7:00 AM CDT - Thursday, Sep 24
Breakfast
Exhibit Hall E
Join us in Exhibit Hall E for breakfast - 7:30 AM - 9:00 AM
8:00 AM CDT - Thursday, Sep 24
When Your Systems Disagree: Building Trusted Asset Data Around Jamf
Spotlight Theater - Exhibit Hall D
Jamf knows your Apple devices. But who owns a laptop, what it cost, whether the contract is renewed, and whether it is still compliant all live across HR, finance, procurement, identity, and security, and those systems rarely agree. In this session, Oomnitza co-founder Ramin Ettehad walks through what happens when automation and AI act on device data that is out of sync, and what it takes to reconcile it across the full lifecycle. You will learn how to spot where your fleet data breaks down, how to build a view that spans Apple and non-Apple assets without replacing Jamf, and how teams are cutting audit prep time and recovering more devices at offboarding. Practical patterns you can take back to your own environment, whether you manage 500 devices or 50,000.
Getting started with Platform APIs
Jamf Booth Theater - Exhibit Hall D
Dive into Platform APIs to learn how you can develop and integrate your Jamf stack more easily.
Education State of the Union
Grand Ballroom B
This session is tailored for K-12 organizations managing, protecting and optimizing their devices for teaching and learning. The audience will walk away from the State of the Union with a clear understanding of how Jamf is supporting Education and gain ideas of how to transform the teaching and learning experience. Doors open at 8:45am and livestream will start at 8:55am. The session will begin at 9:00am.
Education State of the Union (with American Sign Language)
Grand Ballroom B (ASL)
This session is tailored for K-12 organizations managing, protecting and optimizing their devices for teaching and learning.
9:00 AM CDT - Thursday, Sep 24
10 More Things New Jamf Pro Admins Should Know
Grand Ballroom A2
At JNUC 2022 I presented “10 Things New Jamf Pro Admins Should Know”. It was a fun session of helpful advice, hints and recommendations collected over the years by our Services team visiting with new customers. Whether you’re new to Apple device management or just new to Jamf, you’ll take away ideas that you may have forgotten from your onboarding or were never covered. Let’s review 10 more things (even more, if time allows) new Jamf admins should know to make their jobs easier and more productive.
Beyond Self Service: Surfacing User-Friendly Information with Support.app Extensions
2103C
Support.app has become a popular way for Mac admins to provide users with a branded, approachable support experience on macOS. But beyond its built-in tools, Support.app also provides a powerful framework for building dynamic workflows through Custom Extensions. In this session, we’ll show how Jamf admins can use Support.app Extensions to surface real-time device information, automate remediation actions and simplify complex support workflows through a native macOS interface. We’ll walk through practical examples including compliance status, registration workflows, network status, battery health, password management and Jamf check-in visibility. Attendees will learn how lightweight scripts and Jamf policies can evolve into user-friendly workflows that reduce support friction without exposing users to Terminal commands or backend complexity. Whether you’re new to Support.app or already experimenting with extensions, this session will provide practical design ideas, implementation patterns, and reusable concepts you can bring back to your environment.
Deploying AI with Confidence: From Device Management to Measuring Impact
3501E
AI tools are transforming how organizations work but deploying them is only half the battle. This session walks through the full AI lifecycle: using Jamf Pro and the new AI Governance tool to deploy and govern AI applications, leveraging the Jamf AI Assistant to onboard and support users, and building the metrics framework that proves AI is delivering real value. Whether you're just getting started with AI or struggling to drive adoption of tools already in place, you'll leave with a practical playbook you can bring back to your organization. An AI engineer and a change enablement specialist share what Jamf has learned rolling out AI internally, and what you can steal for your own team.
From Exception To Zero Trust Foundation With Mac First
3501A
For years, Mac was often treated as the enterprise exception. This session shows how a Mac-first strategy turned that perceived exception into a practical foundation for Zero Trust maturity in a regulated financial environment, aligned to the CISA Zero Trust Maturity Model. We will connect device compliance, real-time telemetry, custom tooling and GitOps-driven automation to the language security operations teams care about: trust signals, control outcomes and risk reduction. Attendees will leave with a repeatable model for turning endpoint engineering into security influence, governance evidence and scalable architecture.
Hands-on with Jamf Concepts
2502B
Jamf Concepts is an innovation lab where ideas sparked by real customer engagements get turned into working prototypes and tools — exploring what's possible building on the Jamf platform. In this hands-on lab, you'll get direct access to some of the most popular Concepts and their developers. These aren't slides or demos — they're working tools you can explore, interact with and evaluate against your own environment and workflows. Walk the room, talk to the developers who built them and see how experimental ideas could complement the way you already use Jamf today. Whether you're an admin looking for smarter workflows, a leader thinking about what's possible at scale or just curious — there's something here for you. Come ready to explore, ask questions and share what problems you'd love to see tackled next.
Practical Guide to Blueprints: One Year in Production
2103A
Blueprints changed how many Jamf administrators think about device management, but what does it actually look like after a year in production? This session is a follow up to last year's Practical Guide to Blueprints session. We are bringing back together the Jamf product team and a real customer to share an honest retrospective on what worked, what needed work and what changed. Chris Hafner from Brewster Academy rejoins Michael Managhan and Jakub Talaš from Jamf to compare notes on software update workflows, privacy controls, compliance requirements and the reality of running legacy profiles alongside modern management. Attendees will leave with practical implementation strategies, a clearer picture of where Blueprints is headed and honest advice from someone who has been in their shoes.
Prompt Engineering with Jamf's AI Assistant (BYOD)
2502A
AI is everywhere. Knowing what to ask, and how to ask it, is a skill most of us are still developing. This hands-on lab focuses on one thing: getting real, practical value out of Jamf's AI Assistant in your own environment. Attendees will log into Jamf environments via Jamf Account SSO and work through a guided prompt workbook, progressing from confidence-building exploration queries to action-oriented prompts that accelerate real administrative workflows. *Note: This session is BYOD, please bring your own Mac. Along the way, you'll learn how to refine prompts when results aren't quite right, how to provide context that improves output quality and how to treat AI Assistant as a starting point for doing work rather than a finished product. For those ready to go further, the session closes with a look at how AI Assistant can serve as your personal guide to the Jamf API. This session is meant to be collaborative, so please be ready to share your own unique uses cases and the challenges you face in your own environment.
The AI-Empowered Jamf Admin: From Scripts to Agents
Grand Ballroom A1
AI isn't replacing the Jamf admin. It's changing what one admin can do. Two Jamf consulting engineers share how they've wired AI directly into their Apple fleet management workflows, moving past traditional scripts and dashboards into agentic, conversational and AI-assisted administration. Walk through real, working examples and demos from our actual environments. You'll see a Model Context Protocol (MCP) server that lets an AI agent execute Jamf workflows natively on macOS. Natural language interfaces that turn plain English into precise Jamf Pro API queries. AI-assisted health scoring that flags at-risk devices before users file a ticket. And how Claude Code has reshaped the way we build and maintain admin tooling, with less busywork and more craft. Whether you're a hands-on admin looking to 10x your workflow or a leader evaluating how AI fits into your team's operations, you'll leave with a clear picture of what's practical today: Jamf's native AI capabilities, custom agentic tooling, what to build toward and what guardrails to put in place before giving an AI agent access to your environment. No prior AI experience required. You will leave with loot.
The Mac Is Deployed. Now Who Answers the Ticket?
2504A
Jamf and Apple Business Manager (ABM) get every Mac assigned, enrolled, and into the employee's hands. Then the requests start: access, app installs, "my Mac won't," day-one onboarding. This session shows how Fireblocks put an AI service desk agent in Slack and Teams that resolves 70 to 75 percent of those requests autonomously, grounded in live asset data from Jamf and ABM, so the device is tied to its employee from the moment it is assigned through every ticket it ever raises. Real workflows, real resolution rates, and what to automate first.
Threat Hunting with Beacon by Jamf Threat Labs
Jamf Booth Theater - Exhibit Hall D
Watch Jamf Threat Labs show how Beacon surfaces and investigates real-world Mac threats.
Why Your MDM Works… Until It Doesn’t: When Endpoint Protection Posture Becomes the Problem
2505A
Apple MDM is designed to behave consistently: the same request should produce the same result. Yet in many enterprise environments, identical actions can yield inconsistent outcomes — policies fail, installs stall and check-ins succeed only after retry. This session presents a real-world investigation into two separate failure domains that initially appeared related: - A Jamf Pro server-side XML serialization defect, later confirmed by Jamf Engineering as a previously unknown product issue and assigned PI-1159 - A separate endpoint-side control-plane fragmentation pattern in which layered security tools evaluated the same traffic under different runtime conditions Through controlled testing, log correlation and packet capture analysis, this session demonstrates how multiple enforcement layers can introduce timing-dependent behavior. The result can look random from the MDM administrator’s perspective, even when each individual system is operating according to its own rules. Attendees will learn how to: - Distinguish between unrelated failure domains - Recognize retry-dependent success, path-dependent behavior and state-sensitive failures - Validate root causes using logs, network traces, and system state correlation - Restore reliable macOS management by aligning control-plane behavior without weakening security posture This session provides a practical diagnostic framework for MacAdmins and security engineers working in complex, high-governance environments where MDM, identity, networking and endpoint protection controls all intersect.
Premium Support Updates
Jamf Booth Theater - Exhibit Hall D
Find out how a dedicated Technical Account Manager helps you get more value from Jamf.
Authentication Made Easy: Simple, Secure Sign-In on Shared Apple Devices
Spotlight Theater - Exhibit Hall D
This session explores practical ways to simplify secure sign-in for frontline workers using shared Apple devices. Attendees will learn how passkeys and FIDO-based authentication can reduce reliance on typed usernames and passwords by enabling sign-in with a badge, fingerprint, or face. We will also clarify how passkeys can be used to securely access Jamf and other enterprise accounts and applications on Apple devices. The session will cover the user experience, security benefits, and practical considerations for deploying passwordless authentication in shared-device environments.
10:00 AM CDT - Thursday, Sep 24
An Apple Journey with UC Health: Mac and Mobility Roadmap
2505A
Join us as we walk through how UC Health deployed Mac across the entire organization — from early ideas and pilot use cases to full clinical and non‑clinical rollout. We’ll explore how Mac and mobility support real workflows today and share what’s next as we continue to balance clinician experience, compliance, and security. We’ll finish by grounding it all in reality: how the “average Joe” actually uses mobility to deliver care and support the hospital, day in and day out.
App Installers, Reimagined: Third-Party Apps in Blueprints
Grand Ballroom A1
App Installers changed how admins deploy and update third-party macOS apps. Now, third-party app management is being rebuilt from the ground up — inside blueprints. This session introduces a new approach to managing third-party apps in Jamf Pro. You'll see how to browse the app catalog, add apps to a blueprint, and keep them up to date automatically as new versions become available — with control over when installs happen on your devices. We'll walk through the new workflow and show how it compares to App Installers today. If you manage third-party apps with Jamf, this session shows you what's coming next.
Apple session: What's New for IT
3501E
Compliance From Chaos: Benchmarks, Blueprints and a Better Fleet (BYOD)
2502A
Many Jamf Pro administrators know their fleet has compliance gaps. However, setting up an automated, reliable workflow can seem like a daunting task. This interactive lab walks through a real, end-to-end workflow for setting up Compliance Benchmarks and blueprints in Jamf Pro, covering CIS Level 2 enforcement, software currency monitoring and declarative OS update management. Attendees will complete the full workflow in a guided simulation they can revisit and replicate in their own environment. *Note: This session is BYOD, please bring your own Mac.
Compliance Without Compromise: Apple Device Management in Jamf's FedRAMP and High Compliance Environments.
Grand Ballroom A2
Managing Apple Devices in a federal or high compliance environment doesn't have to mean trading agility for security. This session explores Jamf's two purpose-built environments — FedCloud, authorized under FedRAMP and Jamf's High Compliance environment, authorized under NIST 800-53 Rev 5 — and the powerful capabilities within them. We'll walk through Declarative Device Management, blueprints, compliance baselines and the Jamf App Catalog, showing how each helps you maintain compliance without slowing down your team. Whether you're supporting a government agency or a regulated enterprise, leave with a clear picture of what these environments offer and how to make the most of them.
Discovery Deputy: macOS Tooling for Jamf School
Jamf Booth Theater - Exhibit Hall D
An early look at Deputy, a Jamf Concept. Automation tooling for macOS & Jamf School. Take a look and tell us what you think!
From ClickOps to Code: Refactoring Jamf Workflows into Terraform Modules
2502B
Join this interactive hands-on lab designed for technical teams looking to take their Jamf platform management to the next level with Infrastructure as Code (IaC). In this lab, participants will gain foundational practical experience using Terraform to convert existing workflows into reusable, modular code across: -Jamf Pro -macOS Security Portal -Jamf Security Cloud By the end of the lab, attendees will understand how to build and structure Terraform modules that support different environments and enable scalable and consistent management of their entire Jamf platform.
From Tickets to Resolved: AI Agents for Device Support
2504A
Ravenna is an AI-native platform, built inside Slack and Teams, that helps IT teams resolve employee requests end to end instead of working tickets one at a time. This session opens with how that works broadly, then goes deep on device-related support, the territory every JNUC attendee lives in daily. Attendees will see a real walkthrough of a device request moving from intake to resolution, and leave with a concrete view of what's automatable in device support today versus what still needs a person in the loop. We'll also share a real customer story from a team using Ravenna to close this exact gap. Find us at booth #602 all week to go deeper, and to see a live demo of the story we're sharing on stage.
How Salesforce will Improve User Experience and Security with Okta and Platform SSO
3501A
The Mac enterprise community has been excited about Apple's development of the Platform SSO framework for user identity management. Now that many of these features are available with support from Jamf and Okta, see how Salesforce will be implementing PSSO to improve the new hire onboarding experience while also increasing security behind the scenes.
Identity-Aware Cloud Infrastructure: Securing Azure & AKS with Jamf Connect ZTNA
2104A
As organizations move toward "Private-by-Default" cloud architectures, the challenge of providing seamless access to developers and admins grows. Traditional VPNs are often clunky, and public endpoints are a security risk. This session provides a technical blueprint for implementing Identity-Aware Cloud Infrastructure by integrating Jamf Connect Zero Trust Network Access (ZTNA) with Azure Private Endpoints. We will explore how any organization can eliminate the need for public-facing endpoints by leveraging Jamf Trust as a secure gateway ensuring that users can only reach the Azure Portal, CLI and internal Kubernetes clusters when they are on a trusted, managed device. We will cover the networking "magic" of Site-to-Site IPsec interconnects between Jamf Security Cloud and Azure VNETs, and how to define access policies that make private resources feel local.
K-12: Deploying Platform SSO in Schools
2103A
Is implementing Platform SSO a struggle for your school district? D203 uses Active Directory for authentication which does not work well with macOS 26. We have about 200 lab iMac devices that require the implementation of Platform SSO using Entra. Learn about our deployment solution and together we can come up with better practices going forward.
Securing Mac with Jamf Threat Prevention and Data Security
Grand Ballroom B
This session covers two capabilities worth knowing about: a redesigned Threat Prevention experience built on Jamf Threat Labs' research, and a new capability that goes beyond detection to protect what matters most — your data. Whether you're already using Jamf or just getting started, you'll leave with two things worth your attention this week.
Sustainability That Actually Makes Money: Turning Apple Device Lifecycle into Budget, Compliance and Measurable Impact
2103C
Sustainability in Apple device environments is often treated as reporting, not strategy. This session shows how IT leaders can integrate lifecycle management into Jamf-driven workflows to recover budget, reduce risk and meet growing ESG and compliance requirements. Attendees will learn how to time refresh cycles around market value, align secure decommissioning with data protection standards and quantify both financial return and environmental impact. Guests will leave with a practical framework to turn device lifecycle into a repeatable system that improves performance, strengthens security and supports institutional goals.
Simplify Apple OS Updates with Upgrade Manager
Jamf Booth Theater - Exhibit Hall D
See how Upgrade Manager simplifies the scheduling, monitoring, and rollout of iOS, iPadOS, and macOS updates across your organisation.
11:00 AM CDT - Thursday, Sep 24
Analyze Your Environment With SHI
Spotlight Theater - Exhibit Hall D
Let SHI help you optimize your Apple deployments to ensure you are managing your environment in the most efficient way possible. From their Fleet Analysis tool, providing enhanced insights into your Apple inventory, to their wide array of service offerings SHI goes beyond a reseller to a trusted IT partner. Their investments in your environment enable your devices and teams to maximize their potential.
Identity-triggered device management in education
Jamf Booth Theater - Exhibit Hall D
Learn how identity signals can automatically drive device configuration and access in school environments.
Business as Unusual: iPad devices as Controversial Learning Tools
2505A
In a world growing increasingly skeptical of instructional technology and how it is used in the classroom, it is important to pause and meet the moment. Dopamine addiction is real, AI is controversial and iPad devices can serve as a distraction for students. This session will focus on real strategies to ensure that instructional technology is a powerful and purposeful tool to continue to transform teaching and learning in the midst of controversy.
From Shadow IT to Shadow AI: Govern AI Tools with Jamf
Grand Ballroom A2
AI agents and coding assistants are the fastest-growing category of shadow IT, yet most organizations lack visibility into which tools employees are using. This session walks through a practical framework for blocking unwanted AI tools and managing approved ones across your Jamf-managed Mac fleet. You'll leave with a reusable detection-to-remediation pipeline you can adapt to most AI tools, plus content filtering strategies to control browser-based AI access.
From Zero to Classroom Control: Deploying Jamf Teacher with Jamf Pro
2502B
Jamf Teacher gives educators powerful, real-time control over student iPad devices — but getting it deployed correctly through Jamf Pro requires careful planning. This session walks attendees through the full deployment lifecycle: from scoping and managed app configuration to class setup, restriction management, and day-to-day teacher experience. Whether you're a K-12 admin managing hundreds of classrooms or just getting started, you'll leave with a repeatable deployment playbook.
How NOT to Onboard an iPhone or iPad - From connectivity chaos to the eSIM gold standard with 1GLOBAL and Jamf
2504A
The Good, the Bad and the Secure — with 1GLOBAL eSIM and Jamf for Mobile This session follows the end-user journey from initial device onboarding through to the challenges, risks and potential chaos that can come with poorly managed mobile connectivity. We’ll look at how not to onboard an iPhone or iPad with connectivity, including some real-world examples that highlight where things can go wrong. We’ll also explore the risks organisations face when they lack control over eSIM and mobile connectivity — from direct financial impact to wider security exposure. From there, we’ll show what secure looks like. Using 1GLOBAL and Jamf for Mobile, we’ll walk through a streamlined end-user experience that simplifies eSIM deployment, removes unnecessary manual steps, improves control, and helps protect both the user and the organisation. The goal is simple: make connectivity almost invisible for the end user, while giving IT and security teams far greater control.
Managing the Jamf Platform at Scale with Infrastructure as Code
Grand Ballroom A1
Managing Jamf configuration through a web UI works until it doesn't. As environments grow in complexity or span multiple instances, manual processes introduce inconsistency, configuration drift and operational risk that are difficult to detect and costly to fix. This session shows how Infrastructure as Code techniques and tooling, including Jamf's Terraform providers, bring version control, automated pipelines and repeatable deployments to Jamf Protect, Jamf Pro and the broader Jamf platform. Using a production multi-tenant Jamf Protect macOS Security Portal deployment as the worked example, we walk through the practical journey from UI-driven management to a fully automated CI/CD pipeline with isolated state, secrets management and Git as the single source of truth. Walk out with patterns that work across any Jamf environment, regardless of scale or product.
Modernizing Mobile App Approvals: How Travis County Uses NowSecure + Jamf to Reduce Risk
3501A
In this joint session, Travis County and NowSecure will share how they built and scaled a mobile app technology assessment program that materially reduced risk and approval timelines for a large public-sector environment. Attendees will learn how Travis County replaced a weeks-long approval process with a streamlined workflow using NowSecure reports, enabling faster, evidence-based decisions with fewer surprises. We’ll walk through Travis County’s end‑to‑end intake and review process, highlight real metrics and lessons learned from assessing government mobile apps, and then unpack what’s actually inside the NowSecure reports—how the tests work, what signals and risks they surface beyond simple high/medium/low scores, and how security, legal, and compliance teams use those insights to protect sensitive data while still saying “yes” to the right apps.
Rethinking Device Management: Advanced Blueprints in Jamf Pro (BYOD)
2502A
Blueprints and Declarative Device Management are the future of Apple device management. In this session, we'll take a look at the more advanced components we have available including Disk Management policy, Service Background Tasks, Service Configuration Files and Custom Declarations. *Note: This session is BYOD, please bring your own Mac.
Seesaw AI and Jamf Teacher in the Classroom: Improving Digital Workflow
2104A
Discover how a purposeful deployment of iPad brought together the power of Jamf and Seesaw to transform learning across diverse device environments. This session highlights the implementation of Seesaw across 1:1 and shared iPad devices and parent-owned devices at Jamf CEI/MATTER partner schools in Zimbabwe. Attendees will explore how to leverage Seesaw AI and Jamf in their organization as a complement to STEAM programs, by supporting improved lesson creation and shortening the feedback loop between teachers, students and parents.
Shared iOS Devices are my Bag Baby!
3501E
See how Tapestry — the parent company of Coach and Kate Spade — is using shared iOS devices with Jamf Setup and Jamf Reset to simplify frontline operations across its distribution centers. In this session, Rob Barlow, Tapestry's lead architect for end user compute, and Chris Diaz, Jamf senior business development executive, industry solutions will discuss the growth of shared devices for the frontline and how it simplifies work for the end user, increases device flexibility and device observability for admins while using Microsoft Entra ID. You will also see how frontline managers and staff leverage Return to Service to have a tier zero self help option in the field if something isn't working as expected, this solution has helped decrease the amount of tier -1, 0 tickets and helped the end user get back to the work they can only do.
Tips and Tricks from the Jamf Engineers
Grand Ballroom B
This session is packed with focused, practical and surprising tips and tricks from the Jamf Solutions Engineering team. Each one is designed to be immediately actionable: something you can take away and try the very same day. Whether you're looking to step up your workflows, uncover hidden features or just get more from tools you already have, there's something useful for every Jamf admin.
What’s new in Routines
2103C
There’s a lot changing in Routines, starting with the biggest: the workflow is now yours to see and shape. We’ll open the canvas — every step of a is workflow visible and configurable, built around how your environment works. Templates aren’t going anywhere either; we’re investing in a deeper library, giving you a head start when you need one. From there we’ll get into the rest: a broader connector library so Routines can reach more of the tools your team already runs, execution visibility so you can see what happened on a run and troubleshoot it, and access controls so only the right people can modify a workflow. Whether you’re running Routines today or looking at it for the first time, you’ll leave with a clear picture of what it can do.
Zero-Touch at Scale: SDSU’s Deployment Strategy Using Platform SSO and Secure Enclave
2103A
San Diego State University transformed its endpoint deployment model by combining Apple’s zero-touch provisioning with Platform Single Sign-On (SSO) and Secure Enclave-backed authentication. Brian Lenz and Chris Potente will discuss SDSU’s journey to deliver secure, fully configured macOS devices to faculty, staff and students without IT intervention, while maintaining strong identity assurance and compliance. Attendees will gain a practical blueprint for integrating Apple School Manager, MDM, Platform SSO and hardware-backed security to modernize device lifecycle management in higher education.
Threat Hunting with Beacon by Jamf Threat Labs
Jamf Booth Theater - Exhibit Hall D
Watch Jamf Threat Labs show how Beacon surfaces and investigates real-world Mac threats.
12:00 PM CDT - Thursday, Sep 24
Lunch
Exhibit Hall E
Join us in Exhibit Hall E for lunch - 12:15 PM - 1:45 PM
Screen time to screen value
Jamf Booth Theater - Exhibit Hall D
Learn how shifting from screen time to screen value can improve learning outcomes.
From Zero-Touch to Zero-Ticket: Extending Jamf's Deployment and Management into Autonomous Mac Monitoring and Issue Resolution
Spotlight Theater - Exhibit Hall D
Jamf gets Macs enrolled and configured in minutes and maintains the policies and configuration. But once that MacBook is in an employee's hands, "zero-touch" often gives way to "constant-triage" of battery drain, Wi-Fi flakiness, app crashes, and web pages issues that Jamf's lens wasn't built to catch in real time. This session walks Mac admins through ControlUp's deep integration with macOS metrics and data, centralized scripting and alerting and more in a platform that the help desk and support personnel can use also for PCs. We'll demo the deployment flow live, then show what IT actually sees and can auto-remediate once telemetry starts flowing. Attendees leave with a practical adoption path they can run in their own macOS environment the same week.


