Transcript
Good morning, Jamf Nation. Wow, there are a lot of people here today. It's nice to see the room full, and we've got some really awesome new stuff to show you. Okay, so Katie's shown you how Blueprints give you one place to define and deploy configurations across your Apple fleet. And of course, software update enforcement is one of the most critical things that you could do in a Blueprint, because devices running the latest version from Apple are obviously going to be as secure as possible. But configuration updates are just part of your security and management story. You also need to be thinking about how your devices meet your organization's security Not just if they're configured, but if they're configured correctly against a recognized benchmark and with evidence that you can verify and show. Jamf compliance benchmarks, which are built on the macOS Security Compliance Project, or MSCP, and aligned to CIS Level 1 and 2 and NIST benchmarks, are continuously validating your device posture. So they will automatically remediate any deviations when they find them, and it's going to generate an auditing document that you can hand over to your team or your regulator or your auditor when required as an evidence trail. Now, the relationship between Blueprints and compliance benchmarks is worth trying to understand, because they're complementary, they're not overlapping. Blueprints is how you declare what a device should be. Compliance benchmarks are how you continuously verify that it stayed that way and corrects it when it doesn't. So together, they're closing the loop between intent and reality. Now, when I was an Apple admin, I probably lived on the intent side of this calculation. Make an update or a config change, push it out, and just kind of hope that everyone got it. Maybe do a little bit of spot checking. But these days, with more regulation and oversight in our industry, we need to deal with the reality side of this calculation as well. We need to prove that those device changes and updates did actually hit every device, that they're still in effect, and that people aren't changing them. So that's how compliance benchmarks are important, or why they're important. Now, sitting underneath all of this, we also have Jamf Protect, and that's giving you that continuous monitoring, behavioral analytics, threat prevention on all your devices, and it's streaming the data telemetry that we're capturing directly over to your SIEM system, which might be Sentinel, Splunk, Google SecOps. There is a variety of choices here. Now, we're sending Apple native signals. It's not generic endpoint noise or fluff. And then finally, to connect all this together, there's a unified set of APIs that connect to the entire Jamf platform, and that connects to the rest of your security stack. So your source system, ticketing system, HR, identity platform, and so on. So takeaway from this is that Jamf is not operating as an island in your environment. It's an integrated part of your technology stack. But maybe you don't have a SIEM, or perhaps you don't have access to it because it's controlled by another team. Or it might just be that having all that rich telemetry is just overwhelming. And if you're presented with a dashboard like this, you're not too sure where you would even start, let alone what to do if an incident was flagged. Well, this is where Beacon by Jamf Threat Labs comes in. This is a brand new service which puts Jamf's own Mac threat researchers to work in your environment. When you have this service, these guys will be actively hunting for threats using your Protect telemetry data. And if they find something, they will deliver a direct notification to you, and they'll give you the remediation guidance that you need to fix it. And this is all coming from a team that does nothing other than think about Mac security day in and day out. So in summary, Blueprints are enforcing the update. Compliance benchmarks are validating that every device has them. Protect is then giving us the telemetry data signals. And then Jamf Beacon is answering the hardest question here, which is, was there already suspicious activity in your network before you even knew that there was a patch available? So if you'd like to know more about how Jamf Beacon can help you, please stop by the Jamf Shorts Theater in the Success Lounge. That's the room downstairs on the ground floor. And if you'd like to know more about Apple telemetry and how it can help you, make sure you catch the session that's at 2 p.m. in the King Vault room. That's on the lower ground level. That session is a cracker. I've seen it. It's awesome. OK. So your devices are configured. They're up-to-date. Your security stack's getting those signals. Your compliance posture says everything's fine. And your dashboard is looking green. But here's a question that's not been answered yet. In fact, this question may not have even been asked. What about AI? You see, right now on those same devices that just came up with all those green check marks, your developers are probably running Claude Code or Codex or Cursor. And your knowledge workers are probably using Cowork or ChatGBT. And maybe you have an engineering team that's using GitHub Copilot. A few people have probably picked up tools you've not even heard of before. They might even be running LLMs locally on their device, maybe one with a big red lobster icon. These tools are already in your fleet. And most of them arrived within the last 12 months. And we all know who is most likely to be running shadow IT tools, don't we? That's right. It's your execs and your VIPs every time, guaranteed. The people who you don't want to be having a data leakage problem with. And yet these are the tools that are probably consuming a lot of your corporate data, sensitive facts about your company. And here's the thing. If the user has activated an MCP server in their AI tool, that's like having an uncontrolled API gateway that's connected directly to your internal systems. Now, that's a compliance gap that your existing security posture doesn't cover. 98% of organizations are reporting unsanctioned AI use on their endpoints. And here within Europe, companies are also having to prepare for the EU AI Act. Now, this is an obligation that applies to the UK as well. And it calls for organizations to document their risk management of AI in your environment. So if you're in a regulated industry like fintech, healthcare, public sector, or you work with organizations in those environments, you need to be working on this right now. Because this comes in very, very soon. So the problem isn't that your users are running these AI tools. We use a lot of these tools ourselves at Jamf. The problem is that no one has a control plane for them. Now, AI vendors have started to ship with enterprise configuration controls for these tools. Things like model restrictions, data access permissions, MCP server governance, command level permissions, allow and deny. And yet, almost all of them are just sitting untouched. Very few companies know that these controls exist for AI tools, let alone have gone to the trouble of configuring them and scoping and deploying them. So AI is usually not being governed in most people's environment, which is a massive risk. Well, that's why today we're announcing a new functionality, Jamf AI Governance. This is your control plane for AI on Mac. This will help you to see the AI tools that are running across your Mac fleet. And you will know what has been sanctioned or approved, and what is ungoverned and uncontrolled. You'll be able to see what's running in your environment right now, and then control it using the management plane that you're already using today, the Jamf platform. So let's take a look at AI Governance. What you're about to see here is a world first public preview of this new functionality, which is going to be launching on June the 30th. You're the first customers anywhere to see this, which means I'm petrified right now if this is going to work or not. So let's have a quick look at the product in the real world. I'm going to invite to the stage my friend Rob Potvin, who's a senior consulting engineer here at Jamf. Thank you. We are on the bleeding edge here, by the way. All the demo god sacrifices have been made. Okay, so first of all, let's start with Jamf Account. Now the reason we're starting Jamf Account, that's of course the launchpad into all the services that you get on the Jamf platform. And the reason we've got it in here is because quite often the AI Governance team is completely separate to the Mac admin team. So this lets them have visibility into this particular piece without you having to let them into Jamf Pro or muck around with those sort of permissions. So let's go into AI Governance, Rob. And the first thing that people usually want to do is see what AI tools are running in their environment. So as this page loads, and you can see we can change the timeframe there, it's giving us an idea of all those tools that we're seeing running. So you can see it is Claude, VS Code, Cursor, Windsurf, all sorts of tools. There's a good chance you wouldn't have known that those things were running. Now Claude code is something we use a lot at Jamf. So let's click on that and go and see what we can see is happening there. So you can see how many people are using that. You can see the usage over time here as well. And you can see what's calling Claude, but also what Claude is calling itself. So you're getting an idea now of the activity that's going in and out of this tool. And you notice down the bottom there in red, it's got potentially risky commands. So these are the things that are probably worrying you, might even keep you up at night, or at least your InfoSec team. Things like, is Claude calling OSA script? Is it calling SCP? Is it calling SSH? These are the things that you probably want to get alerted about. So here's the great thing about what you're seeing here. All this data that's being surfaced here, we've not installed any new agent on your device at all. This is using the Jamf agent that's already on your devices. So nothing else extra is required. And that also means that no other cross-platform tool can do this for you today, because they just don't have the same insights into your devices that Jamf does. OK, so we've done the AI visibility. We see what's running. Let's have a look now at how we can start to govern AI. A common request here would probably be, let's make sure everyone in the team is using the same model version. So we're going to set up Claude. You can see there's other options in there we're adding to all the time. We're using Anthropic for our authentication. That means we're using their infrastructure. That's who builds us for the tokens. And then in here, we're going to specify which model we want the team to use. Now, to be honest, we were going to actually talk about restricting Fable here, but the US government has done that for us already and destroyed our demo. So what we're going to do is we're going to restrict the team to Sonnet and Haiku, because Opus just choose tokens, and we're really cheap with this demo. So we will just choose those. You can see we can also specify default, so we can steer a team towards using one model that might be cheaper to run or give more consistent results as well. We don't want everyone on a different version with hallucinations coming into our work. While we're here, let's also go and add a startup message to the AI tool as well. Now, this is a lot like I'm going to show Rob and I's age here. But back in the day, it was quite common when you were testing things to put a login window banner on your Macs, and that way you would see if your MCX prefs were working or not. We're going to do the same thing here. It's an easy way to see if these settings are working or not. So you can see there's a lot of settings in here. We don't have time to dig into all of that today. The important thing here is we're pulling all of this stuff down from Anthropic live. So when Anthropic make changes to the enterprise controls and their products, it's going to get surfaced here in the Jamf GUI for you. And that means you don't have to go in there and be editing any sort of JSON files, XML files by hand. It's all here in a GUI that explains exactly what these settings do for you. OK, so we've saved this policy. Now we need to deploy this out to our devices. How do we do that? It's going to be the same way we did the software update settings. We're going to use a blueprint to do this. So we're going to use the app switcher to jump across to pro now. This might be where you, as the Jamf admin, is going to get involved in deploying these settings out. The great thing about using a blueprint is, of course, it's going to use DDM to deploy this. It's going to be fast. It's going to be reliable. It's going to be tamper-proof. It's going to hit the device at the lowest level. The user's not going to be able to overwrite these settings. So Rob's in here. He's going to search for Claude, and he's going to find the settings that we just made. So he's going to pick that policy and the version of it, and you'll see the settings in there that matches what he set up before. So we know that's good. He's going to scope that out to our developers. So we've got a smart group already made for that, and he's going to give that a name and hit Deploy, and those settings are now going to head out to the device. Okay, fantastic. So we've done that. We've created the policy. We've deployed it. Let's go and see if that actually worked now. So we'll jump across to one of our endpoints, and let's go and fire up Claude Code as if we're a developer. I'm very impressed with Rob's terminal design here, by the way. I love that. Okay, so we're going to fire up Claude, and you can see that banner message there in the middle, right? Kind of like a login window. Hello, Jamf Nation. So we know those settings have come down, and they're sticking. Let's have a look at what models are available. And we go and ask for the models, and you can see we've got Haiku and Sonnet. Opus hasn't shown up, neither has Fable. So those settings came down, and they worked. Okay, we know that it worked. How do we prove back to our leadership or our change control team that it actually worked? Well, if we go back to AI Governance, we've made it so that you can download a report that shows all the settings that you've got in there. So if we pull that report down, it's going to generate a PDF for us, which Rob will then pull up, and that report is going to show us the AI visibility. So that's great to hand to your leadership. It's also going to dig into the details of the policies we've made, who made them, timestamps, audit logs, all that sort of nice stuff that you can hand over either to your change control team or your auditor. So this is what it looks like to use Jamf to govern AI on your Macs. Great demo. Thanks, Rob. I don't know why I was worried. It worked fine. So that's Jamf AI Governance. It's brand new. We're very excited to show it to you, and as Tim Apple would say, we think you're going to love it. It's coming on June the 30th for Jamf for Mac customers, and if you would like to learn more about this product, make sure you go to the live lounge, which is happening in the Queen and James Waltz, that's down on the lower ground floor at 115.