Jamf
Jamf Pro is the leading Apple device management platform for enterprises, providing comprehensive MDM (Mobile Device Management) for macOS, iOS, iPadOS, and tvOS devices. Connecting Jamf Pro to Harmony enables automated device provisioning, intelligent policy management, and streamlined Apple fleet operations.
What the Jamf integration enables
Automated Device Enrollment
Trigger device setup and configuration workflows automatically
Device Compliance
Monitor and enforce security policies across devices
Inventory Management
Track device assignments, status, and health
Asset Purchase Tracking
Sync procurement, warranty, and vendor data for each managed device
Application Discovery
Automatically ingest installed software inventory into your Applications catalog
Custom Script Deployment
Deploy and manage scripts on macOS devices directly from Harmony
Building Location Visibility
Surface building name, city, and country for Jamf-managed assets
Automation Workflows
Build custom workflows using the Jamf Pro API
Anything defined in the Jamf Pro API can be accessed through Harmony workflows.
Prerequisites
Before connecting Jamf to Harmony, ensure you have:
Jamf Pro Administrator access
Permissions to create API users and roles
Your Jamf Pro URL (e.g.,
company.jamfcloud.com)A Harmony account with admin privileges
Connect Jamf Pro to Harmony
Step 1: Create API Client in Jamf Pro
Log in to your Jamf Pro console
Click Settings (gear icon) in the top-right
Navigate to System → API Roles and Clients
Click the API Clients tab
Click + New to create a new API client
Configure:
Display Name:
Harmony IntegrationGrant the following API permissions:
Advanced Mobile Device Searches
Read
Computer Enrollment Invitations
Read
Computer Extension Attributes
Read
Computer Inventory Collection
Read
Computer Inventory Collection Settings
Read
Computer PreStage Enrollments
Read
Computers
Read
Mobile Device App Maintenance Settings
Read
Mobile Device Enrollment Invitations
Read
Mobile Device Extension Attributes
Read
Mobile Device Inventory Collection
Read
Mobile Device Managed App Configurations
Read
Mobile Device Applications
Read
Mobile Device PreStage Enrollments
Read
Mobile Device Self Service
Read
Mobile Devices
Read
Smart Mobile Device Groups
Read
Policies
Read, Create, Update
Scripts
Read, Create, Update
View Disk Encryption Recovery Key
Read
Send Computer Remote Lock Command
Create
Send Mobile Device Remote Lock Command
Create
Send Computer Restart Command
Create
Send Mobile Device Restart Device Command
Create
View Computer Device Lock Pin
Read
Click Save
Copy the Client ID and Client Secret (the secret cannot be retrieved later)
Step 2: Navigate to Integrations
Log into your Harmony dashboard
Navigate to Settings → Integrations
Find Jamf Pro under MDM
Click Connect

Step 3: Configure Connection
Enter an Instance name for your Jamf Pro connection
Enter your Base URL (e.g.,
https://yourcompany.jamfcloud.com)Enter your Client ID (Jamf Pro OAuth client ID)
Enter your Client secret (Jamf Pro OAuth client secret)
Click Connect

What gets synced
Once connected, Harmony pulls comprehensive data from Jamf Pro and organises it across several areas of the platform.
Device inventory
Harmony automatically discovers and categorises your Apple device fleet with rich, structured detail:
Device type detection - MacBooks, iMacs, iPhones, and other Apple hardware are automatically identified and categorised by model name
Hardware information - device model, serial number, processor, memory, and storage
Compliance status - each device is evaluated against FileVault encryption, supervision status, and security settings to surface compliance posture at a glance
Network interfaces - primary and additional network adapters are captured
Security posture - FileVault encryption status, battery health, and partition details
Purchase and procurement details
Harmony enriches each asset record with purchase data sourced directly from Jamf's computer inventory. The following details are captured and kept in sync:
Purchase number (PO number) and vendor - giving you a clear procurement trail for every asset
Purchase price - parsed from international formats
Warranty and lifecycle dates
Building location
When a device has a building assigned in Jamf, the building name appears between the Location and Source fields on the asset detail page. This works even for devices that do not have a user assigned - as long as building data exists in Jamf, it is surfaced in Harmony. Building information includes the building's name, city, and country as configured in your Jamf environment.
Installed applications
Harmony automatically ingests software inventory data collected by Jamf and populates it into your Applications catalog, giving you a complete, up-to-date view of what is installed across your fleet. An ignore list is applied during ingestion to filter out noise and keep your application inventory clean and meaningful. Security and IT teams get accurate software visibility for Jamf-managed devices alongside any other sources already connected to Harmony.
Device lock with auto-generated PIN
When triggering a device lock action through Jamf, Harmony can automatically generate a secure PIN on your behalf - removing the need to manually specify one. This streamlines the process for support agents handling lock requests directly from a ticket. Providing a custom PIN remains available as an optional parameter if preferred.
Custom script deployment
You can deploy custom scripts to macOS devices managed through Jamf Pro directly from Harmony. When a custom script action is triggered, Harmony automatically creates and manages both the script and its associated policy in Jamf Pro, handling the full lifecycle so your devices stay in sync.
Script creation and updates - scripts are created or updated in Jamf Pro via the modern JSON API, with content validation before deployment
Policy management - a corresponding Jamf policy is automatically created and linked to the script, using a recurring check-in trigger so managed devices receive and execute the script reliably
API version compatibility
The Jamf integration uses the current Jamf Pro v3 API for computer inventory and FileVault recovery key endpoints, ensuring uninterrupted data collection as Jamf retires older API versions. The v3 responses are fully compatible with existing data - no changes to your Jamf configuration or data are required.
For older Jamf Pro instances, Harmony automatically falls back to the previous API version if v3 is not available, ensuring compatibility across all supported Jamf Pro versions.
Troubleshooting
Best Practices
Need help? Contact support@harmony.io for assistance with your Jamf integration.
Data & Privacy
Last updated
Was this helpful?
