Overview
The Jamf Protect integration enables ThreatAware to access your Jamf Protect console data, providing visibility into Apple device security, threat detection, and compliance status. This helps you validate endpoint protection across your macOS and iOS devices.Connection Method: API
Setup Time: 15 minutes
Access Required: Jamf Protect Administrator account
Data collected
The Jamf Protect integration provides:- Apple device security status
- Threat detection events
- Device compliance information
- Protection status indicators
Use cases
Apple Device Monitoring
Monitor security status across macOS and iOS devices
Threat Detection
Track detected threats on Apple devices
Compliance Validation
Verify Apple device security policies are enforced
Security Posture
Assess overall security posture of Apple endpoints
Setup instructions
1
Log in to ThreatAware
- Navigate to the ThreatAware dashboard
- Go to Settings → Integrations
- Use the search bar to find Jamf Protect
- Click Connect - a pop-up window will appear
2
Access Jamf Protect Console
- Open the Jamf Protect Console
- Log in using your administrator credentials
3
Navigate to API Settings
- Go to Settings in the Jamf Protect Console
- Select API Clients from the menu
4
Create API Client for ThreatAware
- Click Add API Client to create a new API client
- Name the client “ThreatAware Integration” (or similar)
- Assign permissions:
- Select Read-only access for monitoring purposes
- This allows ThreatAware to collect data without modification capability
- Click Save or Create
5
Copy API Credentials
- The system will display the Client ID and Client Secret
- Copy the Client ID
- Copy the Client Secret (note: this is typically shown only once)
- Store both credentials securely
6
Configure in ThreatAware
In the ThreatAware pop-up window, enter:
- Client ID: The Client ID from Jamf Protect
- Client Secret: The Client Secret from Jamf Protect
- Jamf Protect URL: The URL of your Jamf Protect instance (default:
https://protect.jamfcloud.com) - Click Authorize or Connect to establish the integration
7
Verify Connection
- In ThreatAware, verify the Integration Status displays as Active
- Data collection will begin within 1 hour
- Check that Jamf Protect device data appears in ThreatAware
Required credentials
Client ID
Client ID
Field Name: Jamf Protect Client ID
Type: String
Description: The unique identifier for your Jamf Protect API client
- Generated when creating the API client in Jamf Protect
- Required for API authentication
- Example:
ca6e6f79-5a2d-4c8f-9f1e-2d5c8f9a1b2c
Client Secret
Client Secret
Field Name: Jamf Protect Client Secret
Type: Password (encrypted)
Description: The secret credential for authenticating to the Jamf Protect API
Jamf Protect URL
Jamf Protect URL
Field Name: Jamf Protect URL
Type: String
Description: The URL of your Jamf Protect instanceDefault:
https://protect.jamfcloud.com
Custom: If using a dedicated or on-premises instance, enter your custom URLVerification and testing
After setup, verify the integration is working correctly:-
Check Integration Status
- Navigate to Settings → Integrations in ThreatAware
- Confirm Jamf Protect shows Active status
- Check the last sync timestamp
-
Verify Device Data
- Wait 60 minutes for the initial data poll
- Search for a known Apple device in ThreatAware
- Verify Jamf Protect security information appears in device details
-
Test Security Queries
- Create a test query to filter devices by Jamf Protect security status
- Verify the data matches your Jamf Protect Console
Troubleshooting
Invalid Credentials Error
Invalid Credentials Error
Symptoms: Integration status shows authentication failureSolutions:
- Verify the Client ID and Client Secret are correct
- Ensure credentials were copied completely without extra spaces
- Check that the API client exists and is active in Jamf Protect
- Verify the API client has not been deleted or revoked
- If unsure, create a new API client and update the credentials
Permission Errors
Permission Errors
Symptoms: Integration connects but cannot retrieve device data or access is deniedSolutions:
- Verify the API client was created with Read-only permissions
- Check that the API client has sufficient permissions in Jamf Protect
- Ensure your Jamf Protect administrator account still has access
- Review Jamf Protect API Documentation for permission requirements
- Regenerate the API client with correct permissions if needed
Invalid URL
Invalid URL
Symptoms: Integration fails to connect with URL errorSolutions:
- Verify the Jamf Protect URL is correct and accessible
- Default URL should be:
https://protect.jamfcloud.com - If using a custom URL, ensure it is correct for your deployment
- Test the URL in a browser to confirm it is reachable
- Check firewall rules allow outbound HTTPS (443) to the Jamf server
No Data After 1 Hour
No Data After 1 Hour
Symptoms: Integration shows active but no Jamf Protect device data appearsSolutions:
- Verify there are Apple devices enrolled in Jamf Protect
- Check that devices have reported to Jamf Protect recently
- Confirm the API client has access to view devices
- Wait additional time - first sync may take longer than 1 hour
- Review ThreatAware integration logs for error messages
- Contact ThreatAware support if data collection continues to fail
Important notes
Additional resources
Jamf Protect API Documentation
Official Jamf API documentation for detailed setup and permissions
ThreatAware Support
Contact ThreatAware support for integration assistance