Endpoint Protection and Compliance
Dive into the critical aspects of Endpoint Protection and Compliance for your Apple fleet. These sessions are designed for you to explore and learn about advanced strategies for securing your Apple endpoints, ensuring compliance with industry regulations and mitigating potential threats. Gain valuable insights from Jamf Nation and Jamfs who will share real-world experiences and best practices to help enhance your security posture and stay ahead of evolving threats.
Endpoint Protection and Compliance
Select the icon within any available time slot to add a session to your agenda. To reserve personal time, click the + Add Personal Time button.
Endpoint Protection and Compliance
Dive into the critical aspects of Endpoint Protection and Compliance for your Apple fleet. These sessions are designed for you to explore and learn about advanced strategies for securing your Apple endpoints, ensuring compliance with industry regulations and mitigating potential threats. Gain valuable insights from Jamf Nation and Jamfs who will share real-world experiences and best practices to help enhance your security posture and stay ahead of evolving threats.
Sessions
Breakout Session
- Breakout SessionMac and Mobile ComplianceOtherGovernment200 Level - IntermediateIn-PersonYes - Show in Prod CatalogMaciPadiPhoneJamf ProThursday, Sep 2410:00 a.m. Thursday, Sep 24Managing Apple Devices in a federal or high compliance environment doesn't have to mean trading agility for security. This session explores Jamf's two purpose-built environments — FedCloud, authorized under FedRAMP and Jamf's High Compliance environment, authorized under NIST 800-53 Rev 5 — and the powerful capabilities within them. We'll walk through Declarative Device Management, blueprints, compliance baselines and the Jamf App Catalog, showing how each helps you maintain compliance without slowing down your team. Whether you're supporting a government agency or a regulated enterprise, leave with a clear picture of what these environments offer and how to make the most of them.
, Sales Engineer III, Jamf
, Sales Engineer III, Jamf
- Thursday, Sep 24th10:15 am - 11:00 am CDTGrand Ballroom A2
- Breakout SessionMac and Mobile ComplianceReporting & Risk ReductionOtherGovernmentHigher EducationAviation/TransportationEnterprise100 Level - IntroductoryIn-PersonYes - Show in Prod CatalogMaciPadiPhoneJamf ProWednesday, Sep 231:00 p.m. Wednesday, Sep 23From 30 days to 5. From manual grind to autonomous workflow. This session unpacks how our team rebuilt OS compliance at Eli Lilly, turning a month-long operational slog into a one-week, repeatable engine powered by Declarative Device Management (DDM), automated communication workflows that leverage Apple Push Notifications and Logic Apps. No more chasing devices. No more spreadsheet gymnastics. Just declarations doing the work, notifications meeting users where they are and orchestration tying it all together into measurable business outcomes. You'll leave with the blueprint: how DDM software update declarations actually behave in the wild, how to architect a phased rollout across an enterprise-scale fleet, and how to wire up APNs-driven user nudges and Logic Apps automations that close the loop between Jamf, your data layer, and leadership dashboards. We'll show you the compliance reporting executives actually act on — not vanity metrics, but signal. Real fleet. Real numbers. 60,000+ iPhone and iPad devices. 7,300+ Mac devices. We'll walk through the architecture decisions, the tradeoffs we made (and the ones we'd redo), the failure modes we hit and the lessons that turned DDM from a shiny WWDC demo into a production-grade compliance engine.
, Snr Associate-Support Services, Eli Lilly and Company
- Wednesday, Sep 23rd01:00 pm - 01:45 pm CDT2103A
- Breakout SessionMac WorkflowsIntegrations and APIsOtherGovernmentHigher EducationAviation/TransportationEnterprise100 Level - IntroductoryIn-PersonYes - Show in Prod CatalogMacJamf ProJamf ProtectJamf ConnectWednesday, Sep 233:00 p.m. Wednesday, Sep 23This session walks through a complete app resilience workflow for macOS fleets, pairing Jamf Pro with CrowdStrike Falcon to keep the Jamf framework and its components always installed, always running and always reporting. From the binary to Self Service, organizations want assurance that their mission-critical apps, settings and configurations are not only present on the client, but that any drift from the core configuration is detected and remediated as quickly as possible. We’ll cover health checks that continuously validate framework integrity on the device, required MDM communication, configuration state and the presence of required binaries and LaunchDaemons, along with the dashboards that surface this data so admins can spot fleet-wide trends and one-off outliers at a glance. From there, we’ll dig into remediation controls, including automated policies, Self Service fallbacks, and scripted repairs that bring devices back into compliance without user disruption, as well as the information gathering layer of extension attributes, inventory collection, and Falcon telemetry that feeds those decisions. Attendees will leave with a reconciled monitoring approach across both consoles, aimed at Mac admins, security engineers and IT ops teams responsible for keeping Jamf and Falcon healthy on macOS.
, Senior Strategic Partner Manager, Jamf
, Staff Partner Solutions Architect, Jamf
, Solution Architect, CrowdStrike
- Wednesday, Sep 23rd03:30 pm - 04:15 pm CDT2505A
- Breakout SessionMac WorkflowsMobility WorkflowsReturn to ServiceSetup and Reset with Single LoginOtherHigher EducationK-12 EducationAviation/TransportationEnterprise300 Level - AdvancedIn-PersonYes - Show in Prod CatalogMaciPadiPhoneJamf ProOther11:00 a.m. Friday, Sep 25Friday, Sep 25Learn how to transform your Jamf workflows with advanced automations that solve real-world admin challenges. This session demonstrates production-ready solutions including time-limited admin approval workflows, automated compliance escalation and cross-platform integrations that extend Jamf's capabilities beyond the console. You'll see live builds of multi-step automation chains using Jamf-native automation tools, webhooks, integrations with other tools like Slack and more that eliminate manual tasks and improve fleet management. Whether you're looking to implement self-healing deployments or streamlined onboarding orchestration, you'll leave with practical blueprints you can deploy immediately.
, Senior Consulting Engineer, Industry Solutions, Jamf
, Sales Engineer III, Jamf
- Friday, Sep 25th11:30 am - 12:15 pm CDTGrand Ballroom B
- Breakout SessionMac and Mobile ComplianceReporting & Risk ReductionOtherGovernmentHigher EducationK-12 EducationAviation/TransportationEnterprise200 Level - IntermediateIn-PersonYes - Show in Prod CatalogMacJamf Protect10:00 a.m. Friday, Sep 25Friday, Sep 25Jamf Protect Telemetry is now ingested into your Security Information and Event Management (SIEM) and you are receiving data. We will discuss what is possible to discover, how security employees can better threat hunt their data and how telemetry can even assist in enforcing policy and compliance. Attendees will gain knowledge of how to effectively utilize Jamf Protect Telemetry for a wide variety of use cases with a security-focused approach.
, Threat and Detections Researcher I, Jamf
- Friday, Sep 25th10:15 am - 11:00 am CDT3501E
- Breakout SessionReporting & Risk ReductionOtherGovernmentHigher EducationOtherEnterprise300 Level - AdvancedIn-PersonYes - Show in Prod CatalogMacJamf Protect4:00 p.m. Thursday, Sep 24Thursday, Sep 24The Apple Keychain has become a cornerstone of credential management for millions of users across the Apple ecosystem. In response, Apple has implemented robust protections for the iCloud Keychain — restricting synchronization exclusively to devices within Apple’s “Circle of Trust” and encrypting stored secrets with keys derived from the Secure Enclave. These layered defenses are designed to ensure that even physical acquisition of Keychain data from Apple’s servers yields nothing actionable. This talk introduces a novel vulnerability (CVE-2026-28860) that fundamentally undermines these protections. Leveraging a deep understanding of macOS internals, we demonstrate a technique capable of extracting all passwords stored within the Keychain — requiring neither root privileges nor prompts to the user. Beyond credential theft, we explore the broader attack surface this vulnerability exposes, presenting additional scenarios where data gleaned from the iCloud Keychain enables further, more severe compromise.
, Director, Threat Labs, Jamf
- Thursday, Sep 24th04:15 pm - 05:00 pm CDT2103C
- Breakout SessionReporting & Risk ReductionIntegrations and APIsOtherGovernmentEnterprise200 Level - IntermediateIn-PersonYes - Show in Prod CatalogMaciPadiPhoneJamf Pro11:00 a.m. Friday, Sep 25Friday, Sep 25Keeping devices on the latest OS version is critical for compliance and security — but visibility into update progress is often lacking. This session demonstrates how to build dashboards that clearly show OS adoption across your fleet, including devices that are one or more versions behind. Learn how to leverage Jamf Pro Smart Groups, Extension Attributes and API integrations to classify devices as Safe, Vulnerable, or Out of Compliance. We’ll also cover how to account for inactive or locked devices and deliver actionable insights for audits, security teams, and executives.
, Senior Enterprise Applications Engineer, GRAIL, Inc.
, Senior Sales Engineer, Jamf
- Friday, Sep 25th11:30 am - 12:15 pm CDT2103A
- Breakout SessionMac and Mobile ComplianceIntegrations and APIsOtherGovernmentHigher EducationAviation/TransportationEnterprise200 Level - IntermediateIn-PersonYes - Show in Prod CatalogMaciPhoneJamf ProJamf School3:00 p.m. Thursday, Sep 24Thursday, Sep 24Meeting the compliance demands of a regulated financial institution requires more than policy, it requires repeatable, auditable enforcement at scale. In this session, Fredrik Virding from Klarna joins Jamf product leadership to share how one of Europe's leading fintech companies adopted Jamf Compliance Benchmarks across its Mac fleet. Attendees will learn how Klarna approached rollout, managed stakeholder expectations and aligned benchmark controls with existing regulatory frameworks. The session covers practical decisions made along the way, from baseline selection to remediation workflows and the measurable outcomes achieved. Whether you manage devices in a regulated industry or are simply looking to mature your compliance posture, you will leave with a real-world blueprint you can apply immediately.
, Senior Engineer, Klarna
, Senior Product Owner, Jamf
, Product Manager II, Jamf
- Thursday, Sep 24th03:00 pm - 03:45 pm CDT3501A
- Breakout SessionMobility WorkflowsReporting & Risk ReductionOtherGovernmentHigher EducationAviation/TransportationEnterprise200 Level - IntermediateIn-PersonYes - Show in Prod CatalogiPadAndroidiPhoneJamf ProJamf ProtectAndroid Manager4:00 p.m. Thursday, Sep 24Thursday, Sep 24Your organization probably has an AI policy. But does it cover the apps on every employee's phone? AI capabilities are entering mobile applications through third-party SDKs and updates that security teams never vetted, often connecting to the same enterprise cloud storage where your corporate data lives. With over half of mobile apps now containing AI components that traditional review processes miss, visibility into what AI is doing inside your app portfolio has become an urgent priority. In this session, you'll learn to: - Use Jamf content filtering to control AI access on mobile devices today - Analyze your app estate with NowSecure to reveal hidden AI components and data flows - Bridge the conversation between your Mac and mobile teams on AI security
, Senior Security Sales Manager, Jamf
, Senior Vice President, NowSecure
- Thursday, Sep 24th04:15 pm - 05:00 pm CDT2505A
- Breakout SessionReporting & Risk ReductionOtherOther100 Level - IntroductoryIn-PersonYes - Show in Prod CatalogMacJamf ProtectThursday, Sep 2410:00 a.m. Thursday, Sep 24This session covers two capabilities worth knowing about: a redesigned Threat Prevention experience built on Jamf Threat Labs' research, and a new capability that goes beyond detection to protect what matters most — your data. Whether you're already using Jamf or just getting started, you'll leave with two things worth your attention this week.
, Product Manager II, Jamf
, Director, Threat Labs, Jamf
- Thursday, Sep 24th10:15 am - 11:00 am CDTGrand Ballroom B
- Breakout SessionMac WorkflowsReporting & Risk ReductionOtherGovernmentHigher EducationK-12 EducationAviation/TransportationEnterprise300 Level - AdvancedIn-PersonYes - Show in Prod CatalogMaciPadJamf ProOther9:00 a.m. Thursday, Sep 24Thursday, Sep 24Apple MDM is designed to behave consistently: the same request should produce the same result. Yet in many enterprise environments, identical actions can yield inconsistent outcomes — policies fail, installs stall and check-ins succeed only after retry. This session presents a real-world investigation into two separate failure domains that initially appeared related: - A Jamf Pro server-side XML serialization defect, later confirmed by Jamf Engineering as a previously unknown product issue and assigned PI-1159 - A separate endpoint-side control-plane fragmentation pattern in which layered security tools evaluated the same traffic under different runtime conditions Through controlled testing, log correlation and packet capture analysis, this session demonstrates how multiple enforcement layers can introduce timing-dependent behavior. The result can look random from the MDM administrator’s perspective, even when each individual system is operating according to its own rules. Attendees will learn how to: - Distinguish between unrelated failure domains - Recognize retry-dependent success, path-dependent behavior and state-sensitive failures - Validate root causes using logs, network traces, and system state correlation - Restore reliable macOS management by aligning control-plane behavior without weakening security posture This session provides a practical diagnostic framework for MacAdmins and security engineers working in complex, high-governance environments where MDM, identity, networking and endpoint protection controls all intersect.
, Mac admin
- Thursday, Sep 24th09:00 am - 09:45 am CDT2505A
- Breakout SessionMac WorkflowsReporting & Risk ReductionOtherOther200 Level - IntermediateIn-PersonYes - Show in Prod CatalogMacJamf Protect1:00 p.m. Thursday, Sep 24Thursday, Sep 24Most endpoint security tools tell you what ran on your Mac. They capture process execution, file writes and authentication events. But there's a question they can't answer: where did it call home? Network activity is where modern attacks live — C2 beaconing, data exfiltration, lateral movement, shadow IT. Without network visibility, your incident investigations hit a dead end at the worst possible moment. In this session, we'll walk through how Jamf Protect's Network Telemetry closes this blind spot on Mac — built natively on Apple's Endpoint Security API, not ported from Windows. You'll see how every inbound and outbound connection is captured with full process attribution: which app, which user, which destination, at what time. We'll cover real detection scenarios — the silent exfiltrator, the reverse shell, the insider threat — and demonstrate how network telemetry feeds Jamf's AI Assistant to turn raw connection data into plain-language MITRE ATT&CK-mapped investigation summaries in minutes, not hours. For compliance-driven teams, we'll show how a single telemetry stream satisfies logging requirements across NIST 800-53, M-21-31, HIPAA, PCI DSS, NIS2, Essential Eight, and CMMC — eliminating the need to stitch data from multiple tools. Whether you're a security analyst hunting threats, an IT admin trying to prove compliance or an administrator who just wants to understand what's leaving your network — this session will show you what Apple-native network visibility looks like. And why you'll never want to fly blind again.
, Senior Sales Engineer, Jamf
, Manager, Product Owners, Jamf
- Thursday, Sep 24th01:45 pm - 02:30 pm CDT3501A
- Breakout SessionMobility WorkflowsIntegrations and APIsReturn to ServiceGovernmentOtherAviation/TransportationEnterprise300 Level - AdvancedIn-PersonYes - Show in Prod CatalogiPadiPhoneJamf Pro11:00 a.m. Friday, Sep 25Friday, Sep 25This session is a technical deep dive into Apple's Managed App Framework, including what it enables and how the Jamf platform can be used to orchestrate the delivery of configurations, credentials and device identities directly into managed apps. Using real world examples, we'll cover each capability in sequence: app configuration, zero-touch authentication, ACME identities bound to the Secure Enclave, mutual TLS and a layered security model that extends hardware attestation from the transport layer into the application itself. Attendees will leave with the technical foundation to consider and start applying these capabilities in their own environment.
, Consulting Engineer, Jamf
, Senior Consulting Engineer, Apple Technologies, Jamf
- Friday, Sep 25th11:30 am - 12:15 pm CDT3501E