Jamf Pro
Integration & Setup Manual
Jamf Pro Integration Guide
Overview
Cup’n’String Guard integrates with Jamf Pro to deploy AI tool firewall configuration profiles to managed macOS devices. Guard pushes declarative .mobileconfig profiles via the Jamf Pro API — enforcement is cooperative and device-resident (the macOS MDM stack applies the pf or Application Firewall rules locally). Guard tracks device compliance posture from Jamf and associates it with each registered Cup’n’String agent.
Support level
Cooperative Endpoint Control — declarative profile apply via Jamf Pro API with async deployment tracking. Device-posture-aware: Guard reads Jamf compliance signals.
Recommended Guard mode
Observe to audit which Macs have the required pf/Application Firewall profiles deployed, then Enforce to push and maintain profiles automatically.
Known limitations
- Enforcement is cooperative: the macOS MDM stack applies profiles locally. An offline or managed-by-user device may not receive updates promptly.
- Jamf Pro deployment is async — profile delivery depends on device check-in cadence.
- For stronger, immediately enforceable rules, combine Jamf Pro profile delivery with the Cup’n’String native macOS pf integration.
Setup outline
- Confirm the supported platform and deployment requirements with your administrator.
- Use a dedicated integration identity with the minimum required permissions and validated TLS connections.
- Review policy in your environment before enabling enforcement, then verify the intended access outcomes.
Contact the Cup’n’String team for deployment-specific configuration and verification guidance. Never share credentials in support messages or screenshots.
Integration Info
Links
Verify what categories and runtimes this stack fits inside in the global compatibility dashboard.
Supported Environments Matrix