Загрузка...

Mac Admin Telemetry: Shift from Reactive to Proactive IT with Jamf Protect #JNUC 2025

Discover how Mac administrators can leverage Jamf Protect telemetry to transform reactive IT support into proactive fleet management—without expensive SIEM solutions or dedicated security teams. Senior Sales Engineer Eric Metzger shares practical workflows for real-time monitoring, shadow IT detection, and automated alerting using tools you already have.

This JNUC 2025 session demonstrates how telemetry provides continuous endpoint data streams from Apple's native frameworks, enriched with actionable context. Learn to parse JSON event data, build Azure Function workflows, and create Slack/Teams notifications—all through accessible "vibe coding" techniques using AI assistance.

#JamfProtect #MacAdmin #EndpointSecurity #enterpriseit

0:00 Introduction: From Reactive to Proactive Mac Administration
2:19 Eric's Journey: MSP Origins and the Birth of CMD Reporter (Telemetry Precursor)
5:23 What Is Telemetry? Comparing Jamf Protect to Jamf Pro Capabilities
8:19 Understanding the Endpoint Security API and Real-Time Data Collection
10:16 JSON Explained: Breaking Down Telemetry Event Structure for Mac Admins
12:00 Event Enrichment: How Jamf Adds Context to Raw Apple Framework Data
14:22 Deep Dive: Analyzing an OD Create User Event (200+ Lines of Data)
18:09 Real-World Use Case: Automated User Creation Alerts
20:44 Vibe Coding with AI: Building Workflows Without Traditional Programming
24:27 Azure Functions Workflow: Telemetry to Slack Notifications Step-by-Step
25:49 Shadow IT Detection: Monitoring Apps Running from Non-Standard Locations
30:03 Key Takeaways: Mindset Shift for Modern Mac Administrators
32:06 AI Limitations: Trust But Verify Your Chatbot-Generated Code
33:24 Getting Started: Testing Telemetry on Individual Machines
36:30 Cost Analysis: Telemetry Workflows at $35-$2,100/Month vs Traditional SIEM Solutions
38:38 Advanced Possibilities: Unified Logs, Forensic Auditing, and Jamf Pro API Integration

What You'll Learn:

► How Jamf Protect telemetry differs from traditional Jamf Pro extension attributes and why it matters for Mac fleet management
► Understanding JSON structure and enriched telemetry events from Apple's Endpoint Security API
► Building real-time alerts for user creation, shadow IT detection, and unauthorized application launches
► Creating cost-effective monitoring workflows using Azure Functions, AWS Lambda, or Google Cloud Functions
► Practical proactive IT strategies that reduce firefighting and improve end-user experience
► Security and privacy considerations when handling telemetry data containing PII

Видео Mac Admin Telemetry: Shift from Reactive to Proactive IT with Jamf Protect #JNUC 2025 канала Jamf
Яндекс.Метрика
Все заметки Новая заметка Страницу в заметки
Страницу в закладки Мои закладки
На информационно-развлекательном портале SALDA.WS применяются cookie-файлы. Нажимая кнопку Принять, вы подтверждаете свое согласие на их использование.
О CookiesНапомнить позжеПринять