Always Connected, Always at Risk: How AI is Reshaping Mobile Security
Let’s be honest—most of us practically live on our phones. They’re always on, always connected and always on the move. That makes them prime targets, and the bad actors know it. Using AI, they’re crafting smarter scams, fake networks and apps that look real but are designed to steal your data. In this session, we’ll explore how mobile security is evolving; it's no longer just about securing the device, but also what it connects to. Verizon is leading the charge by embedding protection directly into the network, blocking threats and suspicious connections before they ever reach the device. Paired with the right solution, like Jamf, this creates a powerful layer of mobile defense. We’ll also discuss how AI is shaping the future of security—for both attackers and defenders—and how network-level protection combined with endpoint security can proactively stop threats. This isn’t a sales pitch—it’s a real look at where mobile security is headed and how we’re helping lead the way. If you're looking to stay ahead of mobile threats, especially on iPhones and iPads, this session is for you.
Automating Jamf Security Platform Configuration
In this session, we will discuss the different approaches an organization can have towards managing an API based SaaS tool. We will focus on automating the configuration of our Jamf Security platforms. Our talk will focus on Terraform as the chosen IaC platform for what we built and we will then dig into how we built a Terraform Provider to support our Jamf Security platforms. Additionally, this session will reference information discussed in the “Infrastructure as Code with Jamf” and “Automating Apple Endpoint Management” sessions. This will include referencing the Jamf Pro Provider written by Lloyd’s of London and discussing our Onboarder tool built around using that Jamf Pro Provider as well as the Provider we will be covering in this session.
Binary Insight: Opening Up Jamf Threat Labs Scanning to Customers
In today's evolving threat landscape, security teams need efficient ways to validate files without compromising endpoint security. Jamf Threat Labs binary scanning service addresses this challenge by providing a cloud-based interface to Jamf Protect's detection capabilities. This session covers how this service got built, the problems it solved internally at Jamf, and how organizations can use this service to submit file hashes or binaries for analysis against Jamf Protect's detection engine without requiring local execution or endpoint deployment. We'll explore real-world applications, from validating internal applications before deployment to investigating suspicious files in a secure environment. Security professionals will learn how this service integrates into existing workflows, enhancing threat hunting capabilities while reducing risk. The session includes live demonstrations of the service, practical examples, and best practices for incorporating this tool into security operations. Whether you're a security administrator, developer, or IT professional, this session will demonstrate how cloud-based binary scanning can strengthen your security posture while streamlining validation processes.
Context is Key: Leveraging Contextual Insights to Drive Effective Security Remediations
With great alerts comes great responsibility. In this session we’ll explore how we can take the great information and alerting capabilities of Jamf Protect and combine it with Jamf Pro to provide effective security remediations. We’ll look at how and why we might want to consider this approach and why good enough isn’t really good enough. If we can do better for our organization and our users, we should! We’ll look at the macOS security portals API and how we can interact with it to get the right information we need for an effective security response. If you’ve never interacted with an API before or don’t know what that even means, don’t worry! We’ll give a look into what an API is, the types of API that Jamf uses and some of the differences before going right into how we get the context we need to create an effective security remediation.
From Patch to Progress: The Evolution of the Jamf App Catalog with App Installers
Managing software updates at scale has long been a complex, time-consuming challenge for IT teams. Traditional patch management workflows, while essential, often require constant oversight and manual effort. In this session, we will explore how Jamf is shifting towards smarter, hands-off software delivery through the evolution of the Jamf App Catalog and the rapid growth of App Installers. We will cover the scale we operate at, highlight key advancements from the past year, and show how App Installers streamline app deployment and maintenance. With practical guidance, examples and integration tips, this session will help Jamf admins confidently move from patch to progress and manage app lifecycles more efficiently than ever before.
Have Your Cake and Eat It Too! Maximizing the Jamf Platform with Your Microsoft Licensing
This session will explore how the Jamf platform integrates with Microsoft Power Automate to optimize workflows and boost automation across shared environments. Attendees will learn how to leverage these tools to automate routine tasks, enhance security and develop effective IT solutions. Through real-world examples and best practices, the session will demonstrate how Jamf Routines can trigger Power Automate actions using the Jamf Pro API for streamlined device management. Participants will leave with practical templates and a clear understanding of how to harness these technologies to drive innovation and deliver a top-tier Apple experience.
Help! How Can We Integrate Jamf’s Security Solutions Into Our Microsoft Security Stack?
One common objection to adopting Jamf Protect—and Jamf Pro for response actions—in a mixed Windows / macOS environment is: “We already have Microsoft Defender XDR and Microsoft Sentinel with our E5 / A5 licenses—why add anything else?” Security teams and SOC analysts often worry about unfamiliar tools, new runbooks, and the effort required to wire everything into existing SOAR workflows. That hesitation overlooks a key fact: Jamf and Microsoft have co-engineered native, low-friction integrations. Jamf telemetry streams straight into Microsoft Sentinel, while device and identity signals pass through Microsoft Entra ID and Intune. You get best-of-breed macOS protection without sacrificing the single pane of glass you already know. During the session, presenter Simon Binder, Lead Architect, Advania - Knowledge Factory, draws on real-world examples to break down the perceived roadblocks and demystify the alphabet soup—XDR, SIEM, SOC, SOAR, EDR—so everyone starts from the same baseline. Using demonstrations, Binder will walk through the end-to-end connection of Jamf Pro and Jamf Protect to Sentinel, threat-hunting with KQL across Jamf and Windows data side by side, and automated incident response that chains Sentinel playbooks, Jamf remediation commands, Defender XDR alerts, and other Azure services. Attendees will leave knowing: - Why pairing the platform leaders—Jamf for macOS, Microsoft for Windows—delivers a stronger defense than a single-vendor approach. - How Jamf plus Microsoft extracts full value from the E5 / A5 stack they already own. - Exactly what a SOC needs in skills, runbooks and governance to make macOS a first-class citizen in detection and response. The result is a team better prepared to counter cyberattacks and to maximize its security investment across platforms and vendors.
Jamf Concept’s remediaSOAR: Leveraging Jamf APIs to Transform Security Alert Management
The power of Jamf's APIs enables innovative solutions for complex security challenges. In this session, we'll dive into how remediaSOAR was built by leveraging Jamf's robust API ecosystem to create a unified security alert management platform. We'll explore how to: - Utilize Jamf Protect’s API to retrieve and process security alerts. - Leverage Jamf Pro's API for direct remediation actions. - Integrate with Jamf Security Cloud's API for risk score management. - Build cross-platform solutions that extend Jamf's capabilities. Through practical demonstrations and examples, we'll show how remediaSOAR connects these APIs to create a seamless security management experience. Whether you're a developer looking to build your own Jamf integrations or an admin seeking to understand the potential of Jamf's API ecosystem, you'll gain valuable insights into extending Jamf's capabilities through API integration.
Jamf @ Jamf: Zero Trust, Zero Fuss.
Discover how Jamf has implemented a zero trust strategy that strengthens security and elevates the user experience across all our devices; iOS, macOS, Windows and Android. This session dives into Jamf's real-world zero trust framework showing how we align identity, device trust and data sensitivity to create a seamless and secure workflow. We'll walk through real policies, implementation strategies and business value behind Jamf's modern access management framework. You'll leave with a practical blueprint and see a live demo that rewards secure behavior with frictionless access, proving that security doesn't have to come at the cost of usability.
Jamf School Health Check: Digging Deep for a Healthier Environment
Ready to transform your Jamf School environment from "just working" to "working brilliantly"? In this session, we'll take you through the Jamf School Health Check, a proven service to identify opportunities, eliminate inefficiencies and elevate your device management strategy. Like panning for gold, we'll sift through the layers of your setup, token status, profile structure, app deployment, scoping practices and more to uncover valuable improvements. You’ll learn how to address common pitfalls, routine actionable items to maintain a secure, scalable and classroom-friendly environment. Whether you're new to Jamf School, managing hundreds of devices across multiple sites, or inherited a production environment, a Jamf School Health Check will help you turn everyday workflows into pure gold.
Jamf Trust
How American Airlines deployed Jamf Protect to secure their mobile devices and provide compliance across a mobile workforce.
Maximizing the Value of Your Apple Hardware with G.O.A.T.
In this session, we’ll explore how Galide’s Operational Asset Tracking portal and Jamf API integration help streamline the entire device trade-in process. We’ll also delve into best practices and strategies you can use to maximize the residual value of your organizations Apple and non-Apple inventory.
Soaring with Jamf Protect
Jamf Protect with Jamf Pro allows you to create customized remediation workflows to respond to security threats and malicious activity. With these tools, we can create Security Orchestration, Automation and Response (SOAR) workflows for our Mac endpoints. This session will explain how to set up Jamf Protect to look for specific malicious activity or behavior on your Mac endpoints and then implement workflows to remediate the situation as well as collect additional forensics data for further analysis. Key discussion points: • Configuring Analytics and plans in Jamf Protect. • Configuring the remediation workflow between Jamf Protect and Jamf Pro. • Presenting information to the user. • Example real-world SOAR collection playbooks: • Endpoint network isolation • Quarantined file acquisition and removal • Aftermath - collect additional data from the host and store it in a secure repository Learning outcomes • Understand how the integration of Jamf Pro and macOS Security Portal provides remediation capabilities. • Learn how to keep users informed of the ongoing incident response. • Learn how to automate detection, containment and recovery actions across macOS endpoints. • See how Jamf provides security teams with the ability to forensically analyze security events. The session will include a mixture of high-level theory, setting out how analytics are configured with Jamf Pro policies, as well as providing real-world workflows. We start by discussing how analytics are configured in Jamf Protect to detect malicious activity and then respond by triggering a Jamf Pro policy to remediate. The main part of the session is to dig into these workflows. We will discuss how to classify your workflows with a threat level, thus determining the method of remediation or response. Some workflows may be required to be fully automated with no user interaction, others you may wish to engage the user with either some useful information via alerts using software such as SwiftDialog or even take them to a Self Service Policy. We will dig into a few useful workflows including handling quarantined items and uploading the quarantined file to a cloud storage solution for further analysis, isolating the Mac endpoints network to prevent it from communicating to other network endpoints and the use of Aftermath to collect further forensic data which you can upload to a cloud storage solution.
The new security endpoint with Chrome Enterprise and Jamf
In today's rapidly evolving threat landscape, securing endpoints has become more critical than ever. This session will explore how Chrome Enterprise and Jamf can work together to create a new standard for endpoint security. We'll delve into the latest management and security capabilities that can support your organization.
Threat Modeling: Practical Mac Security in the Zero Trust Era
Threat modeling is an approach to analyzing and identifying threats that threaten an organization or system. We use security products such as Jamf on a daily basis to improve the security of our organization, but we cannot effectively promote security measures unless we have a bird's-eye view of the overall threats surrounding our organization. In this session, we will guide you the approach using threat modeling, from the basics to concrete practical examples. **This will include:** - Basic concepts and process of threat modeling - The usefulness of threat modeling in modern IT environments - Case studies with concrete examples You'll learn how to utilize all of these through practical examples, tips and tricks to use threat modeling to improve the security of your organization.
Unified Defense: How Security Analysts, Developers and Data Scientists Collaborate on ML-Powered Phishing Detection
In an era where phishing attacks are becoming increasingly sophisticated, traditional detection methods often fall short of identifying complex threats. In our mission to protect customers against evolving cyber threats, our approach combines the strengths of three specialized groups: security analysts, developers and data scientists. Our security analysts manage and monitor billions of requests and extensive blocklists, working around the clock to detect, investigate, and respond to potential threats. Supporting this frontline defense, our developers have built a powerful analytical pipeline that enriches raw data—transforming it into actionable insights that significantly enhance threat hunting capabilities. Meanwhile, our data scientists design, train and continuously improve machine learning models to boost detection accuracy and proactively identify emerging threat patterns. Our cross-functional collaboration focuses on delivering intelligent, scalable and proactive cybersecurity solutions to keep our customers safe. This technical session showcases how this unified approach has revolutionized our phishing detection capabilities through advanced HTML content analysis and machine learning and explores an innovative approach to enhancing phishing detection. We'll demonstrate the architecture and methodology of extracting meaningful features and patterns from HTML content to improve threat detection accuracy while maintaining performance. Attendees will learn how our approach combines human expertise with machine learning capabilities to create a more robust and intelligent security solution. We'll share practical insights into building and maintaining such a system, including technical challenges overcome and lessons learned in combining traditional security approaches with modern machine learning techniques.
Why your Mac is next: how amateur data stealers grew into full-scale cybercrime ecosystems hunting for your company’s data
While macOS has long benefited from its reputation as a secure platform, the threat landscape is evolving. In this talk, Moonlock, a cybersecurity division of MacPaw, will showcase how modern macOS malware now mirrors the sophistication and business models seen in the Windows world: from traffer teams to modular toolkits, and the implications this has for enterprise security. Attendees will gain insight into: – How macOS-focused malware evolves and adapts, often faster than defenders expect. – Real examples of infection chains that often use AI and scraped personal data to fool even cautious users. – The role of the darknet in facilitating the resale of stolen macOS data and malware kits. – How to protect yourself and your organization from being infected in early stages.
Workbrew: How to Unite Developers, IT Administrators, and Security Professionals
IT admins are under pressure to deliver secure, compliant environments with limited time and growing complexity. Meanwhile, developers are moving fast with tools like Homebrew—often outside the visibility of IT or security. The result? Blind spots, silos, and tension between speed and control. In this session, we’ll show how to bridge the gap using Workbrew - a tool loved by Jamf customers. You’ll learn how to bring Homebrew out of the shadows and into your managed environment. With Workbrew you’ll learn howHomebrew can become a shared asset—empowering developers while giving IT full visibility, auditing, and alignment with security policies. Walk away with: A clear understanding of what Homebrew is—and isn’t—from an IT lens Common attack vectors against Homebrew in your fleet Guidance on aligning developer freedom with organizational control Seeing Workbrew in action reducing friction and risk while increasing velocity This session is for any admin who wants to support innovation without compromising on visibility, compliance, or peace of mind.
Wrangling Risk: Browser Security and Management
In this session, members of the Enterprise Information Security team and Client Platform Engineering team from Jamf discuss how they use Jamf and Google products together to manage the Chrome browser for enterprise use. We'll cover: - Powering the enrollment of browsers into Chrome Enterprise Core with Jamf Pro. - Gathering insights and evaluating risk scoring of extensions and apps with Chrome admin console. - Building continuous monitoring with Google Security Operations SIEM. - Using data and analytics alongside device and network telemetry from Jamf Protect to determine security policy and remediation strategy. - High-level considerations around interpreting risk scoring and understanding the needs of end users while keeping them and corporate data secure.