect and repair MDM communication issues. We’ll also share best practices to ensure your computers are always in communication.
Attendees will…
- Learn the different ways computers communicate with Jamf
- Learn how to leverage each of these methods as a check and balance to verify the others are working properly
- Learn common scripting and workflow best practices to keep MDM communications flowing
- Know third-party risks to your MDM communications
Flawless MDM Communication: Scripting Edition
Did you know that scripts in Policies and Extension Attributes can cause major disruptions in day to day Jamf communication? Building off our successful session last year Mann Consulting returns to discuss strategies when writing scripts to run in Jamf to ensure a secure and reliable way to meet your organization's goals while providing a seamless experience for end users. Pull up a chair and close your laptop. Attendees will… * Learn how scripts can impact your employee experience. * Learn strategies for centrally logging all scripts for easy error reporting. * Get access to script functions we use internally!
Forged in Fire: Building Team Unity Through the Chaos of Endpoint Management
Managing thousands of endpoints is challenging, but building a high-performing, unified team in the middle of that chaos is where the real transformation happens. In this session, learn how one IT Endpoint team responsible for managing over 6,000 macOS, Windows and BYOD devices turned constant firefighting into focused execution by aligning around people, purpose, and process—with Jamf at the heart of the journey. We’ll break down how the team stabilized operations by introducing agile workflows, segmenting work streams and creating a dedicated frontline operations layer to shield engineers from day-to-day noise. You’ll also see how Jamf tools enabled automation, improved visibility and gave the team the confidence to shift from reactive to proactive support. Attendees will walk away with practical strategies for structuring teams, enabling focus and leveraging Jamf to support scalable, people-first endpoint management. Whether you’re an admin looking for ideas to take back to your team or a leader aiming to elevate team performance and culture, this session offers a blueprint for building resilient, mission-driven teams that deliver lasting impact.
From Data to Decisions: Navigating Jamf Protect’s Custom Analytic and Unified Logging
Custom Analytics and Unified Logging are powerful functions that help you monitor and understand user behaviors while utilizing the computers within your organization. However, these functions are often underutilized, especially in Japan, due to their complexity and lack of beginner-friendly resources.
In this session, we will guide you through the entire process of creating Custom Analytics and Unified Logging filters, from the basics to the final results.
This will include:
- The concept and benefits of Custom Analytics and Unified Logging
- Methods of gathering relevant events’ data by using built-in and open-source tools
- Step-by-step guidance on utilizing events’ data to create filters
- Best practices for integrating and deploying these filters within the organization
You'll learn how to utilize all this and more through practical examples, tips and tricks to make the most out of these functions and set your IT team up for success.
From Idea to Implementation: The Making of the AI Assistant's Knowledge Skill
The Knowledge Skill of Jamf's AI Assistant (previously known as Ask Jamf) was designed to enhance your support experience. But how did it come to be? In this deep dive session, we'll take you behind the scenes and share the development story. Since last year's JNUC, our Support and Data Science teams have collaborated to develop and refine the Knowledge Skill. You'll discover how our support team's hands-on experience and feedback have directly shaped the tool, ensuring it is primed to meet your needs. You'll learn about the journey, from a promising prototype to the cutting-edge tool it is today.
We'll dive into the technical details of how we leveraged an advanced retrieval-augmented generation (RAG) workflow to create a multi-stage retriever that searches Jamf data sources to find the answers to your questions. Get ready to dive into the fascinating story behind the AI Assistant's Knowledge Skill and learn how it's poised to become an indispensable asset for you and your team.
From Patch to Progress: The Evolution of the Jamf App Catalog with App Installers
Managing software updates at scale has long been a complex, time-consuming challenge for IT teams. Traditional patch management workflows, while essential, often require constant oversight and manual effort. In this session, we will explore how Jamf is shifting towards smarter, hands-off software delivery through the evolution of the Jamf App Catalog and the rapid growth of App Installers. We will cover the scale we operate at, highlight key advancements from the past year, and show how App Installers streamline app deployment and maintenance. With practical guidance, examples and integration tips, this session will help Jamf admins confidently move from patch to progress and manage app lifecycles more efficiently than ever before.
From Testing to Production: How to Adopt Blueprints in Jamf Pro from an Admin’s Perspective
This session will spotlight Blueprints as a powerful tool for modern Apple device management and show how transitioning to this method can improve the admin experience, especially in complex, multi-campus environments. Attendees will hear directly from both the creators of Blueprints and a customer who adopted it, from initial testing to full production deployment. Michael Managhan and Jakub Talaš, the developers behind Blueprints at Jamf, will join Chris Hafner from Brewster Academy, who helped shape the feature during beta testing and now leverages it for their ambitious international expansion. Hafner will share Brewster Academy's real-world journey: managing hundreds of devices across New Hampshire and Spanish campuses, the challenges of deploying units during a complete IT infrastructure rebuild, and how Blueprints simplified complex update processes and security configurations. Whether you're new to Blueprints or unsure how to begin implementation in your educational or multi-site environment, this session offers practical insights, implementation tips, and peer-driven advice to help you gain confidence and take the next step.
Have Your Cake and Eat It Too! Maximizing the Jamf Platform with Your Microsoft Licensing
This session will explore how the Jamf platform integrates with Microsoft Power Automate to optimize workflows and boost automation across shared environments. Attendees will learn how to leverage these tools to automate routine tasks, enhance security and develop effective IT solutions. Through real-world examples and best practices, the session will demonstrate how Jamf Routines can trigger Power Automate actions using the Jamf Pro API for streamlined device management. Participants will leave with practical templates and a clear understanding of how to harness these technologies to drive innovation and deliver a top-tier Apple experience.
Hello Compliance Benchmarks, Ciao Jamf Compliance Editor
Jamf compliance benchmarks is an exciting new feature that Jamf admins have been wanting for a long time. It was announced at JNUC24, now it’s time to see how it works! You’ll hear how we moved to the compliance benchmarks after having enforced CIS Level 1 using the well-known Jamf Compliance Editor in our enterprise. Is early adoption of compliance benchmarks worth it? Join us to learn about the new features it gives us and help you decide if moving should be on your to-do list or not.
Huh? To H.E.R.O. - How to Use the H.E.R.O. Method to Improve Your Jamf Pro Instance
As a Jamf administrator, you will inevitably encounter moments in your career where you inherit or set up a Jamf Pro instance that needs improvement. Perhaps you walk into a new job and find yourself wondering, "Why was this done this way?" or "This isn't how I was trained to do it." This session will guide you through the process of transforming that Jamf Pro instance—whether it's a new setup or a legacy one—into a Healthy, Efficient, Reliable and Optimized environment using our H.E.R.O. method. Join two experienced Jamf administrators who have taken on the challenge of overhauling Jamf instances and learned a lot along the way. You'll leave with practical strategies for auditing, streamlining, and improving your Jamf Pro environment—ultimately helping you become a H.E.R.O. in your own instance. By the end of this session, you'll walk away with a clear framework for transforming your Jamf Pro instance into a lean, efficient and well-documented environment, ultimately saving time, resources, and stress for your team. Don't miss out on becoming a Jamf H.E.R.O.!
In the Trenches with Platform SSO, Okta, Connect, and Network Relay at Jamf
How is Jamf handling its evolution from Jamf Connect to an environment enriched with Platform SSO, Network Relay, and Managed Device Attestation? Come join Jamf IT and Product leaders to see how Jamf@Jamf is thinking about and deploying these technologies across its fleet of global Apple devices. We’ll be spending most of our time in product consoles exploring configuration details, so be ready for a highly interactive and engaging session!
Introducing Compliance Benchmarks for Jamf Pro
Compliance has often times been a complex maze for Apple admins to navigate. It is difficult to understand where to begin, what baselines to consider and how to use Jamf products to achieve the compliance outcomes that your organization requires.
In this session, we will cover:
- What it means to have compliant Apple devices
- How to choose the right level of compliance for your organization
- How to configure Jamf to audit and enforce compliance standards
- How to deal with non-compliant devices with Conditional Access policies
Jamf and Okta - Onboarding and Passwordless Authentication with Okta Device Access
A fully trusted access solution ensures that only authorized users on enrolled devices that are secure and compliant can access sensitive data. Okta and Jamf are essential together to make this solution. In this session, we will discuss the differences between Jamf Connect and Okta Desktop Access (Okta's Platform Single Sign-on implementation), how to onboard both tools, and where tools like Desktop MFA, FastPass, Jamf Trust and Network Relay can be used to make a solution that users love and admins trust.
Jamf API CLI Tool: One Solution for Secure Jamf API Access in Policies and Scripts
Using the Jamf API with policies and scripts in a secure manner can sometimes be a daunting task. This session will present a tool that allows you to use the Jamf API without exposing sensitive credentials in the policy or script.
The tool is a command line utility that, when called, provides an API Bearer token key and its expiration information without exposing the underlying credentials on the computer it is called from.
This session will discuss the following main topic points:
- How the tool works and why you may want to use a tool like this
- An overview of the security model behind the tool
- Setting up and building the tool
- How the tool simplifies your scripts that use the Jamf API
- Handling potential misuse of the tool
The use of Jamf API calls with policies and scripts in a secure manner is an important topic in both new and existing Jamf implementations.
This session hopes to present one potential solution for this task and hopefully bring a small spotlight to a sometimes neglected focus area of device management.
Jamf Concept’s remediaSOAR: Leveraging Jamf APIs to Transform Security Alert Management
The power of Jamf's APIs enables innovative solutions for complex security challenges. In this session, we'll dive into how remediaSOAR was built by leveraging Jamf's robust API ecosystem to create a unified security alert management platform. We'll explore how to: - Utilize Jamf Protect’s API to retrieve and process security alerts. - Leverage Jamf Pro's API for direct remediation actions. - Integrate with Jamf Security Cloud's API for risk score management. - Build cross-platform solutions that extend Jamf's capabilities. Through practical demonstrations and examples, we'll show how remediaSOAR connects these APIs to create a seamless security management experience. Whether you're a developer looking to build your own Jamf integrations or an admin seeking to understand the potential of Jamf's API ecosystem, you'll gain valuable insights into extending Jamf's capabilities through API integration.
Jamf Pro Performance Tuning: Extension Attribute Audit
Computer extension attributes—used to collect additional inventory data from Macs—are one of the most powerful and flexible features in Jamf Pro. By using the Script input type, admins can gather nearly any client-side setting and take action based on the results. After feedback from internal beta testers using the new JNUC 2024 Inventory Update Progress script, it became clear that an extension attribute audit was long overdue. In this session, you'll learn how to apply Sir Dave Brailsford’s “aggregation of marginal gains” philosophy to optimize your extension attributes for performance and accuracy. While some edge cases saw 18x to 24x improvements, the average performance gain across our audit was 7x.
Jamf Protect Template: A Simple Template to Notify End Users on Remediation
Are you looking to deploy your Jamf Protect macOS remediation scripts but are unsure where to start? Or perhaps you want to provide end-user notifications during remediation? The Jamf Protect Template has you covered. This script allows you to house all your remediation scripts within Jamf Pro, leveraging swiftDialog to power end-user notifications, offering a customizable and consistent experience for administrators and users alike.
In this session, you'll learn how to utilize Jamf Protect Analytics, leverage Smart Groups with Jamf Pro and deploy the Jamf Protect Template. We will begin by discussing how to configure your analytics within a Jamf Protect Plan and how to add those analytics to an extension attribute in Jamf Pro. Finally, we'll cover adding your scripts to the Jamf Protect Template and discuss considerations for your own remediation scripts.
Jamf School and MacOS--What's New? Zero-Touch Deployment and So Much More.
This session explores the new capabilities of macOS Automated Device Enrollment (ADE) in Jamf School. Speakers will demonstrate how to deploy a macOS client with integrated tools such as Jamf Connect, Jamf Protect and Jamf Safe Internet. Attendees will also learn how to use Jamf Setup Manager with Jamf School to enable customized deployments, resulting in a fully configured macOS client that’s ready for use.
Just Enough of a Good Thing: User-Friendly and Database-Optimized Inventory Updating
Providing users with detailed feedback on inventory updates is only half of the story. To help avoid performance issues and database bloat, Jamf Support recommends updating inventory for any single Mac a maximum of twice daily. In this session, you’ll learn how to easily provide your users with detailed feedback and limit inventory updating to a duration you specify. You'll also see a real-world example of leveraging swiftDialog for your upcoming projects.
K-12: Jamf in a Chromebook (and Windows) World
In this session, explore the technology backbone of Naperville Community Unit School District 203 (D203), a leading Illinois district. Supporting thousands of users, SD203 runs on a mix of Google, Microsoft and Apple systems, with Google Drive at the center of student and staff collaboration. Chromebooks are common for students, while Apple devices support music, art and media. We'll cover how MacBooks and iMacs fit into the larger system, including Jamf for device management, software deployment, and navigating cross-platform challenges. We'll also touch on Jamf vs. Intune for managing Apple devices. You'll leave with a clear view of how SD203 keeps its multi-platform tech running smoothly for learning and work.
Kentucky Fried Patching
Join us for an informative session where we discuss our patch management journey at Yum! Brands from start to finish. We'll begin by sharing our patch management goals and the process that led us to choose Jamf Auto Update. Learn how our proof of concepts guided us and hear about our collaboration with the Jamf team. The main event will cover all aspects of Jamf Auto Update: an introduction to this tool, its features, our rollout strategy and the decisions we made during configuration. Additionally, we'll present some patching statistics from before and after deploying Jamf Auto Update. Come learn how Yum! approached patch management with the help of Jamf Auto Update.