Jamf Pro

Import the IP addresses of your Jamf Pro managed Macs and mobile devices into Guard as assets.

The Jamf Pro integration imports your Apple device inventory from Jamf Pro into the Praetorian Guard Platform (PGP). Guard reads your managed computers and mobile devices and adds each device's IP address as an asset, with its operating system and version. This guide walks you through creating a Jamf Pro API client and connecting it to Guard.

What the integration does

Each time the integration runs, Guard:

  1. Signs in to the Jamf Pro API with your API client's credentials.
  2. Reads your computer inventory and your mobile device inventory.
  3. Skips devices that have not checked in (computers) or updated their inventory (mobile devices) in the last 30 days.
  4. Creates an asset for each remaining device's IP address. For a computer, Guard uses the last IP address Jamf Pro recorded for it and falls back to its last reported IPv4 address.
  5. Records the device's operating system version on the asset. For a computer, Guard also records the operating system name; for a mobile device, it records the device type.

Devices with no IP address in Jamf Pro are skipped. Guard also drops IP addresses it should not scan:

  • Loopback, link-local, multicast, and unspecified addresses.
  • Addresses in public cloud provider ranges.
  • Private addresses, such as 10.0.0.0/8 or 192.168.0.0/16.
  • Any address, public or private, that does not answer a single ping within half a second.

To import private and non-responding addresses, contact Praetorian support.

The integration only reads from Jamf Pro. It does not change devices, policies, or settings. Jamf Protect data is not imported.

Prerequisites

  • A Jamf Pro instance (Jamf Cloud or on-premises) that Guard can reach over HTTPS.
  • A Jamf Pro account that can create API roles and clients.
  • Permission to add integrations in Guard.

Step 1: Create an API role and client in Jamf Pro

  1. In Jamf Pro, go to Settings → API Roles and Clients.
  2. On the API Roles tab, create a role and give it these privileges:
    • Read Computers
    • Read Mobile Devices
  3. On the API Clients tab, create a client, assign it the role from step 2, and enable it.
  4. Generate a client secret. Copy the Client ID and the Client Secret and store them safely. Jamf Pro shows the secret only once.

Step 2: Connect Jamf Pro in Guard

  1. In Guard, go to Integrations and open Managed Detection and Response → Jamf Pro.
  2. Enter:
    • Jamf Pro URL: your instance's base URL, for example https://your-company.jamfcloud.com. It must start with https://.
    • API Client ID: the client ID from step 1.
    • API Client Secret: the client secret from step 1.
  3. Click Connect.

Before saving, Guard checks the URL, requests an access token with your client credentials, and reads one record from your computer inventory. If any check fails, Guard shows the error and does not save the integration.

Verify the integration

After the first run, go to Assets and search for the IP address of a device that checked in to Jamf Pro recently, has a public IP address outside cloud provider ranges, and answers ping. Its asset should show the device's operating system version.

Troubleshooting

Message

What to do

Missing Required Fields or Missing Required Field

Fill in the Jamf Pro URL, API Client ID, and API Client Secret. A value that is only spaces counts as empty.

Invalid Format: for example, "value must use https://" or "value resolves to a private address"

Enter the full https:// base URL of your Jamf Pro instance. Guard does not accept http:// or internal hosts.

Authentication Failed: Jamf Pro rejected the supplied credentials

Check the client ID and secret, confirm the API client is enabled, and generate a new secret if needed.

Insufficient Permissions: the credentials cannot read computer inventory

Add Read Computers to the API role assigned to the client.

Connection Failed: could not reach the Jamf Pro API

Check the URL and confirm your Jamf Pro instance accepts connections from the internet.

Validation passes but the run fails on mobile devices

Guard checks only computer access when you connect. Add Read Mobile Devices to the API role.

The run fails with a message that inventory is truncated at 1000 pages

Guard reads up to 100,000 recently active computers and 100,000 recently active mobile devices per run. If the computer inventory hits the limit, Guard stops before it reads mobile devices. Contact Praetorian support.

Devices are missing from Assets

The device may have no IP address in Jamf Pro, may not have checked in within 30 days, may have a private or cloud provider IP, or may not answer ping. See What the integration does.

If you need help with this integration, contact support@praetorian.com.