惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

MyScale Blog
MyScale Blog
博客园 - 叶小钗
小众软件
小众软件
宝玉的分享
宝玉的分享
Apple Machine Learning Research
Apple Machine Learning Research
Jina AI
Jina AI
Last Week in AI
Last Week in AI
量子位
腾讯CDC
罗磊的独立博客
酷 壳 – CoolShell
酷 壳 – CoolShell
博客园 - Franky
博客园 - 【当耐特】
Hugging Face - Blog
Hugging Face - Blog
有赞技术团队
有赞技术团队
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
V
Visual Studio Blog
爱范儿
爱范儿
月光博客
月光博客
博客园 - 三生石上(FineUI控件)
雷峰网
雷峰网
V
V2EX
WordPress大学
WordPress大学
Google DeepMind News
Google DeepMind News
阮一峰的网络日志
阮一峰的网络日志
K
Kaspersky official blog
Vercel News
Vercel News
L
LINUX DO - 热门话题
The Hacker News
The Hacker News
The Register - Security
The Register - Security
IT之家
IT之家
C
Cybersecurity and Infrastructure Security Agency CISA
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
人人都是产品经理
人人都是产品经理
Martin Fowler
Martin Fowler
S
SegmentFault 最新的问题
N
News | PayPal Newsroom
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Attack and Defense Labs
Attack and Defense Labs
S
Securelist
T
The Blog of Author Tim Ferriss
GbyAI
GbyAI
Microsoft Security Blog
Microsoft Security Blog
H
Hacker News: Front Page
博客园 - 聂微东
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
Project Zero
Project Zero
I
InfoQ
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
PCI Perspectives
PCI Perspectives

Jamf Blog

Jamf Nation Live 2026 London and Berlin: AI Governance and DDM 5 Mac Security Gaps Hiding in Your Apple Fleet Classroom Management Tools and Student Learning Outcomes Mobile forensics, minutes not weeks Turn Security Signals into Action with Jamf and Amplifier Security Strengthen Jamf Zero Trust Network Access With Dedicated Internet Gateway Jamf AI Assistant Now Available: Smarter Apple Device Management and Security MacBook Neo: The New Enterprise Entry Point for Mac at Scale Boost Employee Productivity in the Enterprise with Jamf Automation for Small IT Teams: Save Time Managing Macs What a lower-cost MacBook Neo means for education Where Apple Meets the Enterprise: Jamf’s Interoperability Advantage for Secure, Automated Access Control Simplify access, secure your apps: why SSO matters for K-12 Inside Predator’s kernel engine RSA Conference 2026 recap: AI security, enterprise mobile security and the shift to connected security platforms ClickFix technique uses Script Editor instead of Terminal on macOS Why Mac configurations fall out of sync — and how to fix them G2 names Jamf in its 2026 Best Software Awards across three categories Empowering Mac users: How Jamf Self Service+ reduces tier one support overhead for enterprise IT teams Privacy by default, flexible when required: introducing limited privacy in Jamf Safe Internet From arrival to discharge: how iOS is reimagining the healthcare journey Federated Identity Management for K-12 Education Identity and access management in K-12 schools OpenClaw: the helpful AI that could quietly become your biggest insider threat Get Started with Scripting Series: macOS Terminal, Scripting and Jamf Pro API Managing Apple devices at Black Hat Europe with Jamf Scaling device deployments without scaling your IT team How Predator spyware defeats iOS recording indicators Making Mac work in a PC world The hidden costs of manual device provisioning Threat Actors Expand Abuse of Microsoft Visual Studio Code Mac management and security for lean IT teams Automated certificate management and device security integration The hidden risks in your mobile apps “Mac in 2026: Secure by Design Meets the Enterprise” webinar Jamf named a Unified Endpoint Management leader…again! Jamf recognized as a Leader in 2026 Gartner® Magic Quadrant™ for Endpoint Management Tools Predator’s kill switch: undocumented anti-analysis techniques in iOS spyware 2026: what to expect in tech Retail runs on iOS: Let’s take a tour through Jamf’s booth at NRF 2026 From ClickFix to code signed: the quiet shift of MacSync Stealer malware Jamf After Dark: How WorkBrew solves Homebrew security and compliance for Mac developers Managing emerging technologies: A playbook for modern IT leaders How schools can maximize learning using Apple devices and Jamf Practical intelligence: why it matters for enterprise teams Jamf Connect Q&A Jamf After Dark October recap: platform progress, identity shifts and security insights Powering managed virtualization and Windows app delivery in Mac-first enterprises FlexibleFerret malware continues to strike Managing Jamf configuration with Terraform and GitOps workflows Back to security basics: phishing Introducing the Jamf 140 Course HIMSS 2026 recap Introducing Beacon by Jamf Threat Labs GhostClaw expands beyond npm: GitHub repositories and AI workflows deliver macOS infostealer Android and Jamf: manage and secure your mobile fleet Social engineering in K-12 for beginners Jamf Nation Live 2026: Hands-On Apple Expertise Across Six Cities Developer Mode-as-a-Defense: How iOS Security Features Deter Nation-State Spyware Stop chasing passwords: how school IT can reduce reset tickets Bring Your Own Key (BYOK): Take Control of Your Encryption in Jamf Cloud DarkSword iOS Exploit Kit: 3 Lessons for Mobile Security Threat Labs Jamf Training Celebrates 20 Years of Apple IT Education and Certification Balancing Safety and Learning: K-12 Content Filtering for IT Admins Why Mac security updates take too long and how to fix it Why the Jamf platform is the natural foundation for MSPs Jamf After Dark: mobile forensics Introducing the redesigned Mac threat prevention. Now available in beta.  Beyond access: rethinking the complete Apple deployment strategy for education Gain faster updates and real-time fleet visibility with DDM What the Canvas breach tells us about the state of education security Why K-12 students need web filtering that travels with their devices Jamf spotlighted in Okta Businesses at Work 2026 Report Jamf Nation Live 2026 recap MobiDash internals: ghost clicks and SSH tunnels in commercial adware Tech Partner Spotlight: Jamf + SmallStep MacBook Neo in K-12 Closing the gaps: How Jamf protects macOS and iOS with real-time threat prevention MSP engineering: The art of scoping in Jamf Pro at scale Mac in education is evolving. Jamf School makes it simple Why Apple devices deserve security built for them Seamless Learning Access: Simplicity that puts learning first Reducing IT firefighting: Fewer failed updates, less manual cleanup Apple WWDC26: Keynote recap How Jamf helps maximize your Microsoft investments MTE as a microscope WWDC26: Key takeaways for education institutions WWDC26: Key takeaways for Apple admins The JNUC 2026 session catalog is live — and the clock is ticking Jamf After Dark: Why we moved 1,900+ Apple devices back to Jamf AI governance for Mac: bringing AI under management AI Adoption Is High, Governance Is Lagging Klue Third-Party Cybersecurity Incident How Identity Automation, Claris, and Jamf Simplify Apple Workflows for Education What Is AI Governance? How Proactive Device Status Reporting Transforms Mac Fleet Visibility AI Governance on Mac: A Practical Guide for IT and Security Teams Restaurants Run on iOS: Jamf and IPORT at the NRA Show AI Governance on Mac: A Practical Guide for IT and Security Teams PamStealer: macOS Malware Posing as Clipboard Manager App
Platform Authentication and Declarative Device Management: The Future of Apple Management
Mike VanDelinder · 2026-04-16 · via Jamf Blog

Declarative device management is here.

Apple is changing their platform — DDM is replacing MDM, with legacy capabilities being deprecated along the way. Staying current with new Apple releases means adopting declarative device management, and our approach to delivering those capabilities is through platform services like blueprints.

Platform authentication is what fills that gap.

Why platform authentication is the future

Platform authentication is now shared across all of Jamf's applications and services, and it makes administrator access management more secure in the process. Jamf ID is an improvement over local application credentials. Connecting your own identity provider is better, and routing that connection through the platform rather than configuring it separately in each product means it applies everywhere from the start.

The past year was about closing the distance between that model and where most customers actually were.

Jamf has been building capabilities that live outside the boundary of any single product — Blueprints, compliance benchmarks, the Platform API now in public beta. Delivering those consistently across Jamf Pro, Jamf School, Jamf Security Cloud, Jamf Protect, and the rest of the portfolio required a single connection between a customer's identity infrastructure and Jamf's, rather than a separate integration for each product.

How platform authentication works

Platform authentication is an OIDC-based integration between your organization and Jamf's platform services, configured once in Jamf Account and applied across everything. Jamf Account is where you have always managed your organization's Jamf relationship — from spinning up a Jamf Pro tenant to accessing support and downloads. It is accessible to every customer regardless of which Jamf products they use, and it sits outside any single product as neutral ground for configuration that applies across the portfolio.

Multiple options, One security path

Two authentication options are available for Jamf's applications and services. Every customer has a Jamf ID, created the first time you sign into Jamf Account. It does not depend on an external identity provider, which means any organization can use it regardless of how they manage identity elsewhere.

For customers with Okta, Microsoft Entra or Google Workspace, keep using it. Connecting your identity provider to Jamf's platform means your administrators sign into Jamf the same way they sign into everything else. Your MFA policies apply. Your session controls apply. When someone leaves and you disable their account in your IdP, their federated access to Jamf products is revoked immediately.

One thing worth knowing: Jamf ID is a user-managed credential, not an organizational one. Disabling someone in your IdP cuts off their federated access, but their Jamf ID remains usable unless you explicitly turn it off. In Jamf Pro SSO settings, you can require federated authentication only, which removes that fallback path. Some offboarding cleanup is still a best practice either way.

Connecting via an identity provider also gives you group membership claims. An administrator's group memberships travel in the identity token when they authenticate, and Jamf Pro maps those to roles and privileges. You manage who has access to what in Jamf Pro by managing group membership in your IdP — the same place you manage it for everything else.

The new model is authentication configured once in Jamf Account and shared across every product, whether that means signing in with Jamf ID or federating back to your identity provider where you have one.

Some customers were starting from scratch. Others had built mature integrations and needed the new model to accommodate what they already had.

We built for both.

Here is what we shipped:

Other notable enhancements

The setup path for new customers has also improved. Enabling Jamf ID authentication from your Jamf Pro dashboard now walks you through the steps without any prior knowledge of the underlying authentication protocols. For customers connecting a federated identity provider, that configuration lives in Jamf Account where you connect your provider, choose which products and instances it applies to, and configure whether Jamf ID, your federated provider, or both are permitted.

Access management is evolving alongside authentication. Today, the connection between an administrator's IdP group memberships and their role inside Jamf Pro is configured at the application layer — Jamf Pro maps claims to roles, and each product manages that configuration on its own. Jamf is moving toward centralized management of those roles and access policies at the platform level, so an administrator's access across all of Jamf's applications and services reflects a single source of truth. That work is underway.

Blueprints, compliance benchmarks, AI Assistant — every capability Jamf has shipped to its platform services in the last year runs on this authentication layer. The Platform API, now in public beta, goes further: a unified set of endpoints providing device data and management capabilities across your entire Jamf environment through a single credential.

If you have been waiting for the right time to make this transition, the gaps from a year ago are largely resolved. If you are already configured, the path forward is to use what is now available.