# Jamf

## Overview

Cisco Identity Intelligence can read user and device information from Jamf to determine management status and other security information about your organization's devices to provide additional visibility.

The goal of this document is to serve as a guide to set up a data integration between Identity Intelligence and your organization's Jamf environment.

### JAMF Data Integration

### Permission requirements

You will need the Admin role in Jamf to add the necessary configuration in Jamf, you will need the Admin role.

### Jamf Pro Configuration Steps

1. Login to Jamf using your Admin account and navigate to **Settings** > **System**
2. &#x20;Select **API roles and clients**&#x20;

<figure><img src="https://582105988-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FqPSBzsjxd7KYg9DNVZ4l%2Fuploads%2FR4GeuMib47LgPQLpxBDV%2Fimage.png?alt=media&#x26;token=e5209bf6-f8b5-49a1-b6fa-656f84d6ca09" alt=""><figcaption></figcaption></figure>

3. Create a new API role with the following permissions: \
   `Read Mobile Devices`                                                                                                                      `Read Computers`                           &#x20;

Add the following permissions to enable Device Lockout functionality:                                                         `Send Computer Remote Lock Command`\
`Send MDM command information in Jamf Pro API`\
`View MDM command information in Jamf Pro API`

<figure><img src="https://582105988-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FqPSBzsjxd7KYg9DNVZ4l%2Fuploads%2FyBozdZ4F31OVNnMRwZ7i%2Fimage.png?alt=media&#x26;token=7de5ee80-bd01-4816-b0fb-56f293542ef6" alt=""><figcaption></figcaption></figure>

4. Once the new role is created, navigate back to the **API roles and clients** page and create a new client using the role you configured in Step 3

<figure><img src="https://582105988-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FqPSBzsjxd7KYg9DNVZ4l%2Fuploads%2F2KSxRcp1dxNRIaWeMH0l%2Fimage.png?alt=media&#x26;token=bda15937-3ba3-41f0-b7d8-cd6cc1e0491e" alt=""><figcaption></figcaption></figure>

5. Copy the **Client ID** and **Client Secret** for later use in Identity Intelligence&#x20;

### Identity Intelligence Configuration Steps

1. Login to your Identity Intelligence tenant and navigate to the **Integrations** menu item in the left hand navigation bar
2. Select **Add Integration**
3. Select **Jamf**
4. Enter your desired display name, your **Jamf Instance URL** (ex: `https://foo.jamfcloud.com`), and the Jamf **Client ID** and **Client Secret** referenced above in Step 5
5. Select **Save**&#x20;
