Iru (Kandji)
Iru (Kandji) is a modern Apple device management platform that provides zero-touch deployment, automated compliance, and intelligent device management for macOS, iOS, and iPadOS. Connecting Iru (Kandji) to Harmony enables automated device provisioning, AI-powered troubleshooting, and seamless endpoint management workflows.
What the Iru (Kandji) Integration Enables
Device Inventory
Sync all managed Apple devices with real-time status
Compliance Automation
Monitor and enforce security baselines automatically
Remote Actions
Execute lock, restart, and erase commands
Custom Script Deployment
Deploy and manage custom scripts across devices using Kandji's blueprint-based architecture
Connected Peripheral Discovery
Automatically discover monitors and peripherals attached to managed devices
Installed Software Discovery
Surface installed applications across your managed Apple devices in the Applications view
Prerequisites
Before configuring the Kandji integration, ensure you have:
Kandji Administrator Access: Admin or full access role in Kandji
API Token: Generated from Kandji settings
Harmony Account: Active Harmony workspace with integration permissions
Configuration in Kandji
Step 1: Generate API Token
Log in to your Kandji tenant at
https://[your-tenant].kandji.ioClick Access in the left sidebar
Click the API tokens tab
Click Add Token

Configure the token:
Name: "Harmony Integration"
Copy the token immediately (it won't be shown again)
Configure Permissions:
Blueprint Management: POST + PATCH + GET
Users: GET
Prism Categories: GET
Audit Log: GET
Library Items: GET
Custom Scripts: POST + PATCH + GET
Device Information: GET
Device Secrets: FileVault Recovery Key, Unlock PIN
Device Actions: Lock, Restart
Click Save

Configuration in Harmony
Step 1: Navigate to Integrations
Log in to your Harmony dashboard
Go to Settings > Integrations
Find Iru (Kandji) and click to Connect

Step 2: Enter API Credentials
Provide the following information:
Instance name: A friendly name for this connection (e.g., "Kandji Production")
Base URL: Your Kandji API URL (e.g.,
https://yourcompany.api.kandji.io)API token: The token you generated in Step 1
Click Connect

What Harmony Syncs from Kandji
Device Inventory: All managed devices with hardware details, fetched using an efficient paginated approach for fast and reliable syncing even across large device fleets
Device Status: Online/offline status, last check-in time
Compliance State: Security compliance and parameter status
Installed Apps: Applications and versions on each device, surfaced in the Applications view with noise filtered out via an ignore list
User Information: Assigned user for each device (devices with empty user fields are handled gracefully)
FileVault Status: Encryption status for Macs
OS Versions: Current macOS/iOS/iPadOS versions
Connected Peripherals: Monitors and other hardware attached to managed devices, discovered via osquery-based custom scripts
Custom Script Deployment
Harmony supports deploying custom scripts to your Kandji-managed devices directly from the platform. Kandji's blueprint-based architecture is handled automatically, so your existing blueprints are never modified.
Key capabilities include:
Automatic blueprint cloning: Harmony clones your existing Kandji blueprints and assigns scripts to the clones, leaving your originals untouched.
Device-targeted deployment: Scripts can be targeted to specific devices, with Harmony grouping devices by blueprint and managing assignments accordingly.
Fleet-wide deployment: When no device filter is set, scripts are assigned directly to all blueprints without unnecessary cloning, making deployment faster and more efficient.
Parallelized API calls: API requests during deployment are parallelized to reduce overall deployment time.
osquery-based hardware discovery: Custom scripts collect hardware data in an OS-agnostic way, keeping your asset inventory accurate across macOS and other supported platforms.
Installed Software Discovery
Harmony automatically discovers installed software on your Apple devices through the Kandji integration. Harmony fetches the list of applications installed across your managed devices and surfaces them in the Applications view, giving you visibility into your software landscape without any manual effort.
An ignore list filters out system-level entries and other noise that is not relevant to your software management workflow.
You can sort applications by user count to quickly identify widely used or underutilized software.
Use Cases
Troubleshooting
Data & Privacy
Last updated
Was this helpful?
