惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Engineering at Meta
Engineering at Meta
G
Google Developers Blog
WordPress大学
WordPress大学
M
MIT News - Artificial intelligence
D
DataBreaches.Net
云风的 BLOG
云风的 BLOG
爱范儿
爱范儿
Microsoft Security Blog
Microsoft Security Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Blog — PlanetScale
Blog — PlanetScale
T
Tailwind CSS Blog
S
SegmentFault 最新的问题
阮一峰的网络日志
阮一峰的网络日志
博客园 - 三生石上(FineUI控件)
酷 壳 – CoolShell
酷 壳 – CoolShell
Recent Announcements
Recent Announcements
T
The Blog of Author Tim Ferriss
I
InfoQ
MyScale Blog
MyScale Blog
V
V2EX
B
Blog
罗磊的独立博客
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More

Jamf Blog

Jamf Nation Live 2026 London and Berlin: AI Governance and DDM 5 Mac Security Gaps Hiding in Your Apple Fleet Classroom Management Tools and Student Learning Outcomes Mobile forensics, minutes not weeks Turn Security Signals into Action with Jamf and Amplifier Security Strengthen Jamf Zero Trust Network Access With Dedicated Internet Gateway Jamf AI Assistant Now Available: Smarter Apple Device Management and Security MacBook Neo: The New Enterprise Entry Point for Mac at Scale Boost Employee Productivity in the Enterprise with Jamf Automation for Small IT Teams: Save Time Managing Macs What a lower-cost MacBook Neo means for education Where Apple Meets the Enterprise: Jamf’s Interoperability Advantage for Secure, Automated Access Control Simplify access, secure your apps: why SSO matters for K-12 Inside Predator’s kernel engine RSA Conference 2026 recap: AI security, enterprise mobile security and the shift to connected security platforms ClickFix technique uses Script Editor instead of Terminal on macOS Why Mac configurations fall out of sync — and how to fix them G2 names Jamf in its 2026 Best Software Awards across three categories Empowering Mac users: How Jamf Self Service+ reduces tier one support overhead for enterprise IT teams Privacy by default, flexible when required: introducing limited privacy in Jamf Safe Internet From arrival to discharge: how iOS is reimagining the healthcare journey Federated Identity Management for K-12 Education Identity and access management in K-12 schools OpenClaw: the helpful AI that could quietly become your biggest insider threat Get Started with Scripting Series: macOS Terminal, Scripting and Jamf Pro API Managing Apple devices at Black Hat Europe with Jamf Scaling device deployments without scaling your IT team How Predator spyware defeats iOS recording indicators Making Mac work in a PC world The hidden costs of manual device provisioning
Platform Authentication and Declarative Device Management...
Mike VanDelinder · 2026-04-16 · via Jamf Blog

Declarative device management is here.

Apple is changing their platform — DDM is replacing MDM, with legacy capabilities being deprecated along the way. Staying current with new Apple releases means adopting declarative device management, and our approach to delivering those capabilities is through platform services like blueprints.

Platform authentication is what fills that gap.

Why platform authentication is the future

Platform authentication is now shared across all of Jamf's applications and services, and it makes administrator access management more secure in the process. Jamf ID is an improvement over local application credentials. Connecting your own identity provider is better, and routing that connection through the platform rather than configuring it separately in each product means it applies everywhere from the start.

The past year was about closing the distance between that model and where most customers actually were.

Jamf has been building capabilities that live outside the boundary of any single product — Blueprints, compliance benchmarks, the Platform API now in public beta. Delivering those consistently across Jamf Pro, Jamf School, Jamf Security Cloud, Jamf Protect, and the rest of the portfolio required a single connection between a customer's identity infrastructure and Jamf's, rather than a separate integration for each product.

How platform authentication works

Platform authentication is an OIDC-based integration between your organization and Jamf's platform services, configured once in Jamf Account and applied across everything. Jamf Account is where you have always managed your organization's Jamf relationship — from spinning up a Jamf Pro tenant to accessing support and downloads. It is accessible to every customer regardless of which Jamf products they use, and it sits outside any single product as neutral ground for configuration that applies across the portfolio.

Multiple options, One security path

Two authentication options are available for Jamf's applications and services. Every customer has a Jamf ID, created the first time you sign into Jamf Account. It does not depend on an external identity provider, which means any organization can use it regardless of how they manage identity elsewhere.

For customers with Okta, Microsoft Entra or Google Workspace, keep using it. Connecting your identity provider to Jamf's platform means your administrators sign into Jamf the same way they sign into everything else. Your MFA policies apply. Your session controls apply. When someone leaves and you disable their account in your IdP, their federated access to Jamf products is revoked immediately.

One thing worth knowing: Jamf ID is a user-managed credential, not an organizational one. Disabling someone in your IdP cuts off their federated access, but their Jamf ID remains usable unless you explicitly turn it off. In Jamf Pro SSO settings, you can require federated authentication only, which removes that fallback path. Some offboarding cleanup is still a best practice either way.

Connecting via an identity provider also gives you group membership claims. An administrator's group memberships travel in the identity token when they authenticate, and Jamf Pro maps those to roles and privileges. You manage who has access to what in Jamf Pro by managing group membership in your IdP — the same place you manage it for everything else.

The new model is authentication configured once in Jamf Account and shared across every product, whether that means signing in with Jamf ID or federating back to your identity provider where you have one.

Some customers were starting from scratch. Others had built mature integrations and needed the new model to accommodate what they already had.

We built for both.

Here is what we shipped:

Other notable enhancements

The setup path for new customers has also improved. Enabling Jamf ID authentication from your Jamf Pro dashboard now walks you through the steps without any prior knowledge of the underlying authentication protocols. For customers connecting a federated identity provider, that configuration lives in Jamf Account where you connect your provider, choose which products and instances it applies to, and configure whether Jamf ID, your federated provider, or both are permitted.

Access management is evolving alongside authentication. Today, the connection between an administrator's IdP group memberships and their role inside Jamf Pro is configured at the application layer — Jamf Pro maps claims to roles, and each product manages that configuration on its own. Jamf is moving toward centralized management of those roles and access policies at the platform level, so an administrator's access across all of Jamf's applications and services reflects a single source of truth. That work is underway.

Blueprints, compliance benchmarks, AI Assistant — every capability Jamf has shipped to its platform services in the last year runs on this authentication layer. The Platform API, now in public beta, goes further: a unified set of endpoints providing device data and management capabilities across your entire Jamf environment through a single credential.

If you have been waiting for the right time to make this transition, the gaps from a year ago are largely resolved. If you are already configured, the path forward is to use what is now available.