Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Beacon & AI Governance: Jamf's Mac Security Stack

Jamf
07/31/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


Good morning, Jamf Nation. Wow, there are a lot of people here today. It's nice to see the room full, and we've got some really awesome new stuff to show you. Okay, so Katie's shown you how Blueprints give you one place to define and deploy configurations across your Apple fleet. And of course, software update enforcement is one of the most critical things that you could do in a Blueprint, because devices running the latest version from Apple are obviously going to be as secure as possible. But configuration updates are just part of your security and management story. You also need to be thinking about how your devices meet your organization's security Not just if they're configured, but if they're configured correctly against a recognized benchmark and with evidence that you can verify and show. Jamf compliance benchmarks, which are built on the macOS Security Compliance Project, or MSCP, and aligned to CIS Level 1 and 2 and NIST benchmarks, are continuously validating your device posture. So they will automatically remediate any deviations when they find them, and it's going to generate an auditing document that you can hand over to your team or your regulator or your auditor when required as an evidence trail. Now, the relationship between Blueprints and compliance benchmarks is worth trying to understand, because they're complementary, they're not overlapping. Blueprints is how you declare what a device should be. Compliance benchmarks are how you continuously verify that it stayed that way and corrects it when it doesn't. So together, they're closing the loop between intent and reality. Now, when I was an Apple admin, I probably lived on the intent side of this calculation. Make an update or a config change, push it out, and just kind of hope that everyone got it. Maybe do a little bit of spot checking. But these days, with more regulation and oversight in our industry, we need to deal with the reality side of this calculation as well. We need to prove that those device changes and updates did actually hit every device, that they're still in effect, and that people aren't changing them. So that's how compliance benchmarks are important, or why they're important. Now, sitting underneath all of this, we also have Jamf Protect, and that's giving you that continuous monitoring, behavioral analytics, threat prevention on all your devices, and it's streaming the data telemetry that we're capturing directly over to your SIEM system, which might be Sentinel, Splunk, Google SecOps. There is a variety of choices here. Now, we're sending Apple native signals. It's not generic endpoint noise or fluff. And then finally, to connect all this together, there's a unified set of APIs that connect to the entire Jamf platform, and that connects to the rest of your security stack. So your source system, ticketing system, HR, identity platform, and so on. So takeaway from this is that Jamf is not operating as an island in your environment. It's an integrated part of your technology stack. But maybe you don't have a SIEM, or perhaps you don't have access to it because it's controlled by another team. Or it might just be that having all that rich telemetry is just overwhelming. And if you're presented with a dashboard like this, you're not too sure where you would even start, let alone what to do if an incident was flagged. Well, this is where Beacon by Jamf Threat Labs comes in. This is a brand new service which puts Jamf's own Mac threat researchers to work in your environment. When you have this service, these guys will be actively hunting for threats using your Protect telemetry data. And if they find something, they will deliver a direct notification to you, and they'll give you the remediation guidance that you need to fix it. And this is all coming from a team that does nothing other than think about Mac security day in and day out. So in summary, Blueprints are enforcing the update. Compliance benchmarks are validating that every device has them. Protect is then giving us the telemetry data signals. And then Jamf Beacon is answering the hardest question here, which is, was there already suspicious activity in your network before you even knew that there was a patch available? So if you'd like to know more about how Jamf Beacon can help you, please stop by the Jamf Shorts Theater in the Success Lounge. That's the room downstairs on the ground floor. And if you'd like to know more about Apple telemetry and how it can help you, make sure you catch the session that's at 2 p.m. in the King Vault room. That's on the lower ground level. That session is a cracker. I've seen it. It's awesome. OK. So your devices are configured. They're up-to-date. Your security stack's getting those signals. Your compliance posture says everything's fine. And your dashboard is looking green. But here's a question that's not been answered yet. In fact, this question may not have even been asked. What about AI? You see, right now on those same devices that just came up with all those green check marks, your developers are probably running Claude Code or Codex or Cursor. And your knowledge workers are probably using Cowork or ChatGBT. And maybe you have an engineering team that's using GitHub Copilot. A few people have probably picked up tools you've not even heard of before. They might even be running LLMs locally on their device, maybe one with a big red lobster icon. These tools are already in your fleet. And most of them arrived within the last 12 months. And we all know who is most likely to be running shadow IT tools, don't we? That's right. It's your execs and your VIPs every time, guaranteed. The people who you don't want to be having a data leakage problem with. And yet these are the tools that are probably consuming a lot of your corporate data, sensitive facts about your company. And here's the thing. If the user has activated an MCP server in their AI tool, that's like having an uncontrolled API gateway that's connected directly to your internal systems. Now, that's a compliance gap that your existing security posture doesn't cover. 98% of organizations are reporting unsanctioned AI use on their endpoints. And here within Europe, companies are also having to prepare for the EU AI Act. Now, this is an obligation that applies to the UK as well. And it calls for organizations to document their risk management of AI in your environment. So if you're in a regulated industry like fintech, healthcare, public sector, or you work with organizations in those environments, you need to be working on this right now. Because this comes in very, very soon. So the problem isn't that your users are running these AI tools. We use a lot of these tools ourselves at Jamf. The problem is that no one has a control plane for them. Now, AI vendors have started to ship with enterprise configuration controls for these tools. Things like model restrictions, data access permissions, MCP server governance, command level permissions, allow and deny. And yet, almost all of them are just sitting untouched. Very few companies know that these controls exist for AI tools, let alone have gone to the trouble of configuring them and scoping and deploying them. So AI is usually not being governed in most people's environment, which is a massive risk. Well, that's why today we're announcing a new functionality, Jamf AI Governance. This is your control plane for AI on Mac. This will help you to see the AI tools that are running across your Mac fleet. And you will know what has been sanctioned or approved, and what is ungoverned and uncontrolled. You'll be able to see what's running in your environment right now, and then control it using the management plane that you're already using today, the Jamf platform. So let's take a look at AI Governance. What you're about to see here is a world first public preview of this new functionality, which is going to be launching on June the 30th. You're the first customers anywhere to see this, which means I'm petrified right now if this is going to work or not. So let's have a quick look at the product in the real world. I'm going to invite to the stage my friend Rob Potvin, who's a senior consulting engineer here at Jamf. Thank you. We are on the bleeding edge here, by the way. All the demo god sacrifices have been made. Okay, so first of all, let's start with Jamf Account. Now the reason we're starting Jamf Account, that's of course the launchpad into all the services that you get on the Jamf platform. And the reason we've got it in here is because quite often the AI Governance team is completely separate to the Mac admin team. So this lets them have visibility into this particular piece without you having to let them into Jamf Pro or muck around with those sort of permissions. So let's go into AI Governance, Rob. And the first thing that people usually want to do is see what AI tools are running in their environment. So as this page loads, and you can see we can change the timeframe there, it's giving us an idea of all those tools that we're seeing running. So you can see it is Claude, VS Code, Cursor, Windsurf, all sorts of tools. There's a good chance you wouldn't have known that those things were running. Now Claude code is something we use a lot at Jamf. So let's click on that and go and see what we can see is happening there. So you can see how many people are using that. You can see the usage over time here as well. And you can see what's calling Claude, but also what Claude is calling itself. So you're getting an idea now of the activity that's going in and out of this tool. And you notice down the bottom there in red, it's got potentially risky commands. So these are the things that are probably worrying you, might even keep you up at night, or at least your InfoSec team. Things like, is Claude calling OSA script? Is it calling SCP? Is it calling SSH? These are the things that you probably want to get alerted about. So here's the great thing about what you're seeing here. All this data that's being surfaced here, we've not installed any new agent on your device at all. This is using the Jamf agent that's already on your devices. So nothing else extra is required. And that also means that no other cross-platform tool can do this for you today, because they just don't have the same insights into your devices that Jamf does. OK, so we've done the AI visibility. We see what's running. Let's have a look now at how we can start to govern AI. A common request here would probably be, let's make sure everyone in the team is using the same model version. So we're going to set up Claude. You can see there's other options in there we're adding to all the time. We're using Anthropic for our authentication. That means we're using their infrastructure. That's who builds us for the tokens. And then in here, we're going to specify which model we want the team to use. Now, to be honest, we were going to actually talk about restricting Fable here, but the US government has done that for us already and destroyed our demo. So what we're going to do is we're going to restrict the team to Sonnet and Haiku, because Opus just choose tokens, and we're really cheap with this demo. So we will just choose those. You can see we can also specify default, so we can steer a team towards using one model that might be cheaper to run or give more consistent results as well. We don't want everyone on a different version with hallucinations coming into our work. While we're here, let's also go and add a startup message to the AI tool as well. Now, this is a lot like I'm going to show Rob and I's age here. But back in the day, it was quite common when you were testing things to put a login window banner on your Macs, and that way you would see if your MCX prefs were working or not. We're going to do the same thing here. It's an easy way to see if these settings are working or not. So you can see there's a lot of settings in here. We don't have time to dig into all of that today. The important thing here is we're pulling all of this stuff down from Anthropic live. So when Anthropic make changes to the enterprise controls and their products, it's going to get surfaced here in the Jamf GUI for you. And that means you don't have to go in there and be editing any sort of JSON files, XML files by hand. It's all here in a GUI that explains exactly what these settings do for you. OK, so we've saved this policy. Now we need to deploy this out to our devices. How do we do that? It's going to be the same way we did the software update settings. We're going to use a blueprint to do this. So we're going to use the app switcher to jump across to pro now. This might be where you, as the Jamf admin, is going to get involved in deploying these settings out. The great thing about using a blueprint is, of course, it's going to use DDM to deploy this. It's going to be fast. It's going to be reliable. It's going to be tamper-proof. It's going to hit the device at the lowest level. The user's not going to be able to overwrite these settings. So Rob's in here. He's going to search for Claude, and he's going to find the settings that we just made. So he's going to pick that policy and the version of it, and you'll see the settings in there that matches what he set up before. So we know that's good. He's going to scope that out to our developers. So we've got a smart group already made for that, and he's going to give that a name and hit Deploy, and those settings are now going to head out to the device. Okay, fantastic. So we've done that. We've created the policy. We've deployed it. Let's go and see if that actually worked now. So we'll jump across to one of our endpoints, and let's go and fire up Claude Code as if we're a developer. I'm very impressed with Rob's terminal design here, by the way. I love that. Okay, so we're going to fire up Claude, and you can see that banner message there in the middle, right? Kind of like a login window. Hello, Jamf Nation. So we know those settings have come down, and they're sticking. Let's have a look at what models are available. And we go and ask for the models, and you can see we've got Haiku and Sonnet. Opus hasn't shown up, neither has Fable. So those settings came down, and they worked. Okay, we know that it worked. How do we prove back to our leadership or our change control team that it actually worked? Well, if we go back to AI Governance, we've made it so that you can download a report that shows all the settings that you've got in there. So if we pull that report down, it's going to generate a PDF for us, which Rob will then pull up, and that report is going to show us the AI visibility. So that's great to hand to your leadership. It's also going to dig into the details of the policies we've made, who made them, timestamps, audit logs, all that sort of nice stuff that you can hand over either to your change control team or your auditor. So this is what it looks like to use Jamf to govern AI on your Macs. Great demo. Thanks, Rob. I don't know why I was worried. It worked fine. So that's Jamf AI Governance. It's brand new. We're very excited to show it to you, and as Tim Apple would say, we think you're going to love it. It's coming on June the 30th for Jamf for Mac customers, and if you would like to learn more about this product, make sure you go to the live lounge, which is happening in the Queen and James Waltz, that's down on the lower ground floor at 115.

TL;DR

  • Jamf's Mac security stack layers Blueprints (intent), Compliance Benchmarks (continuous verification against mSCP, CIS, NIST), Jamf Protect (telemetry and threat prevention), and unified APIs connecting to SIEM, identity, and ticketing systems.
  • Beacon by Jamf Threat Labs is a new managed service that puts Jamf's Mac security researchers to work hunting threats in your Protect telemetry, delivering direct alerts and remediation guidance without requiring internal SIEM expertise.
  • Jamf AI Governance, launching June 30, is a new control plane that discovers all AI tools running on Mac fleets — including shadow AI — and applies enterprise controls (model restrictions, MCP governance) deployed via Blueprint DDM.
  • The EU AI Act and 98% unsanctioned AI usage rates are cited as the regulatory and operational drivers for AI Governance, with MCP servers specifically called out as creating uncontrolled API gateways into internal systems.
  • The entire AI Governance capability runs on the existing Jamf agent with no new endpoint software required, and produces audit-ready PDF reports for leadership, change control teams, and regulators.

The Jamf Mac Security Stack Explained

This keynote segment from Jamf Nation Live London 2026 opens by framing the layered security architecture Jamf provides for Apple fleets. Blueprints serve as the declaration layer — defining what a device should look like and enforcing software updates. Compliance Benchmarks, built on the macOS Security Compliance Project (mSCP) and aligned to CIS Level 1 and 2 and NIST standards, continuously validate that devices remain in that desired state, automatically remediating deviations and generating audit-ready evidence trails. The distinction is deliberate: Blueprints express intent, Compliance Benchmarks verify reality. Jamf Protect sits beneath both, delivering continuous behavioral monitoring, threat prevention, and Apple-native telemetry streamed to SIEM platforms such as Microsoft Sentinel, Splunk, and Google SecOps. A unified API layer connects the entire Jamf platform to the broader security stack — ticketing systems, identity providers, HR platforms — positioning Jamf as an integrated component of enterprise security rather than a standalone tool.

Beacon by Jamf Threat Labs: Managed Mac Threat Hunting

For organizations that lack a dedicated SIEM, lack access to one controlled by another team, or simply find raw telemetry dashboards overwhelming, Jamf introduces Beacon by Jamf Threat Labs. This managed service deploys Jamf's own Mac-focused threat researchers directly against an organization's Jamf Protect telemetry. Rather than requiring internal analysts to interpret complex signals, Beacon's team actively hunts for threats, delivers direct notifications when suspicious activity is identified, and provides specific remediation guidance. The service addresses a critical timing gap: detecting suspicious activity that may have occurred before a patch was even known to be available. Beacon is positioned as the answer to the hardest question in the security stack — not whether devices are configured correctly, but whether they were already compromised before the configuration was applied.

Jamf AI Governance: Controlling Shadow AI on Mac

The keynote's headline announcement is Jamf AI Governance, described as a control plane for AI tools running on Mac fleets. The problem framing is pointed: 98% of organizations report unsanctioned AI use on endpoints, tools like Claude Code, Cursor, Windsurf, and locally-run LLMs are already present on managed devices, and activated MCP servers create uncontrolled API gateways into internal systems. The EU AI Act adds regulatory urgency, particularly for fintech, healthcare, and public sector organizations. AI Governance addresses this by surfacing all AI tools running across the fleet — without deploying any new agent, using the existing Jamf agent — and enabling administrators to apply enterprise controls such as model restrictions, MCP server governance, and command-level permissions sourced live from AI vendors like Anthropic. Policies are deployed via Blueprint using Declarative Device Management (DDM), making them fast, reliable, and tamper-proof. An audit-ready PDF report documents all settings, policies, timestamps, and audit logs for change control teams and regulators. The product launches June 30 for Jamf for Mac customers.

Chapters

0:00 - Blueprints and Software Update Enforcement
1:04 - Compliance Benchmarks: Posture Validation
2:40 - Jamf Protect and the Integrated Security Stack
3:35 - Beacon by Jamf Threat Labs Introduced
5:24 - The Shadow AI Problem
6:13 - MCP Servers, EU AI Act, and Governance Gap
8:02 - Announcing Jamf AI Governance
9:18 - Live Demo: AI Tool Discovery
11:31 - Model Restrictions and Enterprise Controls
13:58 - Blueprint Deployment via DDM
15:05 - Endpoint Verification and Audit Report
16:56 - Launch Date and Wrap-Up

Key Quotes

1:44 "Blueprints is how you declare what a device should be. Compliance benchmarks are how you continuously verify that it stayed that way and corrects it when it doesn't."
6:53 "If the user has activated an MCP server in their AI tool, that's like having an uncontrolled API gateway that's connected directly to your internal systems."
7:09 "... 98% of organizations are reporting unsanctioned AI use on their endpoints."
7:54 "The problem isn't that your users are running these AI tools. We use a lot of these tools ourselves at Jamf. The problem is that no one has a control plane for them."
11:34 "All this data that's being surfaced here, we've not installed any new agent on your device at all. This is using the Jamf agent that's already on your devices. So nothing else extra is required."
11:46 "No other cross-platform tool can do this for you today, because they just don't have the same insights into your devices that Jamf does."

FAQ

What is the difference between Jamf Blueprints and Compliance Benchmarks?

Blueprints define what a device should be configured to — they declare intent and enforce settings including software updates. Compliance Benchmarks continuously verify that devices remain in that desired state, automatically remediate deviations when found, and generate audit documentation. They are complementary: Blueprints set the standard, Compliance Benchmarks prove it is being maintained.

Does Jamf AI Governance require a new agent to be installed on endpoints?

No. AI Governance uses the existing Jamf agent already deployed on managed devices. No additional endpoint software is required, which Jamf also uses as a competitive differentiator, noting that cross-platform tools cannot provide the same depth of Mac-native insight.

When does Jamf AI Governance launch and who can access it?

Jamf AI Governance launches on June 30 and is available to Jamf for Mac customers. The keynote at Jamf Nation Live London 2026 represented the first public preview of the product anywhere.


Categories:
  • » Cybersecurity » Endpoint Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Security Operations
  • Endpoint Management
  • AI & Machine Learning
  • Compliance & Governance
  • Demo
  • Technical Deep Dive
  • Mac security stack
  • AI governance
  • shadow AI
  • managed threat hunting
  • compliance benchmarks
  • Declarative Device Management
  • MCP server risk
  • EU AI Act
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Beacon & AI Governance: Jamf's Mac Security Stack

              Industry Events (Sponsor Hosted)

              • Aug
                03

                Discover DLP Memories: The ever-evolving triage agent enhancing efficiency each shift.

                08/03/202611:00 AM ET
                • Aug
                  06

                  Safeguarding Sensitive Data in the Era of Public AI Platforms

                  08/06/202604:00 AM ET
                  • Aug
                    06

                    Same Tactics, Enhanced Speed: AI Agents’ Impact on Identity Attacks

                    08/06/202602:00 PM ET
                    More events

                    Upcoming Webinar Calendar

                    • 08/03/2026
                      11:00 AM
                      08/03/2026
                      Discover DLP Memories: The ever-evolving triage agent enhancing efficiency each shift.
                      https://www.truthinit.com/index.php/channel/2062/discover-dlp-memories-the-ever-evolving-triage-agent-enhancing-efficiency-each-shift/
                    • 08/06/2026
                      04:00 AM
                      08/06/2026
                      Safeguarding Sensitive Data in the Era of Public AI Platforms
                      https://www.truthinit.com/index.php/channel/2058/safeguarding-sensitive-data-in-the-era-of-public-ai-platforms/
                    • 08/06/2026
                      02:00 PM
                      08/06/2026
                      Same Tactics, Enhanced Speed: AI Agents’ Impact on Identity Attacks
                      https://www.truthinit.com/index.php/channel/2064/same-tactics-enhanced-speed-ai-agents-impact-on-identity-attacks/
                    • 08/07/2026
                      11:30 AM
                      08/07/2026
                      Refreshing Beverage Ideas Paired with Essential Cybersecurity Insights
                      https://www.truthinit.com/index.php/channel/2063/refreshing-beverage-ideas-paired-with-essential-cybersecurity-insights/
                    • 08/13/2026
                      12:00 PM
                      08/13/2026
                      Harnessing AI for Secure Innovation in the Enterprise with Netskope & Omada
                      https://www.truthinit.com/index.php/channel/2065/harnessing-ai-for-secure-innovation-in-the-enterprise-with-netskope-omada/
                    • 08/19/2026
                      12:00 PM
                      08/19/2026
                      Becoming Agent Ready: Insights and Strategies with Cyera
                      https://www.truthinit.com/index.php/channel/2036/becoming-agent-ready-insights-and-strategies-with-cyera/
                    • 09/02/2026
                      12:00 PM
                      09/02/2026
                      Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                      https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                    • 09/30/2026
                      04:00 AM
                      09/30/2026
                      AI Command Center: Optimizing Visibility and Control in Your Operations
                      https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                    Truth in IT
                    • Sponsor
                    • About Us
                    • Terms of Service
                    • Privacy Policy
                    • Contact Us
                    • Preference Management
                    Desktop version
                    Standard version