- 2 Minutes to read
- Print
- PDF
Jamf
- 2 Minutes to read
- Print
- PDF
About this document
This document provides the step-by-step procedure to configure Jamf in SAFE.
Introduction
SAFE integrates with Jamf, and fetches the security misconfiguration of the Jamf account in SAFE.
Prerequisites
Access required in SAFE:
SAFE Admin Access
Access required in Jamf:
Jamf Admin Access
Required User Inputs:
API Instance URL
Client ID
Client Secret
Required Scope:
Read Patch Management Software Titles
Read SSO Settings
Read Push Certificates
Read Computers
Read Accounts
Read Patch Management Settings
Generate Connection Details
How to generate Client ID and Client Secret
Login to your Jamf account as Admin.
Click on the Settings from left navigation.
Search for “API roles and clients” and open it
On the API Keys page, Click on the New button available at the top-right of the screen
Enter the Display Name
Select the below permission from the dropdown
Read Patch Management Software Titles
Read SSO Settings
Read Push Certificates
Read Computers
Read Accounts
Read Patch Management Settings
Click on the save button.
System will create the API roles and clients
Click on the back button and click on the API Clients Tab.
Click on the New button.
Enter a Display Name for the API Client.
Select the API roles you created above, In the API roles field.
Enter the Access Token Lifetime in seconds. It's important to regularly update the Access Token in SAFE according to its expiration date
Click on the Enable API client button.
Click on the Save button.
Click on the Generate client secret button.
Copy and save the Client ID and Client secret to use it while configuring Jamf in SAFE.
It's important to regularly update the Client ID and Client Secret in SAFE according to its expiration date.
How to get API Instance URL
Access the Jamf Instance, and capture the URL
Copy and save the API Instance URL to use it while configuring Jamf in SAFE.
Configure Jamf in SAFE
Log in to your SAFE account as Admin.
Click on the Integrations option from the left navigation.
Scroll to find the Jamf integration card or search for Jamf in the search bar.
Hover over the Jamf integration card and click on the Configure button.
Enter the following:
API Instance URL
Client ID
Client Secret
Enter the Auto Sync Frequency.
Click on the Test Connection button.
Once the connection is successful, click on the Save button.
Once the configuration is saved successfully, click on the Sync Now button to trigger an on-demand sync.
Upon a successful sync, the system pulls the Jamf assets and their findings in SAFE. You can track the status of the sync in the History table.
View Results
Go to the integration homepage
Scroll to find the Jamf integration card or search for Jamf in the search bar.
Click on the Jamf integration card for Finding View and Asset View.
Finding View: This tab displays all the findings details pulled from Jamf.
Asset View: This tab displays all the assets pulled from Jamf.
History
Learn More about Integration History here.
SAFE's Outgoing IP Addresses
Click here to find the outgoing IP addresses of SAFE. All traffic to any integrations in SAFE will see one IP address as the source IP of the incoming connection.