Login to view this video
Browse and search by keywords or use filters to find sessions that interest you most. Stay tuned as more sessions are added regularly.
Admin Rights in a Jam: Safeguarding Devices by Revoking Admin Rights with Jamf Connect
At Toast, we are continuously improving our security posture without compromising our users’ ability to innovate and deliver. Toast’s quick growth is pushing our teams to find scalable and affordable solutions to mature the security of our IT environment. This presentation will focus on our urgent need to revoke admin rights from our laptop users and provide them with a single holistic solution to temporarily elevate their access.
The issue: Our laptop environment allowed open administrative access for all users, and our IT and Security teams used multiple Endpoint Detection and Response tools, Mobile Device Management (MDM) systems, and other systems to monitor and detect security incidents. We needed to come up with a holistic, auditable, low cost and low-impact solution to revoke admin rights and allow users to temporarily elevate.
The process: We decided we had two paths forward: 1. build an in-house solution using our existing tools, or 2. purchase, learn, implement and integrate, and support a new tool. Our project team demoed multiple admin rights management tools that were overly robust, very high cost and required a learning curve to implement. We spoke to Jamf to understand if we could utilize MDM to fill our needs, and we were excited to find they were in beta with an administrative rights access feature.
The solution: In house — we implemented Privilege Elevation using Jamf Connect to disable administrative rights and provide a solution to temporarily escalate and revoke administrative rights. We were able to deliver under budget, under timeline and with only a reported 1% impact rate to our users.
Relevance: Our presentation will talk through our project, from conception to completion; it will touch on our use of the new Jamf Connect Privilege Elevation feature and some roadblocks that we encountered along the way, allowing everyone the ability to learn from our process.
The issue: Our laptop environment allowed open administrative access for all users, and our IT and Security teams used multiple Endpoint Detection and Response tools, Mobile Device Management (MDM) systems, and other systems to monitor and detect security incidents. We needed to come up with a holistic, auditable, low cost and low-impact solution to revoke admin rights and allow users to temporarily elevate.
The process: We decided we had two paths forward: 1. build an in-house solution using our existing tools, or 2. purchase, learn, implement and integrate, and support a new tool. Our project team demoed multiple admin rights management tools that were overly robust, very high cost and required a learning curve to implement. We spoke to Jamf to understand if we could utilize MDM to fill our needs, and we were excited to find they were in beta with an administrative rights access feature.
The solution: In house — we implemented Privilege Elevation using Jamf Connect to disable administrative rights and provide a solution to temporarily escalate and revoke administrative rights. We were able to deliver under budget, under timeline and with only a reported 1% impact rate to our users.
Relevance: Our presentation will talk through our project, from conception to completion; it will touch on our use of the new Jamf Connect Privilege Elevation feature and some roadblocks that we encountered along the way, allowing everyone the ability to learn from our process.
Speakers

Senior Systems Administrator, Toast
Senior Manager, IT Systems, Toast
Session Type: Breakout Session
Products: Jamf Pro, Jamf Connect
Audience: Commercial
Skill Level: Level 200