AI-Powered & Human-Activated: Amplify Secure User Productivity with Smarter Mac Compliance
Learn how Oscar Health uses a system that uses AI to automate user engagement, drive remediation, and close security gaps for Mac devices in real time. By turning users into part of the fix, not just the risk, Amplifier reduced the burden on Oscar’s Security and IT teams while improving user and endpoint hygiene. Instead of chasing users for tasks, Amplifier activates end users directly, making them part of the security workflows without disrupting productivity. We'll share how users closed Jamf Smart Group actions faster to update, patch, remove unapproved software and fix endpoint issues without disrupting their work. See a real world example of how Jamf, its customer and a Jamf Marketplace partner collaborated using API integrations of AI with Jamf smart groups, webhooks and policies. Learn best practices and insights of how you can reduce user security risk by slashing response time from days to minutes and cut IT security workload by 50%. Learn how you can truly harness the power of AI and your workforce to secure your business. Why now? Most companies struggle to identify and engage their riskiest users when it comes to endpoint security. Pending user security tasks often get ignored and delayed, and incumbent tools rely on compliance snapshots to satisfy audits, missing the steady drift in user behavior. AI now accelerates the speed and precision of attacks to identify and exploit vulnerable users and their devices. With over 50% of breaches linked to poor user and endpoint security hygiene, businesses are even more vulnerable unless they act proactively.
Automate and Elevate: Harnessing Jamf Integrations at Cisco
The session will demonstrate all our current and planned integrations and workflows, ranging from pre-built to custom solutions. These include Mac integrations with ServiceNow, Webex, Duo, Aisera, Entra ID, Snowflake, AWS S3, GitHub and AppOmni. Automations include Mac prestage reassignment, FileVault Recovery Key bot via Aisera, Trusted Device Status on our homegrown Device Portal, Automated Mac Lock on Employee Termination, various Webex bots, and our upcoming FileVault Recovery Key Archive. Mobile integrations include Duo, Snowflake, internal support tools for end users, and a future integration with Tangoe (Managed Mobility Services). Webhooks enable automations for device events related to Enrollment, unenrollment, Device cleanup, and Employee Termination.
Automatic Mac enrollment with Prime shipping benefits
Discover how to enhance your Apple device management through Jamf AI Assistant and Apple Business Manager on Amazon Business. This session explores the practical implementation, key benefits, and future capabilities of these powerful tools. Learn how ABM on Amazon Business streamlines device procurement and automated deployment, while Jamf AI Assistant enhances management efficiency. Whether you're managing a small fleet or enterprise-scale deployment, you'll gain valuable insights into maximizing your investment in Apple device management through intelligent automation and AI-driven solutions.
Automating Jamf Security Platform Configuration
In this session, we will discuss the different approaches an organization can have towards managing an API based SaaS tool. We will focus on automating the configuration of our Jamf Security platforms. Our talk will focus on Terraform as the chosen IaC platform for what we built and we will then dig into how we built a Terraform Provider to support our Jamf Security platforms. Additionally, this session will reference information discussed in the “Infrastructure as Code with Jamf” and “Automating Apple Endpoint Management” sessions. This will include referencing the Jamf Pro Provider written by Lloyd’s of London and discussing our Onboarder tool built around using that Jamf Pro Provider as well as the Provider we will be covering in this session.
A Year in the Life: Implementing Device Compliance and Conditional Access on a Global Scale
This session explores today’s evolving landscape of device compliance and security management. As the demand for secure, compliant environments grows, we’ll share our journey and the practical solutions we’ve implemented—offering insights that can be applied across a wide range of organizations. Attendees will walk away with actionable strategies for navigating Conditional Access implementations while balancing strong security with a positive user experience. Learning Objectives: - Understand the technical and non-technical challenges in implementing Microsoft Conditional Access using Jamf Pro Device Compliance. - Learn effective strategies for piloting, testing, and identifying potential issues in Conditional Access implementation. - Gain insights into documenting processes and creating self-solve options for users to enhance compliance. - Explore deployment phases and user communication strategies to ensure smooth implementation. - Discover potential issues, workarounds and solutions, including collaboration with vendor support. Methodologies: - Case study presentation - Interactive Q&A sessions - Demonstrations of custom solutions and tools - Sharing best practices and lessons learned Anticipated Outcomes: - Attendees will be equipped with practical knowledge and strategies to implement Conditional Access in their own environments. - Enhanced understanding of user communication and engagement techniques to minimize friction during implementation. - Ability to troubleshoot and resolve compliance issues independently using documented processes and self-solve options.
Context is Key: Leveraging Contextual Insights to Drive Effective Security Remediations
With great alerts comes great responsibility. In this session we’ll explore how we can take the great information and alerting capabilities of Jamf Protect and combine it with Jamf Pro to provide effective security remediations. We’ll look at how and why we might want to consider this approach and why good enough isn’t really good enough. If we can do better for our organization and our users, we should! We’ll look at the macOS security portals API and how we can interact with it to get the right information we need for an effective security response. If you’ve never interacted with an API before or don’t know what that even means, don’t worry! We’ll give a look into what an API is, the types of API that Jamf uses and some of the differences before going right into how we get the context we need to create an effective security remediation.
Crowning Achievements: How Jamf Helps Power Innovation at ECU SoDM
Managing Apple devices in a clinical and educational environment presents unique challenges. At ECU School of Dental Medicine (SoDM), Jamf is more than just an MDM—it’s a key tool for streamlining support, enforcing security and enhancing the user experience. This session will explore how SoDM leverages Jamf to manage Apple devices, integrates with tools, automates workflows and improves IT efficiency. We will explore how we develop and apply policies for faculty, staff and students and the impact these have on their day-to-day experience. We’ll discuss how these policies impact SoDM, share strategies for balancing compliance and usability, and highlight real-world automation and reporting examples that maximize the value of Jamf.
Device Compliance and Platform Single Sign-On with Microsoft and Jamf
Microsoft has announced mandatory changes (effective Q3 2025) to the way Device Compliance stores a workspace join key on computers registered with Entra. Jamf Pro is ready and has new commands for administrators to troubleshoot. In addition, Jamf Pro can deploy the Platform Single Sign-On extension (PSSOe) configurations to make enrolling machines easier than ever before. In this session, attendees will learn: Section 1: * What is Microsoft Entra Device Compliance * How and when does Entra ID calculate compliance and use it to grant access to resources * How does Microsoft leverage the Secure Enclave for user vs device identity * What ramifications does Microsoft's implementation of PSSO have for the IT admin Section 2: * How to deploy Device Compliance with Jamf Pro * How to deploy Platform Single Sign-On with Jamf Pro * How to troubleshoot Device Compliance and PSSOe on macOS Section 3: * Impacts for MDMs that don't support hardware-backed device identity * Impacts to device-based conditional access for secondary accounts * Common issues and FAQs Section 4: * Previews of upcoming PSSO/Device Compliance features
Enterprise Security Standards in Action: The future of identity integrations with SSF and CAEP
In this session, we'll walk through how Jamf and partner platforms like Okta, SGNL, and SailPoint work together using SSF/CAEP to enforce policy based on real-time compliance — all without complex custom integrations. Whether you're looking to reduce risk, improve automation or meet modern compliance requirements, this session will show you how a standards-first approach is making it easier than ever for the industry to build secure, adaptive access experiences.
eSIM Best Practices for iPhone & iPad: Setting the Gold Standard in Mobile Security for 2025 and Beyond - with zero touch global deployment.
Join us for a dedicated session exploring what’s possible with eSIM technology in 2025. We’ll cover powerful capabilities such as remote installation, managing multiple eSIM profiles, and more. Discover how Jamf Pro, Jamf Trust, and 1GLOBAL eSIM together set the Gold Standard in device security. With MDM-controlled and centrally distributed eSIM, we can deliver a highly secure experience for end users—enhanced further by Jamf Trust to ensure safe onboarding, day-to-day use, and secure offboarding. This is the Gold Standard in mobile device security—built for the future.
Fewer Tickets, Happier Users: Custom Jamf frontends using Jamf API and Google Apps Script
In large organizations, support teams often face a tricky balance: how do you empower frontline techs to resolve issues quickly without giving them too much access to sensitive systems like Jamf Pro? For us, the answer was to build a custom web interface that gave our techs exactly what they needed — and nothing more. This session will walk through how our team used Google Apps Script and the Jamf API to build a lightweight, secure, and cost-effective custom website. The site allows location-based techs to view devices in their assigned area and perform a limited set of scoped actions — things like remotely clearing passcodes, viewing LAPS passwords, triggering software update plans, and redeploying the Jamf framework — all without needing Jamf Pro access. The result? Faster support, fewer tickets, and a better experience for both techs and end users. We’ll explain how we used our existing Google Workspace environment to manage authentication and access, allowing us to roll out the site securely without any additional infrastructure or licensing costs. We’ll also cover how we designed the site around the principle of least privilege, ensuring that techs can only see and act on devices within their location. Along the way, we’ll highlight specific API endpoints we used, how we secured credentials, how we handle logging and version control, and what lessons we learned during development. Whether you’re a Jamf admin looking to empower support staff or someone curious about extending Jamf’s capabilities through the API, this session will give you practical ideas — and a real-world example you can adapt to your environment.
Hardening and Compliance for Higher Education and Other High-Value Targets
Faced with higher security and compliance requirements, Brian Lenz and his team at San Diego State University (SDSU) had to conquer budget restraints, limited time and an ever-changing world to ensure a secure and trustworthy macOS platform, built on Jamf solutions and their integrations with Microsoft products as well as open source tooling and frameworks. This session will be co-presented by Simon Binder, Lead Architect at Advania – Knowledge Factory, who will offer an external perspective on the security threats facing higher education institutions—both in the U.S. and internationally—as well as other high-value organizations. Binder will share strategies for overcoming these challenges by implementing proven, hardened security frameworks using Jamf Pro and complementary solutions. Lenz will share their vision and strategic direction for the future, while both Lenz and Simon will discuss the technologies, configurations and products in use. More importantly, they’ll walk through the process that brought SDSU to where it is today. They will showcase how to implement, update and report on the frameworks and on how this can be extended by using Microsoft Intune for compliance reporting, and provide practical insights into how to work with users, managers, auditors and IT to ensure a balance between security and user experience. Attendees, independent of the size of the organization they represent, will leave the session with more knowledge about and insights into the current threat landscape and what to prioritize to stay compliant and secure. They will also see and understand how security configuration management within Jamf Pro works, when to leverage additional tools and solutions and finally get inspired by SDSU's journey, that they might take back home and apply to their environments.
Have Your Cake and Eat It Too! Maximizing the Jamf Platform with Your Microsoft Licensing
This session will explore how the Jamf platform integrates with Microsoft Power Automate to optimize workflows and boost automation across shared environments. Attendees will learn how to leverage these tools to automate routine tasks, enhance security and develop effective IT solutions. Through real-world examples and best practices, the session will demonstrate how Jamf Routines can trigger Power Automate actions using the Jamf Pro API for streamlined device management. Participants will leave with practical templates and a clear understanding of how to harness these technologies to drive innovation and deliver a top-tier Apple experience.
Help! How Can We Integrate Jamf’s Security Solutions Into Our Microsoft Security Stack?
One common objection to adopting Jamf Protect—and Jamf Pro for response actions—in a mixed Windows / macOS environment is: “We already have Microsoft Defender XDR and Microsoft Sentinel with our E5 / A5 licenses—why add anything else?” Security teams and SOC analysts often worry about unfamiliar tools, new runbooks, and the effort required to wire everything into existing SOAR workflows. That hesitation overlooks a key fact: Jamf and Microsoft have co-engineered native, low-friction integrations. Jamf telemetry streams straight into Microsoft Sentinel, while device and identity signals pass through Microsoft Entra ID and Intune. You get best-of-breed macOS protection without sacrificing the single pane of glass you already know. During the session, presenter Simon Binder, Lead Architect, Advania - Knowledge Factory, draws on real-world examples to break down the perceived roadblocks and demystify the alphabet soup—XDR, SIEM, SOC, SOAR, EDR—so everyone starts from the same baseline. Using demonstrations, Binder will walk through the end-to-end connection of Jamf Pro and Jamf Protect to Sentinel, threat-hunting with KQL across Jamf and Windows data side by side, and automated incident response that chains Sentinel playbooks, Jamf remediation commands, Defender XDR alerts, and other Azure services. Attendees will leave knowing: - Why pairing the platform leaders—Jamf for macOS, Microsoft for Windows—delivers a stronger defense than a single-vendor approach. - How Jamf plus Microsoft extracts full value from the E5 / A5 stack they already own. - Exactly what a SOC needs in skills, runbooks and governance to make macOS a first-class citizen in detection and response. The result is a team better prepared to counter cyberattacks and to maximize its security investment across platforms and vendors.
In the Trenches with Platform SSO, Okta, Connect, and Network Relay at Jamf
How is Jamf handling its evolution from Jamf Connect to an environment enriched with Platform SSO, Network Relay, and Managed Device Attestation? Come join Jamf IT and Product leaders to see how Jamf@Jamf is thinking about and deploying these technologies across its fleet of global Apple devices. We’ll be spending most of our time in product consoles exploring configuration details, so be ready for a highly interactive and engaging session!
Jamf and Okta - Onboarding and Passwordless Authentication with Okta Device Access
A fully trusted access solution ensures that only authorized users on enrolled devices that are secure and compliant can access sensitive data. Okta and Jamf are essential together to make this solution. In this session, we will discuss the differences between Jamf Connect and Okta Desktop Access (Okta's Platform Single Sign-on implementation), how to onboard both tools, and where tools like Desktop MFA, FastPass, Jamf Trust and Network Relay can be used to make a solution that users love and admins trust.
Jamf Concept’s remediaSOAR: Leveraging Jamf APIs to Transform Security Alert Management
The power of Jamf's APIs enables innovative solutions for complex security challenges. In this session, we'll dive into how remediaSOAR was built by leveraging Jamf's robust API ecosystem to create a unified security alert management platform. We'll explore how to: - Utilize Jamf Protect’s API to retrieve and process security alerts. - Leverage Jamf Pro's API for direct remediation actions. - Integrate with Jamf Security Cloud's API for risk score management. - Build cross-platform solutions that extend Jamf's capabilities. Through practical demonstrations and examples, we'll show how remediaSOAR connects these APIs to create a seamless security management experience. Whether you're a developer looking to build your own Jamf integrations or an admin seeking to understand the potential of Jamf's API ecosystem, you'll gain valuable insights into extending Jamf's capabilities through API integration.
Mac Admins vs. Shadow IT: Winning the War for User Compliance
Shadow IT is becoming one of the biggest headaches for Mac admins, with unapproved software, unsanctioned SaaS tools, and personal devices creating compliance and visibility gaps. As more work moves outside of traditional IT boundaries, managing security without disrupting user experience is harder than ever. This session offers practical, Jamf-centered strategies to detect, manage, and reduce Shadow IT risks—without alienating the people you're trying to support. You will learn how to: Track unauthorized software and Homebrew installs using Smart Groups and Extension Attributes Detect and manage Shadow IT SaaS usage through Jamf Pro inventory and integrated security tools Enforce secure BYOD policies that protect work data while respecting user privacy Prepare for emerging risks like Shadow AI and maintain IT governance over AI-powered tools Packed with real-world examples, workflows, and policy tips, this session equips Jamf admins with actionable takeaways to boost visibility, reinforce compliance, and keep users productive—without becoming the "bad guy".
Maximizing the Value of Your Apple Hardware with G.O.A.T.
In this session, we’ll explore how Galide’s Operational Asset Tracking portal and Jamf API integration help streamline the entire device trade-in process. We’ll also delve into best practices and strategies you can use to maximize the residual value of your organizations Apple and non-Apple inventory.
Netflix’s Road from Spreadsheet to Scale and Data Accuracy with Oomnitza ITAM
As enterprise IT environments become increasingly decentralized and complex, managing hardware assets—especially Macs—at scale requires more than manual updates and static spreadsheets. In this fireside chat, Jason Owens shares how Netflix is transforming IT asset management globally using Oomnitza’s ITAM platform. By integrating with tools like Jamf and other core systems, the Netflix team has streamlined operations, boosted visibility, and delivered measurable business value. Key Takeaway: You'll leave with a practical understanding of how an automation-first, integration-powered ITAM strategy—rooted in data accuracy—can enable smarter decisions, greater scalability, and better asset outcomes across a complex environment.
One PreStage to Rule Them All: Secure macOS Deployment with Power Automate
In this session, we’ll walk through how we use a Jamf MDM command to generate a unique device-specific key during Setup Assistant. This key is securely returned to Power Automate, allowing for controlled API access to Jamf Pro, ensuring that devices can only act on their records. This approach enables dynamic configuration within a single PreStage, supporting multiple campuses and use cases while maintaining security and manageability. Attendees will gain a deep understanding of how to: * Leverage Power Automate as an API broker. * Deploy Jamf Setup Manager. * Dynamically set device name, site and data risk classification during provisioning. * Design scalable workflows that meet security and compliance needs. This session is ideal for Jamf administrators, higher ed IT professionals and anyone looking to enhance the security and flexibility of their macOS deployment processes.
Powershell and the Mac Admin
In a world where macOS administration relies on various scripting methods, PowerShell stands out as a powerful, cross-platform tool offering flexibility, efficiency and familiarity. This session introduces PowerShell’s core features, showcases real-world use cases like API management and automation, and explores how it can complement traditional scripting tools. Whether you’re a Mac admin exploring new options or a Windows admin transitioning to Apple environments, you’ll gain practical skills, expand your scripting toolkit and learn to streamline workflows across platforms.
Streamlining Enterprise Certificate Management: A Collaborative Approach with Jamf Pro, DigiCert and IBM
By leveraging third-party certificate authority integrations available in Jamf Pro, enterprise organizations can simplify, automate and strengthen certificate lifecycle management processes. With integrations like DigiCert One Trust Lifecycle Manager, companies such as IBM have streamlined certificate management processes at scale, enabled consistent and reliable secure access to resources and improved the user experience for employees working on Apple devices.In this collaborative panel, speakers from Jamf, DigiCert and IBM will discuss common certificate management challenges many enterprise organizations face, and ways organizations can leverage Jamf Pro features and best practices to solve those challenges. Doug Knight from DigiCert will highlight solutions made possible with DigiCert One Trust Lifecycle Manager. Martin Barnard from Jamf will spotlight the value of feature-based integrations within Jamf Pro and share insight into current product development. Greg Maki from Jamf will provide recommendations from a configuration management and cross-team collaboration perspective. Finally, Jon Krauer from Mac@IBM will bring these insights home by sharing practical real world examples, highlights from recent challenges solved by their program, key benefits they gained from using these solutions and shares tips for effective results.
Super Friends
In the great halls of JNUC, the world’s greatest Apple professionals come together, created from the legendary message threads of Jamf Nation and the Mac Admins Slack! S.U.P.E.R.M.A.N.! ManTech (supporting NASA JPL)! Paramount! Come and join the fraternity of Super Friends with their mission: to fight security risks, to update that which is outdated, and to serve all Apple-kind! S.U.P.E.R.M.A.N. (or just "super") is an open-source script that provides administrators with a comprehensive solution to encourage and enforce macOS minor updates, macOS major upgrades, Jamf Pro Policies or enforced system restarts. Deployed using a single script and optional configuration profiles, "super" creates a background agent (aka LaunchDaemon) that ensures updates are applied with the least user interference possible. Further, "super" offers a broad range of options for customizable dialogs, notifications, schedules, deferrals and deadlines. In other words, "super" makes the macOS update experience better for both users and administrators. This session is comprised of three main sections: Getting started with "super", what's new with "super" since last JNUC and finally, customer success stories (aka Super Friends).
Taking Control: Building an Enterprise API for Secure and Scalable Jamf Integration
Administrators at large organizations increasingly rely on Jamf’s API to create custom integrations and automate device management tasks. Today's economic outlook is driving enterprises to grow and expand their capabilities using technology, not people. With this in mind, the need for scalable, robust and secure automation has never been greater. As automation initiatives grow, it can quickly become a complex task to scale your Jamf API usage while staying secure and efficient. This session will provide the Jamf admin community with critical insights into scenarios where relying on Jamf’s API alone may not adequately meet enterprise demands. Attendees will achieve the following learning objectives - Recognize when the Jamf API alone becomes insufficient for scalable automation. - Observe practical methods for implementing an Enterprise API, including RESTful API design, secure authentication, comprehensive logging and monitoring, and effective abstraction of implementation details from other teams who access Jamf data. - Evaluate common risks and trade-offs, and learn strategies for effectively managing and mitigating these challenges. - Explore real-world use cases that provide immediate, visible benefits. After attending this session, administrators will know how to effectively communicate their vision, create a roadmap to establish priorities and expectations, and successfully implement an Enterprise API. This approach will significantly improve scalability, enhance security, and provide greater flexibility. Participants will leave with the confidence to participate in and accelerate their organization’s automation initiatives.
The new security endpoint with Chrome Enterprise and Jamf
In today's rapidly evolving threat landscape, securing endpoints has become more critical than ever. This session will explore how Chrome Enterprise and Jamf can work together to create a new standard for endpoint security. We'll delve into the latest management and security capabilities that can support your organization.
Wildest Dreams: Unleashing IT Potential with Automation
Current IT support teams often struggle with high ticket volumes and reactive problem solving, leading to overworked teams and frustrated users. This session addresses these challenges directly by providing attendees with actionable strategies to shift towards a proactive, user-empowering model. By showcasing real-world examples of automation and integration with community tools, it will demonstrate how to reduce ticket resolution times, increase user autonomy, and identify opportunities for automated resolutions, ultimately streamlining IT support and improving the overall user experience. Attendees will gain insights into prioritizing starting points, see examples of using Jamf Protect and Jamf Pro to implement automated remediation, and learn how to develop user-driven remediation strategies using tools like Nudge and swiftDialog. The session will also cover how to stay on top of new developments, recommendations for using betas and pilots, and the benefits of knowledge sharing. At the end of the session, attendees will feel inspired to take some of the learnings and see how they can implement them in their organizations, and to share what they have learned with the rest of the community. After all, a rising tide lifts all boats.
Wrangling Risk: Browser Security and Management
In this session, members of the Enterprise Information Security team and Client Platform Engineering team from Jamf discuss how they use Jamf and Google products together to manage the Chrome browser for enterprise use. We'll cover: - Powering the enrollment of browsers into Chrome Enterprise Core with Jamf Pro. - Gathering insights and evaluating risk scoring of extensions and apps with Chrome admin console. - Building continuous monitoring with Google Security Operations SIEM. - Using data and analytics alongside device and network telemetry from Jamf Protect to determine security policy and remediation strategy. - High-level considerations around interpreting risk scoring and understanding the needs of end users while keeping them and corporate data secure.
Zero-Touch Diagnostics Collection
The "Zero-Touch Diagnostics Collection" session at JNUC 2025 addresses a common challenge in IT: the time-consuming and manual process of collecting diagnostic logs for troubleshooting. Salesforce's File Uploader Tool (FUT) offers a solution by automating the secure and efficient upload of log files from Apple devices to cloud storage, eliminating the need for user intervention. This session will delve into the architecture, development and deployment of FUT, and its seamless integration with Jamf. Attendees will discover how to automate log collection from hundreds of devices, streamline workflows, and reduce the burden on both engineers and users. Ideal for IT professionals looking to enhance operational efficiency and minimize manual tasks, this session promises valuable insights into leveraging cloud services and Jamf for improved IT management. Attendees will learn: - The end-to-end workflow for collecting diagnostic log files to cloud storage. - Knowledge of the architectural components and development considerations for file uploader tools. - Cloud storage resources and configurations for file uploads. - Practical understanding of deploying and managing such tools on Apple devices using Jamf policies and scripts. - Inspiration and ideas for streamlining their file upload processes. Key Discussion Points: Architecture of the File Uploader Tool, including session token requests, API gateway verification, and cloud storage upload process. Development aspects, including the developer guide, SDK, and key Xcode project files like Config, HelperTool, Obfuscator, AWSManager, and fileUploader. Cloud storage resource configuration, focusing on AWS S3, API gateway, Lambda function, and the Secret Manager key template. Deployment and usage via Jamf, including packaging, associated scripts, and handling target folder paths in cloud storage. Practical use cases and considerations, such as automated log uploads and cloud storage folder management.