Jamf Pro
Import the IP addresses of your Jamf Pro managed Macs and mobile devices into Guard as assets.
The Jamf Pro integration imports your Apple device inventory from Jamf Pro into the Praetorian Guard Platform (PGP). Guard reads your managed computers and mobile devices and adds each device's IP address as an asset, with its operating system and version. This guide walks you through creating a Jamf Pro API client and connecting it to Guard.
What the integration does
Each time the integration runs, Guard:
- Signs in to the Jamf Pro API with your API client's credentials.
- Reads your computer inventory and your mobile device inventory.
- Skips devices that have not checked in (computers) or updated their inventory (mobile devices) in the last 30 days.
- Creates an asset for each remaining device's IP address. For a computer, Guard uses the last IP address Jamf Pro recorded for it and falls back to its last reported IPv4 address.
- Records the device's operating system version on the asset. For a computer, Guard also records the operating system name; for a mobile device, it records the device type.
Devices with no IP address in Jamf Pro are skipped. Guard also drops IP addresses it should not scan:
- Loopback, link-local, multicast, and unspecified addresses.
- Addresses in public cloud provider ranges.
- Private addresses, such as
10.0.0.0/8or192.168.0.0/16. - Any address, public or private, that does not answer a single ping within half a second.
To import private and non-responding addresses, contact Praetorian support.
The integration only reads from Jamf Pro. It does not change devices, policies, or settings. Jamf Protect data is not imported.
Prerequisites
- A Jamf Pro instance (Jamf Cloud or on-premises) that Guard can reach over HTTPS.
- A Jamf Pro account that can create API roles and clients.
- Permission to add integrations in Guard.
Step 1: Create an API role and client in Jamf Pro
- In Jamf Pro, go to Settings → API Roles and Clients.
- On the API Roles tab, create a role and give it these privileges:
- Read Computers
- Read Mobile Devices
- On the API Clients tab, create a client, assign it the role from step 2, and enable it.
- Generate a client secret. Copy the Client ID and the Client Secret and store them safely. Jamf Pro shows the secret only once.
Step 2: Connect Jamf Pro in Guard
- In Guard, go to Integrations and open Managed Detection and Response → Jamf Pro.
- Enter:
- Jamf Pro URL: your instance's base URL, for example
https://your-company.jamfcloud.com. It must start withhttps://. - API Client ID: the client ID from step 1.
- API Client Secret: the client secret from step 1.
- Jamf Pro URL: your instance's base URL, for example
- Click Connect.
Before saving, Guard checks the URL, requests an access token with your client credentials, and reads one record from your computer inventory. If any check fails, Guard shows the error and does not save the integration.
Verify the integration
After the first run, go to Assets and search for the IP address of a device that checked in to Jamf Pro recently, has a public IP address outside cloud provider ranges, and answers ping. Its asset should show the device's operating system version.
Troubleshooting
If you need help with this integration, contact support@praetorian.com.