Login to view this video
Browse and search by keywords or use filters to find sessions that interest you most. Stay tuned as more sessions are added regularly.
API Defense Tactics: Credential Protection Essentials for Jamf Admins
The session aims to address the critical issue of securely passing credentials within scripts for API calls in Jamf environments. Participants will learn about the risks associated with credential exposure and the best practices for mitigating these risks to enhance security in device management.
We will discuss the challenges of encrypting credentials and the potential vulnerabilities that can be exploited by attackers. The session will cover the use of Jamf Pro webhooks, AWS API Gateway, AWS Secrets Manager, AWS EventBridge and credential storage solutions like HashiCorp Vault/CyberArk. We will also explore the implementation of Lambda functions for secure API authentication.
In an era where security breaches are increasingly common, it's crucial to safeguard API credentials effectively. This session is timely as it provides practical solutions to a pressing problem, ensuring that device management within Jamf environments remains secure against potential attacks.
Attendees will leave with a clear understanding of:
We will discuss the challenges of encrypting credentials and the potential vulnerabilities that can be exploited by attackers. The session will cover the use of Jamf Pro webhooks, AWS API Gateway, AWS Secrets Manager, AWS EventBridge and credential storage solutions like HashiCorp Vault/CyberArk. We will also explore the implementation of Lambda functions for secure API authentication.
In an era where security breaches are increasingly common, it's crucial to safeguard API credentials effectively. This session is timely as it provides practical solutions to a pressing problem, ensuring that device management within Jamf environments remains secure against potential attacks.
Attendees will leave with a clear understanding of:
-
1. The risks associated with improper credential handling in API calls
2. The architecture and flow of a secure API integration using modern cloud services and security tools
3. Step-by-step guidance on setting up a secure environment for handling credentials
4. Strategies for using webhooks, credentials management and serverless functions to enhance security
5. The ability to assess and improve their current Jamf environment's security posture with respect to API credential management
Speakers

Client Engineer, Salesforce Inc.

Client Platform Automation Engineer, Salesforce Inc.
Session Type: Breakout Session
Products: Jamf Pro
Audience: Commercial, Government, Higher Education, K-12 Education, Healthcare - Commercial, Healthcare - Education
Skill Level: Level 300