Products · Jamf for Mac

Mac management, down to the last detail.

Jamf is the platform that runs Mac at scale — deployment, identity, security and support in one place. Onsite configures it, secures it and operates it for the way your business actually works.

Jamf Elite PartnerDelivered by a Jamf Elite Partner — the highest tier of the Jamf partner programme.
A managed MacBook in a professional workspace
01 · Enrolment & management

Deploy, configure and run every Mac, from anywhere.

Macs arrive ready and stay consistent for their whole working life, handled by policy, not by hand.

Jamf ProBlueprints

Declarative, payload-level configuration that ships Apple’s newest features faster.

Jamf ProSmart Groups

Organise the fleet by any live inventory attribute and target policies automatically.

Jamf ProApp Installers

Curated, Mac-ready app packages with automated lifecycle and patch management.

Jamf ProManaged software updates

Enforce macOS versions and deadlines with user deferrals, via declarative management.

A Mac ships to the new hire and configures itself the moment it powers on, through Apple Business Manager. Nobody in IT touches it, and it arrives already secured and compliant.
Zero-touch onboarding, no IT intervention
Consistent configuration at scale
macOS kept current automatically
Third-party apps patched on their own
02 · Identity & privilege

One identity, from login to app.

Tie the Mac to your cloud identity so people sign in once, reach what they should, and carry no standing admin rights.

Jamf ConnectPrivilege management

Time-limited, fully audited admin elevation instead of standing local admin.

Jamf ProPlatform Single Sign-On

Apple’s native Platform SSO across browser and native apps, with Entra and Okta.

The Mac login is tied to your cloud identity, so people sign in once with a password that stays in sync, and can elevate to admin only for a limited, audited moment when they genuinely need it.
Cloud identity at the Mac login
No standing local admin rights
Every elevation time-limited and audited
Single sign-on across every app
03 · Compliance, visibility & telemetry

Prove your posture, on demand.

Complete visibility, compliance you can enforce and evidence, and telemetry streamed into the tools your security team already runs.

Jamf ProAdvanced Mac visibility

User, hardware, software and app inventory from every Mac, with extension attributes.

Jamf ProCompliance benchmarks

Enforce CIS, NIST and DISA STIG automatically, with audit reports on demand.

Jamf ProtectNext-gen telemetry

Stream rich endpoint data into your SIEM and SOAR for full-stack observability.

JamfConditional access

Feed device compliance to Entra ID, Okta and Google so only trusted Macs connect.

Jamf continuously inventories the software on every Mac, checks it against known CVEs from NIST and Apple, and ranks what is genuinely exploitable, so you patch the right machines first and can prove it.
Full fleet inventory and reporting
Audit-ready CIS / NIST / STIG
Endpoint events in your SIEM
Risk-based, conditional access
04 · Endpoint protection

Security built for the Mac, not bolted on.

Mac-native detection and response from Jamf Protect and Jamf Threat Labs, with automated remediation that runs alongside a Microsoft or CrowdStrike stack.

The moment a process behaves like malware, Jamf stops and quarantines it on the Mac itself, without waiting for a cloud verdict, and can remediate every affected device at once.
Mac-native detection and response
Automated quarantine and forensics
Data-loss controls on removable media
Runs alongside your existing EDR
05 · Web protection

Safe browsing, without the friction.

Block malicious content at the network layer and enforce acceptable use, on-device and privately, without slowing anyone down.

Phishing, malicious domains and cryptojacking are blocked at the network layer, before the page loads, on any connection, without routing traffic through a heavy VPN.
Phishing stopped before the page loads
Acceptable-use enforced per team
Browsing stays fast and private
Web activity visible in your SIEM
06 · Zero-trust network access

Replace the VPN with least privilege.

Encrypted, policy-based access to the apps people need, checked against device health, one app at a time.

Jamf ConnectNetwork Relay

Agent-less ZTNA using Apple’s native MASQUE protocol and hardware-verified attestation.

Every request to a business app is checked against the person’s identity and their device’s health before access is granted, one app at a time, replacing all-or-nothing VPN with least privilege.
No legacy VPN to manage
Per-app access, not the whole network
Only compliant devices connect
Always-on, hardware-verified trust
07 · The Jamf platform

A platform, not just a tool.

The connective tissue that makes everything above work together, and keeps getting better.

JamfJamf Account SSO

One login across every Jamf portal and service.

JamfAI Assistant

Natural-language inventory search and fleet insight.

JamfJamf Routines

Prebuilt automation connecting Jamf events to messaging, ticketing and more.

JamfAPIs & integrations

A free API ecosystem and marketplace to extend the platform.

One identity for the whole platform
Automation that cuts manual work
Extensible via API and marketplace
Intelligent, AI-assisted management
Whole product, not just a licence

Jamf is the platform. Onsite makes it yours.

Every chapter above is only as good as the way it is set up and run. We design the architecture, map the security baseline to your obligations, integrate identity, and either hand it to your team or operate it for you.

  • Architecture and rollout, documented and repeatable
  • Security and compliance mapped to your standards
  • Ongoing operation and support, co-managed or fully managed
The Onsite team running a managed Mac estate
Common questions

Jamf for Mac, answered.

What is Jamf for Mac?
Jamf is the leading platform for managing and securing Macs in business. It covers zero-touch deployment, app and update management, identity, endpoint security and compliance — purpose-built for Apple. Onsite implements and runs it for you.
How is Jamf different from Intune for Macs?
Intune can enrol a Mac and apply basic policies. Jamf goes deeper on Apple-specific deployment, patching, identity and security, and keeps pace with new macOS features on day one. Many organisations run both — Jamf for Apple depth, Microsoft for identity. See our guide to managing Apple with Microsoft.
Do we need Jamf Protect as well as antivirus?
Jamf Protect is macOS-native endpoint security — threat prevention, behavioural detection and telemetry designed for how the Mac actually works. It goes deeper on Mac than cross-platform tools and can run alongside them where you already have an EDR standard.
Can Onsite run Jamf for us?
Yes. We can co-manage alongside your IT team or run the whole environment as a managed service — deployment, security, updates and support — so Macs just work and your team is free to focus elsewhere.

See what Jamf, run properly, feels like.

Book a 30-minute Apple Review. We’ll look at your Mac estate, show you what good looks like on Jamf, and tell you honestly whether you need us.