Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Jamf Admin Tips & Tricks: Platform API, CLI & DDM

Jamf
08/08/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


This is the last session before beers, but you are in the right place because it's also the best session. Tips and tricks with the Teletubbies. You're welcome. Just a little bit of addition we throw in for you. I'm gonna welcome Chris, go Rob, and Luke, and Elmo to the stage to take you through all the engineering tips and tricks. And over to you guys. Whoo! Woo! Woo! Woo! Whoo! Woo! Well, thanks very much for hanging in there. This is my favorite session that we ever do at these events. I also know that we are standing between you and a cold beer. So the way to think of this is the longer we wait till we have the beer, the colder it's gonna be. So maybe there's an upside there. I'd like to introduce my team that we're doing with Tips and Tricks with this year. And very multicultural. I would bring a little bit of World Cup competition to this except certain countries didn't make it this year. Luke. And this started as like a bit of an homage to the Apple retro logo. And it somehow turned into Teletubbies. So make of that what you will. The takeaway for me is we're all Apple fanboys. And that's ultimately probably why most of us are in the room. So the way this is gonna work today is first of all, it was asked if I could come out in a Willy Wonka outfit dressed up in the coat and tails with a massive wheel and spin it around. There'd be Oompa Loompas supporting us and it would be completely random what we choose and people would have to come out of the crowd and give a tip or a trick. I spent all the budget on the tokens for the demo this morning. So there's no wheel unfortunately. But what we do have is a virtual wheel. So these guys don't know the order that I'm gonna call on them or what they're gonna have to talk about. I've prepped them with a few ideas. But this session is very off the cuff, very rough. We've not even rehearsed this. But the idea is to give you very raw enthusiasm and passion to see what these guys are excited about. So let's see who's going first. Luke. Okay, Luke. Your topic is going to be, seeing as you did software upgrades earlier and it's the week after WWDC, I would like you to talk to us about how can the audience be best prepared to test OS 27? Okay. Sure. Plug in. You gotta give it a couple of seconds before. Here's the awkward moment when he plugs in. As you can tell, we haven't prepped this. Did anyone come to Luke's software update session, by the way? Yeah? Okay. Have any of you used his upgrade manager app yet? No, not so many hands. Okay. Well, this will be interesting to see how this goes. Cool. Okay. Okay. So, I have a lot of stuff. You also, who wasn't, who was in software update talk earlier? Most of you. Great, wonderful. So, I have a lot of resources open. This is actually really topical because although we didn't talk about it this morning, obviously WWDC was last week, and so all of us on the stage have been watching all the stuff that Apple has been announcing in the last week, and I personally, I know the guys too, have also jumped in and taken advantage of installing all the betas. The device I was using to demo with earlier is actually running iOS 27, which we're told not to do internally, but I did anyway. It worked great. And so, it's a really good time to take a look at how to be able to deploy software updates and enroll in betas and things like that. So, the first thing I would encourage you to do, if you haven't done this before, you're not aware of it, if you go to beta.apple.com, and you are using Apple Business or, if you're using Apple Business or you're using Apple School Manager, you can log into the portal here and it will give you access to all of the current betas. So, if you want to get access to iOS 27, macOS GoldenGate, and so on, you can do that. And given that we talked about this morning from a software update perspective, it has never been more important to be testing, what better place to start than to start testing even further into the future so that you know that when the 27 releases drop that you can jump in completely and ready to go on day zero. Of course, more important than anything else is that you can also not only test compatibility within your organization, but you can test infrastructure and everything like that so that you can be ready on day one. Now, a good tip to do that, and I am in a good position to be able to demo it, will be to use the same instance that I used earlier on. I'm just gonna close it and relaunch it and hope that it works. It did come up there for a second. You're not giving me much faith. There we go. I like demos. This is what happens when you do things off the cuff. So, those of you that joined the session this morning will remember that I used the app to schedule an update for this device and I did let it complete. So, this device was running 15.5. It's now running 26.5.1. I'm trying to show you, but it's taking a couple of seconds for it to load. We'll come back to it in a second. So, what I'm gonna do is create a blueprint to be able to automatically update this device and enroll it into a beta. And not many people are aware that you're able to do this. So, you can use blueprints to automatically have that device adopt a beta program. So, like I said, I have been testing this already. So, I'm gonna open this. I have skipped out some steps here because they're quite laborious and boring and it's not really relevant for you folks. But one of the things that you can do is you can use your instance to be able to generate a token that will automatically enroll your devices. So, I've already generated this token and I'm gonna come in here and I'm gonna find software update. Apparently, software update is the only thing that I can talk about. At least everyone knows how to find this after today. One of the cool features that we have in here is the ability to enroll into betas. So, what I'm gonna do is I'm gonna enable it. I'm gonna say I always want these devices to be enrolled and I'm gonna require it. And I'll paste this token in here. I'll say, hello, Jamf Nation live. I'll hit update, I'll hit save and then I will scope it to that VM. And we'll hope for the best. And if we go back to our VM, let me look. We should find, there we go. So, you can see there the, hello, Jamf Nation live. So now, if we go to software update settings and we refresh, you can see it's already shown up. Mac OS 27 GoldenGate, Appleseed beta. And once it's checked in, you should see that it will start offering me 27.0. It is that easy to be able to push your devices into a beta. The last thing I will show you, just to complete the tip, is that you can also enforce it, just the same way that you can with normal software updates. So, again, I'm gonna use the software update in very much the same way I did this morning with Katie. I'm gonna say, hey, I want to push right now this Mac to 27.0. I'm gonna choose the same device. Just careful with the scope, right? Yeah, don't. Everything here. This is the same instance that's powering the event, so. Hit deploy. And what we should see very shortly is that notification popping in to tell us that we are overdue an update and it will start to download it in the background and automatically push to the user. And there it is. There you go. Cool. Cool. Wow. So go out and do this to your boss's computer. And with that, I'm all tipped out. Who knew that you could do that? Did anyone know that you could do that? There are some hands. Okay. Good tip, bad tip? Hands up. Feels like gladiators now, doesn't it? Good tip. Okay, well done. Well done, Luke. All right, let's see who's next. Anthony Darlow, come on down. Your topic is going to be talking to us about declarative device management. Okie dokie. I'd like to thank Luke for taking up all the bandwidth. By downloading that beta right now on his device. Thank you very much. Oh yeah, I did that actually. Yeah, you did, yeah. You actually pushed that. So when my demos don't work because there's no internet, because the bandwidth's gone. Okay, so DDM Explorer. Who came to the DDM session this morning since we're playing that game? Okay, cool. So we talked about what we could do within the Jamf Blueprints this morning. There is also an app that we have that you can get from the app store called DDM Explorer. This is going to give you the ability to do some of the things we showed you this morning around building your own custom declarations in a way that isn't looking at this. Because this is boring, right? Like for some people, I bet, actually I bet that's really quite exciting for them. Who likes reading documents like that? Yep. See, there's at least one person I knew there was going to be. And you need to learn how to translate that document into this kind of stuff. And like I say, it's potentially a little bit boring or it's a little bit too much for your head to take and it's on a Friday and I just want to melt away and I don't want to have to use the documentation. So DDM Explorer is what I'm showing you now on the screen. It's going to go away and look at that documentation and build out all of the different declarations that you can have within the framework. So for example, as part of what we did this morning, we built a declaration to push an app. And for some people that was like, wow, we didn't know you could do that because we're not doing it in the GUI. Now, I'm not going to lie, I didn't figure out that JSON by looking at the documentation. I came into DDM Explorer. I took out the managed app here. We're going to do, what did we do this morning? It was Outlook, right? So I think the bundle ID is something along the lines of this, but don't quote me on it. So I'm going to build that. As you can see, as I'm building this out, as I'm clicking on the GUI to make it nice, you can see the JSON being built for me on the side there. So I'm going to do an install here. I'm going to do that as required. And I want to assign it a device license, right? So we'll keep it real simple like yesterday. There's my JSON. So if I go over to Jamf Pro, I can go to my blueprint that I started earlier. I can search for a custom declaration. If I could spell, then I probably could. So we do the custom declaration. We get started. A couple of things that we need in here. The first is that payload, but there's also that type that we spoke about as well. If you're in that session, I get that from the top bit. There's a copy button. I grab that. I put that into the type. Boom. And then we get the payload. Add that to there. Push that in. And then obviously once I add that and I scope it like we did this morning, you'd see that then we can push an app with blueprints, with DDM, and we can't do that in the GUI. So I'm not going to actually go push that one right this second because I've got something else I actually want to show you on top of that, right? So this is pulling Apple's documentation. So that GitHub page, this is actually pulling live from that. Now, did anybody see that little event that Apple did last week? That WWD, I don't really know what it is. Did anyone else watch it? There's something about a new OS happening or something, right? And Apple released on their GitHub page all of the new keys and declarations that are going to be available for 27. So if we go into the app, we can actually go and pull that documentation instead of the current documentation. And it takes a while because it goes away and reads the page. It has to parse it within the app. So it will take a second. But what we're going to be able to then see is all these new declarations for 27 and anything that's changed. And we show you that in the app as well. So you can go away and say, actually, we're deploying this today, but there's going to be this change in it. You can see that's now pulled. And if we look down the side, you can see the managed app one, for example, that's got updated next to it. There's something new within this declaration that you can do. Or we've got this content caching one here, for example. So I'm just going to quickly do this one. Let's just get some things done here. Let's disallow caching to be deleted. Who wants a hard drive that's not full? We'll just do these two for now, right? Same difference again. We're going to go away, go to the custom declaration here. Oh, here's one I did earlier. Fantastic. Now notice that this, again, isn't in the GUI because this is 27 stuff, right? This is stuff that doesn't exist today. But you can put a custom declaration, and if you've got a test device like I have on GoldenGate, we can push it to it. So I'm going to go away and do that. Let's go away. I've got a JNL tips and tricks group here for this VM. I'm going to hit save. I'm going to go deploy. Now, one thing I will say is this is that first beta version of 27. I'm also running a VM, and I'm running it on an M1 Mac. It's really struggling. What I found in my testing, because this is why it's good to test, right, is that I'm going to have to actually restart this in order to show you that it pushed down, just so you, you know, VMs are good that way, right? So if we take a second, we'll see that'll happen. And you can see, basically what I'm trying to say here is with DDM Explorer, you can try those custom declarations that we haven't currently got in the GUI without having to read the documentation, and actually what we can do is start testing these new keys in Mac OS 27, like, as of last week, not even just today, right? Roedd hyn yn byw yn y flwyddyn diwethaf. This was live last week. Gallwch fod wedi'i wneud ymlaen pan fyddwch chi'n cael eich dewis ar un o'r beta. Felly mae'n dda iawn. Rydyn ni'n gwybod sut i ddod i 27 fel beta. Rydyn ni'n gwybod sut i gyrraedd rhai o'r pethau newydd hwn. Rydw i eisiau gweld y demo hwn ac yn gwirionedd gwnaeth yr adnoddau ar y deis ein bod ni wedi gyrraedd un o'r adnoddau beta newydd hwnnw ar ôl y flwyddyn diwethaf drwy ddefnyddio Jamf. Felly os ydyn ni'n mynd i'n rheoli deis, byddwn ni'n mynd yno, ac os ydyn ni'n ysgrifennu i lawr, yna dyna ni. Dyna'n ymwneud â'n adnoddau, Cassian. Iawn. Ddwy ffordd dda, ddau ffordd ddau. Oh, llawer o ddeimladau. Gallwn ni ddefnyddio hyn yn yr wythnos diwethaf. Dwi'n gwblhau'n gwybod bod hyn yn rhywbeth y gallwch ei wneud ac roeddwn i'n adeiladu adnoddau gwirionedd ac roeddwn i'n ei wneud yn y ffordd anodd. Felly un o'r adnoddau ar ôl yr adnodd hwn yw roeddwn i'n gwneud un o'r adnoddau API. Tip section, tipseption. Tipseption, yes. Tip within a tip. Roeddwn i'n defnyddio'r API i wneud get o'r blwprint ac roedd hynny'n cymryd y fformat o'r JSON, ond mae hynny'n ddiddorol oherwydd rhaid i mi sefydlu'r API i wneud get pan oeddwn i'n gallu ei wneud ar fy nghyfrif a gweld y JSON. Roeddwn i'n gallu defnyddio'r tip hwn yn yr wythnos diwethaf. Dyma'r cyfeiriad. Iawn, felly gallai Elmo neu Rob yma. Nid ydyn nhw'n gwybod beth fyddai'n mynd i fod. Elmo, byddwn i eisiau i chi siarad am API platfform. Dyna rhywbeth rydyn ni wedi siarad amdano heddiw. Iawn. A oes unrhyw beth y gallwch chi ddod o hyd i hynny? Rwy'n credu. Efallai byddwn i'n gofyn ar Luke hefyd i helpu ar hyn. Rob ddim wedi gwneud unrhyw beth. Iawn, ond byddwn ni'n gobeithio Rob ar ôl. Byddwn ni'n gobeithio Rob ar ôl, felly mae'n iawn. Felly byddwch chi'n mynd i ddod â ffrind, dyna'r hyn rydych chi'n ei ddweud. Byddwn i'n defnyddio Luke fel ysgrifennydd ar y demo. Fel ysgrifennydd ysgrifennydd, dywedwch i mi. Byddwn i efallai... Sut y gallwn ni'i gynhyrchu hyn? Wel, dechreuwch gyda... Pwy yma sy'n defnyddio'r API i ddechrau? Dwi'n gobeithio unrhyw ddangos. Dwi'n gobeithio'r API Jamf, diolch, i fod yn glir. Dydyn ni ddim yn mynd ar unrhyw un, felly... Iawn, dydych chi ddim yn rhaid i chi ddod i mewn i helpu ni neu unrhyw beth. Rydyn ni ddim ond eisiau gwybod. Iawn, dod i mewn. Yr hyn sy'n defnyddio'r API Jamf, yw'r API Glasig? Iawn. Iawn, dim mynediadau, felly efallai ydych chi'n gobeithio neu... Iawn, dwi'n mynd i fynd i fyny. Iawn, dwi'n mynd i fynd i fyny. Yr hyn sy'n defnyddio'r API Glasig yma yw... Iawn. Iawn, dwi'n mynd i fyny. Iawn, a'r API Jamf Pro? Iawn. Felly rydyn ni'n gwybod bod yna ddau API ar hyn o bryd. Dyna'n dda. Yn amlwg, rydyn ni'n gwybod bod llawer o'n cwestiynau yn defnyddio'r API Glasig. Felly mae'n dda i weld bod y staff yn defnyddio'r API Jamf Pro hefyd. Mae rhai yn defnyddio'r API Glasig. Dyna'n dda. Dwi'n gobeithio defnyddio'r APIs. Mae gennym un arall i chi, sy'n dda. Ond dwi'n meddwl, i ddod o hyd i hyn ymlaen... Wel, Luke, rwy'n credu y gallwch chi ddangos rhywbeth ddiddorol ymlaen. I ddod o hyd i hyn yw, rydyn ni'n defnyddio... Rydyn ni wedi clywed AI ychydig mlynedd o ffyrdd heddiw. Rydyn ni'n meddwl ein bod ni'n defnyddio'r AI. Ac rydyn ni'n debyg i ddefnyddio'r AI i helpu gyda pethau fel sgriptio, defnyddio'r APIs. Byddwn i'n ddiogel. Byddwn i'n debyg i ddefnyddio'r AI i helpu i gysylltu'r APIs gyda fi. Mae hynny'n wych, ond os ydyn ni'n defnyddio'r API clasig yn enwedig, neu os ydyn ni'n gwybod llawer o'n sefydliadau cwmni, mae'n golygu bod dyluniadau AI hefyd yn dysgu sut i ddatblygu APIs clasig, yn amlwg. Oherwydd, ar ôl i gyd, mae'r dyluniadau AI wedi'u hyfforddi ar gyfer cynnydd sy'n ymwneud â'r internet. Felly, os ydyn ni'n defnyddio'r APIs clasig, neu os ydyn ni'n ymwneud â'r dyluniadau clasig, mae yna'r mwyaf o ddata ar y API clasig. Ond mae rhywfaint o wasanaethau anhygoel, rwy'n credu, gyda'r API clasig hefyd, o ran, os yw'r dyluniadau AI yn ein helpu i ddefnyddio'r API clasig, ac rydyn ni'n dod â'r credentiaid, mewn gwirionedd, rydyn ni'n deall beth yw'r hyn sy'n ei adeiladu ar gyfer ni. Nid ydw i'n wybodaeth ac yn gwybod beth yw'r API hwnnw'n ei wneud. Nid ydw i'n gwybod, mae'n rhywfaint o risg, o'n i, Luke? Mae'n ddiddorol, oherwydd byddwn i'n dweud, rydw i wedi gwneud JNLau am 5 mlynedd nawr, a byddwn i'n dweud heddiw, rydw i wedi clywed y ffras o'r API yn cael ei rhoi ymlaen mwy na'r hyn rydw i wedi clywed erioed, a'r term AI. I'r rhai ohonoch sydd wedi bod yn fy sesiwn yma, roeddwn i'n rhoi graff ychydig sydd wedi rhoi gysylltiadau amgylcheddol ar gyfer Mozilla, ac roeddwn i'n meddwl ei fod yn barau statig hyd at ychydig mlynedd yn ôl, lle roedd y nifer o amgylcheddolion sy'n cael eu rhoi fel hyn. Nid ydw i'n gwybod am eich holl bobl, ond mae'n cael ei ddod yn ddiddorol i mi i mewn i Jeff, ac rydw i'n siŵr ei fod yn yr un peth yn eich sefydliadau eich hun dros y blynyddoedd diwethaf, mae yna weithio'n dramatig ynglyn â phobl sy'n defnyddio gysylltiadau AI er mwyn gallu hyrwyddo eu gweithgareddau. Pa mor o'ch bobl, ac nid yw hyn i ddod yn ddiddorol, ond pa mor o'ch bobl nad ydych chi'n teimlo'n gyffredinol gyda'r sgrifennu, ond ydych chi'n meddwl y byddwch chi'n gwneud hynny oherwydd mae gennych gysylltiadau sy'n gallu ei wneud i chi. Diolch am eich gwirionedd. Ie, ac mae hyn yn pwynt pwysig sy'n bwysig, fel y dweud Elmo, oherwydd mae'r tŷ hyn yn cael eu hyfforddi ar yr hyn sy'n canolbwyntio'n cyhoeddus ar y gweithle, rydyn ni'n teimlo y byddwn ni, pan fydd unrhyw un o ni'n dod i'r pethau fel Claude, neu y byddwn ni'n dod i'r Codex, Chatty PC, beth bynnag, a dywedwch chi, hei, gysylltiwch i mi sgrifennu i wneud hyn yn GF Pro. Mae'n bob amser yn effeithiol. Mae wedi dod i'r pwynt lle gallwn ei wneud hynny'n hawdd, ond yr hyn rydw i'n ei weld yn anhygoel yw ei fod yn defnyddio'n aml, er nad ydych chi'n ei ddweud yn aml, mae'n defnyddio'r API clasig. Ac mae'n dda, mae'n dal i weithio, mae'n gysylltiad da. Nid i ddangos nad yw'n dda, ond un o'r broblemau gyda hynny, un o'r heriau i chi, yw, i'r rhai ohonoch chi sy'n dod i'r gwrthwyneb, mae'n dda, mae'n democratio'r heriau, mae'n rhoi'r allwedd i chi wneud y peth hwn a gwneud eich gwaith yn gyflym, ond dydych chi ddim yn gwybod beth sy'n cael ei ddod i mewn yno. Ac felly, os oedd un o'r heriau hynny i ddod i'r gwrthwyneb, rydych chi wedi ysgrifennu sgript a byddwch chi'n ysgolio'n gyflym i'ch sefydliad cyhoeddus, mae'r risg yw, os yw pethau'n mynd yn iawn, dydych chi ddim yn gwybod sut i'w gwneud, ac hefyd, oherwydd y ffordd mae'r heriau'n gweithio gyda'r API cyhoeddus, rydych chi wedi rhoi'r rhan o'r gwaith, y sgript, y gallu i wneud unrhyw beth yn eich sefydliad, gallai eich gwaith ddod i'r gwrthwyneb. Mae'n cynrychioli gwahanol... Diolch am ysgrifennu pawb yn y cyhoedd. A dyna oedd y sylwad. Iawn, dylech chi. Dw i'n meddwl y byddwn i'n rhoi segwaid perffaith. Dyma ni. Dyna ni. Mae tip ar ddiwedd yr holl hyn. Y tip yw... Gadewch i ni ddod i hynny. Rydyn ni'n rhaid i ni gael gwasanaethau newydd neu dyluniau newydd os gallwn. Fe wnaethon ni edrych ar y API cyhoeddus, fe wnaethon ni edrych ar y API Jamf Pro, ond Luke, beth allwn ni ei wneud gyda'r API cyhoeddus? Pam y byddwn ni eisiau defnyddio'r API cyhoeddus? Efallai eich bod chi wedi clywed am hyn dros y diwrnod. Mae cyhoeddus cyhoeddus ar gael. Mae'n golygu'r broblem hwn i bawb. Mae'n fwy allweddol na'r unrhyw dyluniau eraill sydd ar gael. Roedd Ant yn dweud ychydig munud yn ôl y gallwch ddefnyddio cyhoeddus cyhoeddus. Gallwch hefyd wneud hynny'n rhagorol, sy'n dda iawn. Mae'r API cyhoeddus yn y lle i'w wneud hynny. Y peth arall yw... Yn amlwg, roeddwn i'n mynd i'r amgylchedd a'r heriau sydd yno. Yn wir iawn, mae'r API cyhoeddus yn cael ei ddefnyddio ar lefel cyhoeddus GIAF. cyhoeddus cyhoeddus GIAF. Unwaith i chi alluogi cyhoeddus cyhoeddus GIAF, mae hwn yn un o'r ffeaturau sy'n cael eich cymryd gysylltiad â chi. Felly, gallwch chi cael cymryd gwasanaeth gwahanol ar gyfer cymryd cymryd cymryd cymryd cymryd gysylltiad â'r API, fel cymryd cymryd cymryd cymryd API yn eich sefydliad. Felly, efallai eich bod chi Mae'r API hwn yn gallu ysgrifennu o'r grwpiau hyn. Mae'r API hwn yn gallu ysgrifennu o'r grwpiau hyn ar gyfer ein cymryd cyhoeddus. ar gyfer ein cymryd cyhoeddus. Felly, mae gennych gyhoeddus cyhoeddus ar hynny. Felly, mae'n bwysig iawn. Felly, a allwn ni ei ddefnyddio? Dewch i'w ddangos yn gyflym. Dewch i'w ddefnyddio. Felly, dyma... Yn ogystal, mae Ant wedi dangos hyn, mae'r cysylltiadau cynllunio, mae'n newydd. Fe wnaeth hi'r wythnos diwethaf. Mae'n hawdd iawn i ni gallu ei ddefnyddio trwy'r API'r platform. trwy'r API'r platform. Rwy'n gobeithio nad ydych chi yn codwyr, ond os ydych chi'n mynd i wefan Apple ac ydych chi'n ysgrifennu i'r dŵr, mae'n debyg i chi beth o wybodaeth mae angen i chi gallu ei ddefnyddio i'w debygau. Beth rydw i'n mynd i'w wneud mynd ymlaen i'r dŵr hwn. Almo a fi yn gweithio ar dŵr ein hun ar hyn o bryd, ac rydyn ni'n chwarae gyda'r API'r platfform, felly rydyn ni'n cael hyn wedi'i sefydlu. Mae'n effeithiol dwy fathau. Unwaith eto, i'r rhai ohonoch chi nad ydych chi'n cogwyr, byddwn ni'n gwneud hyn yn hawdd, ond yn effeithiol, unwaith eich bod chi wedi cael y wybodaeth y byddwch chi'n ei wneud o'r ddewis jynt, sy'n cynnwys ddewis unigol sy'n eich rhwngi i'ch hun. Mae angen i chi hefyd ddatganiad token. Gallwch gael gwasanaethau super-granular ar gyfer y API'r platfform o ran yr hyn y gall a ddim ei wneud. Felly, yn ôl, pan ydym yn siarad am y thretau o ddefnyddio'r API'r blaen, mae hyn hefyd yn cael rai gair gyrrwng i'w helpu. Ond ie, mae gennym token, felly dyma'r cynllun cyntaf yma. Luke, rydych chi'n mynd i'w cofio ac ysgrifennu ymlaen yma. Unwaith eto, dydych chi ddim yn gorfod cymaint am yr tŵl rydyn ni'n ei ddefnyddio neu'r hyn rydyn ni'n ei wneud yma. Y cynllun yw ein bod ni'n cyfrannu y ffyrdd o JSON, sy'n bennaeth yr hyn rydych chi wedi'i ddangos i ni iawn yn ôl yw sut y gallwn ei ddefnyddio Yr hyn sy'n digwydd yma. Rwy'n gwybod eich bod chi oherwydd mae'r text yn anhygoel a ffysgol, yn enwedig i'r rhai sy'n ôl i chi. Ond yn effeithiol, yr hyn rydych chi'n edrych ar yw ein bod i gael y peth yr oedd Ant yn dangos yn yr un peth ond rydyn ni'n ei wneud yn rhagorol. Rydyn ni'n gysylltu Send a'r hyn rydyn ni'n ei wneud yw creu cysylltiad o gyllideb ar gyfer MacOS GoldenGate fel y gallwn ei ddefnyddio i rai o'n 27 debygau i'w hystyried. Iawn. Ac os ydyn ni'n mynd yn ôl i... Ydw i wedi cysylltu? Yn enwedig Elmo. Yn enwedig Elmo. Rydyn ni'n gadael... Dyma'r peth hyfryd am sut mae cysylltu'n haws gyda'r SSO Jamf Account. Gadewch i ni weld... Hei! Dyma'r peth. Felly dyma'r hyn rydyn ni wedi'i greu yn rhagorol gyda'r API Platform. Rydyn ni'n cael bywyd JSON yno. Rydyn ni'n cael hynny o safle ddatblygu Apple. Rydyn ni'n defnyddio ffyrdd i greu hyn yn rhagorol ac dyma'r cynnwys. Felly, pa mor o bobl sy'n defnyddio'r API Platform heddiw? Pa mor o bobl sy'n ddiddorol o'r API Platform heddiw? Iawn. Iawn. Dw i'n mynd i ddefnyddio hyn fel sylwad o ddewis dda. Dewis ddewis. Roedd yna ddewis ddewis. Nid ydw i'n gallu mynd ymlaen. Dw i ddim yn mynd ymlaen. Felly dwi ddim yn mynd ymlaen. Yn ystod, dywedwch eich bod yn ffotograff o Rob yn ei ddewis. Iawn, Rob. Fy ffotograff hysbwyr. Felly, Rob, dw i eisiau i chi siarad am rai o'r mynyddau sy'n canol gan Jamf Concepts. Felly, dwi'n cael llawer. Ond, un sy'n eithaf, mae'n rhaid i ni edrych arno, ac mae'n mynd ymlaen ar y platform API, oherwydd roedd hynny'n thema rydw i'n gobeithio ei gael, yw Jamf CLI. Pobl yma sydd wedi clywed am hyn? Pobl yma sy'n ei ddefnyddio? Iawn. Nawr, bydd e'n mynd i fynd i'r dŵr. Yn ystod, mae'n ymddangos fel dros 1,300 gwaith gwahanol. Ac rydyn ni'n mynd i ddangos ychydig. Mae'r mwyafan hon yn mynd i fod yn rhywbeth fel hyn. Felly, yn gyntaf, rydw i wedi sefydlu hyn. Rydw i'n defnyddio'r platform API, ac allwn i ddewis edrych ar sut mae'n sefydlu. Mae'n hollbwysig bod eich cyfrifiadau ar gyfer defnyddio'r API gyda Jamf CLI ddim yn unrhyw o'r sgriptau, unrhyw o'r llogau. Mae'n cael eu gadael, yn ffodus. Iawn, iawn, iawn, yn bwysig. Felly, beth mae'r Jamf CLI yn ei wneud? Diolch am fynd yn ôl a'n ffwrdd. Wel, gadewch i ni fynd ymlaen. Yn gyntaf, gadewch i ni fynd ymlaen i weld beth y gallwch chi roi ar gyfer Jamf CLI Pro. Gydag un cyffredin cyffredinol, gallwch chi cael cymhwyster cyflawn o'r cyfrifiad Jamf Pro. Nawr eto, rydw i'n defnyddio'r platform API, felly allwn i ddewis newid Pro i gael cymhwyster cyflawn. Ond dyma cymhwyster o'r peth i ddarparu hynny. Mae'n sefydliad platform Jamf CLI, a bydd e'n gofyn i chi mynd trwy'r cyfrifadau platform â'ch cyfrifiadau ac ydych chi'n bwysig i fynd. Rydw i eisiau cael rhan o'r cyfrifiadau i'w achosi. Felly, yn y cyfan hon, rydw i'n mynd i edrych a mynd i gofyn am yr holl cyfrifiadau a gwneud gwirionedd dros y cyfrifiadau. Cymhwyster cyflawn. Rydw i'n cael llythyr o'r cyfrifiadau i'r cyfrifiadau a'r cyfrifiadau sylfaenol. Ond rydw i eisiau gwneud rhywbeth neu dim ond cael rhestr o'r cyfrifiadau sydd ddim wedi'u cyfrifio yn 30 dydd. Unwaith eto, cymhwyster mawr yma ac rydw i'n gallu dod yn ôl gyda'r 54 cyfrifiadau sydd ddim wedi'u cyfrifio yn mwy na 30 dydd. Felly, rydw i'n meddwl bod gennym broblem. Felly, mwy am y cyfrifiadau hynny, yn wir, mae yna, yma, rydyn ni'n cael yr holl gyfrifiadau yn JSON ac rydyn ni'n gobeithio y gysylltiadau hyfforddi ac rydyn ni'n cyfrifio o'r ôl i'r amser 30 dydd a phosib. Yn ddiweddarach, mae'n eisiau iawn gwneud rhywbeth fel hynny, But we're just trying to get that information. ond rydyn ni'n ceisio cael hynny'n ffodus. Then we're saving that information to a file. So go here. It's going to take all those computers and add it into a devices.txt. I could then go on even further. And with the devices.txt, create a static group within Jamf Pro. Moving on, you can go and say, OK, well, guess what? Jamf CLI supports MDM commands. So I can go from there and just say, let's redeploy the framework to that list, to that group. Key point, hence, at the very end, you'll see dash dash dry run. As much as I like to test in production, not now. So dry run is going to be a dry run. But it's going to go through. And it's going to send the MDM redeploy framework command to all those devices that haven't checked in with 30 days. It is a crazy tool. All the output comes in JSON. So you can leverage this for data, for dashboards, you name it. So it would redeploy the framework for all of these different computers here. The real action is replacing the dash dash dry run with a dash dash yes. So a lot of different options here. In this case, a lot of people might have configuration profiles within Jamf Pro. And you want to test that configuration profile as maybe a blueprint. Well, the cool thing is, with Jamf CLI, I can list out all the macOS classic profiles here. And in here, I have a restrictions. I can go here and say, let's import that restriction. Now, if I just import the profile restrictions, who here remembers config profiles sometimes have keys? You check one restriction. In this case, I've checked one restriction, which is going to be no airdrop. But since I checked it in that one area, there's going to be a ton of other keys, right? Because config profiles get kind of messy, right? So they thought of that. So within Jamf CLI, there's an actual little command here called strip defaults. So it's going to import the blueprints, import profile restrictions to blueprints. But it's going to strip out all the defaults and try to leave what it can the best. Again, this is just a good test to see. As you can see here, it's removing no airdrop to center, remove payload app store. Maybe it's not the best test, but again, it's a test. Now, what it actually does is it's taken the restrictions payload. And where's my browser? And if I go to Jamf Pro, and as Elmo did say, logging in is a lot easier with Jamf account. The hamster is spinning. If I go down to blueprints, they're on the side. One moment, please. My instance was a bit faster. Oh, it's busy pulling down that update that Luke scheduled. Luke, can I have my bandwidth back? Everyone clap when blueprints loads. There we go. No, it's not blueprints yet. Don't clap. I broke it. No. OK, there we go. There's the restrictions payload. So this is a good way to take your classic playloads, import them. I think in this example, it's probably not the best due to some of the things. It did bring in the restriction I wanted, but it did not remove the disk burning. But again, you can get that test of a config profile, move it into Blueprint, and see what it looks like. Again, very powerful. So this is a great way for someone who's got a lot of legacy config profiles now to be able to make that transition to Blueprints. Is that right? Yeah. And Jamf CLI can do a lot of things. It can be an AI bridge. So if I wanted to, I could just go and say, hey, give me a list of all the different Mac OS versions that I have in my inventory, comes out in JSON. OK, Claude, make me a script that can use something with that JSON. And it's just getting JSON, so I can get a little terminal thing here. And I got now a list really quick out of it. You can use that as a pocket backup. You can also diff your backups. So using Jamf Pro CLI Pro backup output, it's going to create a folder called My Jamf and just output everything, config profiles, scripts, you name it. If it has access to it, it's going to output. So if it read only, it's just going to pull it all down and put it in a folder for you. It's very, very powerful. At one point, just because I could, I decided to just use it as a data source for JSON, pipe it into Python, and make a really geeky terminal dashboard that gives you information of what's in your fleet. So you can just run it any time. If you really don't like this theme, turns out we can actually change it to Dracula, right? Next page, previous page, so forth. Anyway, Jamf CLI, very, very powerful. Please have a look. And who, yeah, that was a good tip, Martin. I unplugged early, I'm sorry. And who was it that, this is, who's going to be up next, by the way, who was it that wrote that Jamf CLI tool? A multitude of different Jamfs. Keaton, Neil Martin, it's a whole Jamf effort. I think initially it was Keaton Somova. Some of those, so some of those guys are here today, right? Yeah, yeah, Neil Martin's here today, too. He did a ton of efforts. I had actually a pull request, or a request, actually, and he was like, yeah, that's a great idea, and I think in two days it was added. So please check out the site that they had. So there's the GitHub, the concepts page, and then from the concepts page it takes you to their site where it's a whole bunch of great documentation. Excellent. All right, we're gonna cycle back to Ant now. This is when he was playing for Spain in his youth years. I would like you to talk about Platform SSO. Okey-dokey, then. So who's using Platform SSO? Put your hands up. Not as many as I thought. Keep your hands up if you are using Entra with Platform SSO. Somehow people put their hands up saying they're using Entra with Platform SSO, but not using Platform SSO. I don't know how that would work, but hey, cool. Right, I've got a tip for you if you are in that situation. It's a little bit of one of those, hey, this just annoys me, it's also kind of useful kind of tips, right? So when you are creating local accounts with Platform SSO, if you were to read the documentation from Microsoft or from Jamf, you get told to put these details in there. And when you put these details in there, especially this account name, that preferred username, you get user accounts that are really annoying that look like this. Can you see my home folder here is j.porterjamfnation.school because it's taken my full preferred username, my full UPN, taken that out of it and created me a user account on that. I hate that. Like personally, it just really annoys me. It should be just j.porter, right? It really annoys me. So what I found whilst I was looking at Apple documentation, oh, there you go, there's a bigger one that you can see. When I was looking at Apple documentation, because Luke, I do read documentation sometimes, I found- One of the 5% of people in this room. And it is only sometimes. I found this little key that Apple gave us to be able to use for the account name that goes away and takes the short name or shortens this down for Entra deployments. If you're using Okta, they kind of already do it for you. So this is very much an Entra tip, but it is available in the Platform Deployment Guide. And I've just been putting the display name in the full name rather than just name because I know some people want the display name. I'm Anthony Darlow. I much prefer Ant most of the time. So my display name might be Ant rather than Anthony. If I use name, my account becomes Anthony Darlow and I want it to be Ant Darlow. So you can play around with that one a little bit as well. When you do that, you get exactly what I wanted, which is the j.porter, the thing that makes me not then go crazy. It's more than just important there though, because if you're actually using Platform API, no, that's not what I'm talking about. If we're using Platform SSO, that's the one I'm talking about, then, and you're using it from setup, so simplified setup, you want to be able to create that user account, that first user account on there with the right user name if you're using user-based MDM because it's the first person on there and it needs to match your user that you have in Jamf Pro. So this is a real nice tip for that. Here's another tip. Do carry on always reading the documentation because since Entra has supported Platform SSO at setup, they have actually changed their documentation to include this key now that I found out about five seconds before coming on stage. So I will say that I've seen that now, okay, because I do go back and read documentation sometimes. So that's tip number one, but there's kind of like a second one here that I want to talk about because if you are using Platform SSO or you're looking to test this, then we have an app that's on Jamf Concept as well that was designed and made by one of our colleagues on our team called PSSO Utility, and it's one of those real nice ones from an admin point of view that just gives you a bit of an overview that you don't have to go digging into sort of like basically terminal. So if you are using Platform SSO, there is a command that goes away and pulls down all of your SSO, PSSO configuration stuff, and you can look through this and check whether you've used that special key that I've talked about, whether it's even active, whether it's registered and all that, but who wants to go and pass through all this, right? What I'd much rather have is a nice app that I can open and it shows me in a nice GUI way. So from a troubleshooting point of view, when you're pushing this config down, you can make sure and verify that it's getting on the device the way that you want it to. If you still want to see the raw data, you can, but again, that's going to be that lady that's at the back there that likes reading the documentation that wants to read the JSON instead of the nice app there. I can also see what's happening with more of the configuration and what MDM profiles are there just from this GUI app. So it's great from an admin point of view for testing, but actually, if you've got somebody as a remote support and they're having problems with their platform SSO configuration, you could send this and get them to download it through self-service, for example. They could then open this up and say, hey, this is what it's being reported on the device. So it kind of could perhaps be used as a bit of a support tool as well if you're doing remote support. Cool. Is that it? Yeah. Wow. I can't believe how fast you talk through all of that. So I hope people caught it. You will get some of this stuff in a few days. We'll send it out as well. All right, Elmo. I don't think I can talk as fast as Ant, but I'll just show less. Go for it. Yeah, I was thinking about this. AI has been talked about all day from the start to now the end. And I was thinking, I love AI. And I was thinking, hey, how many people in the audience use Jamf's AI Assistant? Then I got sidetracked because then I got thinking of Boris Johnson memes. Use AI, absolutely. Use JTPT. Do you know JTPT? I love JTPT. I love it. I had never seen this before, by the way. He showed this to me and I thought he had made this using AI. This is legit. This actually happened. This is a real video. But the point was, then I got thinking, I was, yeah, how many of us are using AI again in work for Jamf specific things? Probably a lot of us. Why don't we actually just use the AI tool that is already in Jamf that we all have access to? Because this is trained on Jamf data. So it knows Jamf best, better than ChatGPT, even if you're like Boris and you love ChatGPT. So let's see what kind of information, I mean, maybe I'm brand new to this. We've seen it used a few times today already. So I know that you guys know where this lives and how to access it, but are you actually using it? Well, let's just start with something really simple. Hey, what is AI system? What can it help me with? It's gonna think about this question for a second and then it's gonna give us a nice response. But the idea is, if you're new to Jamf, you can use this to just ask kind of exploratory questions around different Jamf tools or features. And if you're an expert in Jamf, I'll show you in a second, you can do some more deep divey things in terms of getting actual like hardcore data on how to use things like platform APIs, for example. But okay, let's look through this real quick. Man, it gives a lot of things. I mean, what can it help me with? It shows me the explain tools, investigative tools, privacy, it's still going. Is there anything specific you'd like to try with AI system today? Let's see, I've got, let's compare the platform API to, well, I said to these as well. Clearly, I can't make a coherent sentence anymore today. But yeah, I wanna compare the Jamf Pro API to the classic API or compare the Jamf Pro API to the AI system tools above. No, you know, it gives me some nice options already. Even if my sentence didn't really make sense, it's giving me some nice options. So let's just say, compare the platform API to the classic API. And let's see what it gives back. So if you're trying to just, yeah, figure out what documentation is around, what's the best way to proceed, rather than look through our Learn documentation, which is great. This just gives you a much more coherent response that you can actually do something with. So I would say, if you haven't given Jamf's AI system a go, definitely do so, because I find it to be a bit more reliable than other AI tools that are trained on who knows what. And they can hallucinate a bit more. So here we get actually a pretty nice Jamf Pro API. I actually said only the classic, but even threw in the Jamf Pro API even better. So I've got a side-by-side of all three of them now, So I've got a side-by-side. and I could go and compare this nice and visual, rather than read through three different documents on what is the classic API, what is the Jamf Pro API, what is the platform API. And then that would take a whole day of perhaps reading. I get a really nice, quick way of looking into this. It even gives me some nice, hey, watch this space. I will. So yeah, really cool. If you don't want beers, I'll stick around later, and we can just keep doing AI prompts all afternoon. So yeah, that's just a quick example again. Actually, it might be more fun if you do the AI prompts with more beer. Well, maybe we can do it that way, yeah. All right, thanks, Elmo. Wow. Notice that we're not rotating the wheel anymore. I just became the wheel. That's it. So, to bring us home, Rob's got something very, very cool to show us. This is probably the one I'm the most excited about. Rob's going to talk to us about a couple more Jamf concepts. Yeah, I'm a big concepts fan, so... And speaking of AI, always use the Jamf AI, but then at the same time, there's other cool things like MCP. Who's heard of, instead of JGTP, who's heard of MCP? Okay, well, Jamf has released an MCP server. It's in beta, it's being built out, but there's some really cool things you can do with it. First off, you can tie it in with something like Cloud Code, and you can just ask it, like, hey, what tools do I have available with the Jamf MCP server? Platform API is not available yet, that's in development, but it does have access to Security Cloud, to Jamf Pro, and Protect, so it can pull all of that information together for your needs. So, as you can see, it's reading the guide skill right now, so it's figuring out what is available, and then it's going to just list out that three products are configured, and these are the tools that we can actually use. So, it's pretty, pretty cool. Now, you know, where do you want to start, security alerts, so forth? Well, since it has access to everything, I wanted to have it build a dashboard for us. I've already kind of created already a prompt for us to use for time saving, because I had no idea this was going to happen. So, I'm just going to let it chug away in the background, building this out for us, and while that's going on just an example of MCP, there's a lot more we have, but we're running out of time. There's a last thing here. Who's here heard of Jamf Extender? This is the coolest tip. Everyone, put your hands up after, because you need to install this. Now, notice I'm using Safari, and yet, we have a plugin for it. So, for, you know, Youresco, thank you so much for this, because it works Safari, Chrome, you name it, even this weird browser called Edge, it's there, it works. What does this do? Well, notice I have a really nice blue banner on the top of my Jamf Pro. Who here has more than one Jamf Pro server? Okay, you need to start talking to us more. You can have an actual, like, sandbox, right? And that's where you test. But knowing the difference between the two, sometimes the domain name you don't really listen to. With Extender, it's plugged into your Jamf Pro server. It is literally a one-click setup, because it leverages the API. It's read-only, nothing is, it's not really doing anything other than interface updates. One thing here, it gives you health, lets you know what's going on here, what's API, UI, the works. I added a little tag here. Very easy to set up here. I just click on Extender, and then I have some preferences here. Let's say the nav bar should match my shirt. So now I got it there. I can get rid of the instance label here. I can put in here Canada Rocks. I have to spell it right, though. Hit Apply, it's there. You know, you can change the colors. A clear Canada Rocks is more of a joke, or Canada's good at football. It's not. Anyway, there's even things like MUT. So you can add, I'm not sure if you know what MUT is, but you can import computers, mobile devices, computer groups from a CSV file built right in. This is just one little aspect of it. Notice here, it comes up with just letting you know what's going on with your mobile apps and books and licensing. If I go down to Computers and Smart Groups, it's going to prefetch and give you a Smart Group listing. So it's going to go through and figure out which Smart Groups are kind of like that meta information of each Smart Group. So we're going to get a count of what computers are in that right here. Because usually you have to click in, right? Yeah, usually you will never get this. You'll also come to the point where they're in All Managed Client, six are targeted. So six policies or blueprints or Mac apps are targeting the All Managed Clients. How much time would that save you? It's crazy. That's just one thing. Configuration Profiles. I can see the payloads without clicking in. I might have two different payloads. So let's compare some profiles. What's the difference between these two? Compare. All these little things. I find new little features every day. I went to, what is it called? Mac apps? No, what is it? Here, Licensed Software. There's an Application Usage Report. Before you needed to run an API script to pull this report out. Now I can pull it out from here. I can go here, run report on Advanced Computer Search and get application usage statistics from that saved computer list. When dealing with API, as we've been all talking about it, when I go down to my system here and I dive into API roles and clients who learn me how to spoke, click on New, I have a full privilege picker for managing. Because before it was really this kind of list. Now down below, I have the ability to get full CRUD permissions on exactly what I want to see when it comes to selecting API credential permissions. So Extender is crazy cool. So highly recommended to it. And that's just a tip of the iceberg. So if you have a chance, again, concepts.jamf.com. And then when we head into here, you can see it. Getting started will take you to the GitHub page where you can download for Chrome, Safari, and highly recommended. It's free. And it's free, yes. Cool tip, cool tip. Yeah? Let's see how... Oh, our MCP server's done. Let's open it in Safari. And we're checking our fleet dashboard. So with the MCP server, I pulled some data out. I love dashboards. Who doesn't love dashboards? They're fun. And here's all the data. Oh, as they break down, did you give me the security? I forgot to add that, though. We do have some issues, 100 security alerts. I think we need to activate this. Anyway, thanks very much. Excellent, thanks, Rob. So it was fast and furious today, which is the idea. We're not going to explain everything in detail. It's to get you started on some of the things you may not know about. Expect us to send out a pack in the coming days that will have more details on all of this. And as there's a free takeaway, here's Luke Allen's football picture from your days playing for Wales, I guess. It's a large bulge in the crotch. Yeah, wow. That's AI for you, mate. Can do anything. So thank you very much for coming today. We very much do appreciate your support in being here. And here's the best thing of all. There's now beer downstairs. Cheers. Cheers.

TL;DR

  • Mac admins can use Apple Business Manager and Jamf Blueprints to automatically enroll devices into macOS 27 Golden Gate and iOS 27 beta programs today, enabling day-zero readiness before public release.
  • The Jamf Platform API provides super-granular, scoped access tied to Jamf Account SSO — a safer alternative to the Classic API that AI tools tend to default to when generating automation scripts.
  • Jamf CLI offers over 1,200 commands for the full Jamf platform, covering stale device remediation, MDM framework redeployment, Blueprint migration from Classic profiles, and AI-assisted scripting workflows.
  • Jamf Extender is a free browser extension that significantly enhances the Jamf Pro web interface with instance colour-coding, Smart Group counts, profile comparison, and application usage reporting — no server-side changes required.
  • The Jamf MCP Server (beta) integrates with tools like Claude Code to enable natural language queries across Jamf Pro, Jamf Protect, and Jamf Security Cloud, including generating live fleet dashboards on demand.

Beta Testing macOS 27 and iOS 27 With Jamf Blueprints

Recorded in the week following WWDC, this session opens with a practical walkthrough of how Mac admins can immediately begin testing macOS 27 Golden Gate and iOS 27 betas within their organisations. Using Apple Business Manager or Apple School Manager, admins can log into beta.apple.com to access current beta seeds and generate enrollment tokens. The presenter demonstrates using Jamf Blueprints to automatically enroll devices into a beta program and enforce beta software updates — a capability many admins are unaware of. The emphasis is on day-zero readiness: testing compatibility, infrastructure, and workflows before the public release so organisations can move confidently when macOS 27 ships. The session also covers DDM Explorer, a tool for building custom Declarative Device Management declarations without needing to read through Apple's full documentation, and demonstrates pulling live macOS 27 DDM declarations directly from Apple's GitHub repository.

Platform API: Safer Automation and Scoped Access

A significant portion of the session addresses the evolution of Jamf's API landscape — from the Classic API to the Jamf Pro API to the newer Platform API. A key concern raised is that AI-generated scripts tend to default to the Classic API because it is the most widely documented, but this carries risk: Classic API credentials typically carry broad permissions. The Platform API addresses this by enabling super-granular, scoped access tied to Jamf Account SSO, so automation scripts can be locked down to touch only what they need. A live demo shows creating a Platform API token and using it to generate a DDM declaration for macOS Golden Gate. The Jamf CLI is also introduced — a command-line tool with over 1,200 commands spanning the full Jamf platform — demonstrated for tasks like finding stale devices, redeploying the MDM framework, importing Classic config profiles into Blueprints, and serving as an AI bridge for scripting workflows.

Platform SSO, Jamf AI Assistant, MCP Server, and Jamf Extender

The final third of the session covers four distinct tools. Platform SSO receives a practical tip around generating cleaner local account names when integrating with Microsoft Entra ID, alongside a PSSO Utility that provides a GUI for troubleshooting Platform SSO issues without needing to dig into logs. The Jamf AI Assistant is demonstrated as a Jamf-trained conversational tool for answering fleet management questions with context-aware answers. The Jamf MCP Server — currently in beta — is shown integrated with Claude Code, allowing admins to query Jamf Security Cloud, Jamf Pro, and Jamf Protect data and even generate a live fleet dashboard through natural language prompts. Finally, Jamf Extender, a free browser extension available for Safari, Chrome, and Edge, is highlighted as a standout tip: it adds colour-coded instance banners, Smart Group prefetching with member counts, configuration profile payload previews, profile comparison, application usage reports, and a full API privilege picker — all without modifying any Jamf Pro data.

Chapters

0:00 - Introduction & Team Welcome
2:34 - Testing macOS 27 & iOS 27 Betas
6:16 - Beta Enrollment With Jamf Blueprints
9:30 - DDM Explorer & Custom Declarations
12:43 - Pulling Live Declarations From Apple GitHub
16:17 - Classic API vs. Pro API vs. Platform API
18:04 - AI Scripts & Classic API Risk
22:26 - Platform API Scoped Access Demo
26:34 - Jamf CLI: 1,200+ Commands
28:36 - Stale Devices & MDM Framework Redeployment
33:19 - Jamf CLI as AI Bridge & Backup Tool
35:22 - Platform SSO & Entra ID Account Names
40:12 - Jamf AI Assistant Demo
44:52 - Jamf MCP Server With Claude Code
46:32 - Jamf Extender: Supercharging Jamf Pro UI
51:36 - Wrap-Up

Key Quotes

2:14 "This session is very off the cuff, very rough. We've not even rehearsed this. But the idea is to give you very raw enthusiasm and passion to see what these guys are excited about."
4:07 "The device I was using to demo with earlier is actually running iOS 27, which we're told not to do internally, but I did anyway. It worked great."
5:00 "It has never been more important to be testing — what better place to start than to start testing even further into the future so that you know that when the 27 releases drop that you can jump in completely and ready to go on day zero."
45:20 "Jamf has released an MCP server. It's in beta, it's being built out, but there's some really cool things you can do with it."
46:29 "Who's here heard of Jamf Extender? This is the coolest tip. Everyone, put your hands up after, because you need to install this."
47:16 "With Extender, it's plugged into your Jamf Pro server. It is literally a one-click setup, because it leverages the API. It's read-only, nothing is, it's not really doing anything other than interface updates."
51:36 "It was fast and furious today, which is the idea. We're not going to explain everything in detail. It's to get you started on some of the things you may not know about."

FAQ

How can I start testing macOS 27 Golden Gate betas in my organisation right now?

Log into beta.apple.com using your Apple Business Manager or Apple School Manager credentials to access current beta seeds. Generate an enrollment token from your ABM/ASM instance and use Jamf Blueprints to automatically enroll target devices into the beta program and enforce beta software updates. This approach lets you test app compatibility, infrastructure readiness, and MDM workflows well before the public release.

Why is the Platform API safer than the Classic API for automation scripts?

The Classic API is the most widely documented Jamf API, so AI tools and older scripts tend to default to it — but Classic API credentials typically carry broad permissions across the entire Jamf environment. The Platform API allows you to create tokens with super-granular, scoped permissions tied to Jamf Account SSO, meaning a script can be restricted to only the specific resources it needs to touch. This significantly reduces risk if credentials are ever exposed or misused.

What is Jamf Extender and where can I get it?

Jamf Extender is a free browser extension available for Safari, Chrome, and Edge that enhances the Jamf Pro web interface without making any server-side changes. It adds colour-coded banners to distinguish between multiple Jamf Pro instances, prefetches Smart Group member counts and targeting statistics, enables configuration profile payload previews and side-by-side comparisons, surfaces application usage reports, and provides a full API privilege picker. It is available via concepts.jamf.com, which links to the GitHub download page.


Categories:
  • » Cybersecurity » Endpoint Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Endpoint Management
  • AI & Machine Learning
  • Identity & Access
  • Technical Deep Dive
  • Demo
  • Best Practices
  • Jamf Platform API
  • Jamf CLI
  • Declarative Device Management
  • DDM
  • macOS 27 Golden Gate beta testing
  • iOS 27 beta enrollment
  • Jamf Blueprints
  • Jamf AI Assistant
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Jamf Admin Tips & Tricks: Platform API, CLI & DDM

              XStreaminars (watch here)

              • Aug
                27

                Becoming Agent Ready with Cyera: Essential Strategies and Insights

                08/27/202601:00 PM ET
                More events

                Industry Events (Sponsor Hosted)

                • Aug
                  13

                  Harnessing AI for Secure Innovation in the Enterprise with Netskope & Omada

                  08/13/202612:00 PM ET
                  More events

                  Upcoming Webinar Calendar

                  • 08/13/2026
                    12:00 PM
                    08/13/2026
                    Harnessing AI for Secure Innovation in the Enterprise with Netskope & Omada
                    https://www.truthinit.com/index.php/channel/2065/harnessing-ai-for-secure-innovation-in-the-enterprise-with-netskope-omada/
                  • 08/27/2026
                    01:00 PM
                    08/27/2026
                    Becoming Agent Ready with Cyera: Essential Strategies and Insights
                    https://www.truthinit.com/index.php/channel/2081/becoming-agent-ready-with-cyera-essential-strategies-and-insights/
                  • 09/02/2026
                    12:00 PM
                    09/02/2026
                    Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                    https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                  • 09/30/2026
                    04:00 AM
                    09/30/2026
                    AI Command Center: Optimizing Visibility and Control in Your Operations
                    https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                  • 11/19/2026
                    01:00 PM
                    11/19/2026
                    360View: Govern, Secure & Recover Your Microsoft 365 Environment
                    https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                  Truth in IT
                  • Sponsor
                  • About Us
                  • Terms of Service
                  • Privacy Policy
                  • Contact Us
                  • Preference Management
                  Desktop version
                  Standard version