System
Difficulty: Advanced
4 min read

JAMF: Apple Device Fleet Management

Guide to configuring JAMF to manage and secure macOS and iOS devices in a professional environment.

Back to tutorials
What is JAMF?
JAMF is the market-leading solution for managing Apple devices (MDM - Mobile Device Management). It allows organizations to deploy, configure, manage and secure their Macs, iPhones, iPads and Apple TVs in a centralized and automated way.

Why use JAMF?

  • Apple specialist: Designed exclusively for the Apple ecosystem, JAMF supports new macOS and iOS features as soon as they are released.
  • "Zero-Touch" deployment: Integrated with Apple Business Manager (formerly DEP), a new device can be automatically configured for a user the moment it comes out of the box.
  • Complete management: Goes well beyond basic MDM, enabling script deployment, software package management (.pkg, .dmg), and a very detailed hardware and software inventory.
  • Self Service: Provides users with an enterprise "App Store"-style portal where they can install approved applications and configurations with a single click.

Prerequisites

  • A JAMF Pro instance (Cloud or on-premises).
  • An Apple Business Manager (ABM) or Apple School Manager (ASM) account.
  • An APNs (Apple Push Notification service) Push certificate to communicate with devices.

Premium Content

This advanced tutorial is reserved for premium members.

9,90€ / month
  • All advanced tutorials
  • New content every week
  • Progress tracking
  • Cancel anytime

Written by

Morgann Riu

Cybersecurity and Linux administration expert. I share my knowledge through free tutorials and training to help system administrators and developers secure their infrastructures.

Frequently asked questions

Configuration profile or policy: which one fits a given need?
A configuration profile is declarative: it describes a native system setting (Wi-Fi, password, FileVault, restrictions) and applies to Macs as well as iOS and iPadOS devices. A policy is an execution engine, Mac-only, that triggers an action at a precise moment: install a .pkg, run a script, map a network drive. Simple rule: a system state to enforce is a profile; an action to perform is a policy.
What happens if the APNs Push certificate expires?
The APNs certificate is what authorizes your JAMF server to talk to devices. Once it expires, no MDM command reaches the fleet: profiles stop being pushed, policies stop firing, inventory goes stale. Since it is only valid for one year, plan the renewal ahead: regenerate the signing request from JAMF, have it signed on Apple's Push certificates portal, then import the certificate back into JAMF.
How do I enroll Macs already in service that were not purchased through Apple Business Manager?
Automated enrollment only covers devices attached to the organization's ABM/ASM account, so it does not apply to an existing fleet bought elsewhere. Two routes remain: user-initiated enrollment, where the person visits your instance's enrollment URL and follows the instructions, or deploying an installation package containing the MDM profile, which suits you better if you already have a way to push packages to those machines.
Static group or smart group: what does it change day to day?
A static group is a list you maintain by hand, suited to a fixed scope such as a batch of loaner machines. A smart group is driven by inventory criteria and recomputes its contents continuously: devices join and leave on their own. That is what makes remediation loops possible — a "Macs with FileVault disabled" group paired with a corrective policy empties itself as machines come into compliance.
How does deploying an app on a Mac differ from an iPad?
On Mac you package the application (usually as a .pkg) and deploy it through a policy; a script can also do the job, for instance by leaning on Homebrew. On iOS and iPadOS the logic is different: applications go through the App Store, with volume licensing managed in Apple Business Manager, or are distributed as "in-house" apps when they were developed internally.

Share this tutorial

Did you enjoy this article?

Comments

Checklist Sécurité Linux

30 points essentiels pour sécuriser un serveur Linux. Recevez aussi les nouveaux tutoriels par email.

Pas de spam. Désabonnement en 1 clic.