Skip to main content

Connecting Vanta & Jamf Pro

S
Written by Shannon DeLange
Updated in the last hour

Connecting Vanta & Jamf Pro

  • Open Integrations from the left-hand navigation panel

  • Search for Jamf Pro in the Available tab

  • Select Connect

  • Log in to your Jamf Pro administrator account

    • Note: We do not currently support using Okta SSO to log into Jamf Pro during this step

  • Select the settings icon, and choose User accounts and groups

Screenshot 2023-09-26 at 4.49.56 PM.png
  • Create a new user that meets Vanta’s requirements

    • Username: We recommend vanta_service_user to help you remember its relation to Vanta

    • Access Level: Full access

      • Note: We also support Site Access and Group Access, allowing Vanta to have access only to specific Jamf objects belonging to a site. However, Users with Site Access cannot fetch Jamf accounts for Vanta access-related workflows. Proceed with this option if you do not wish to monitor Jamf account access in Vanta.

      • Please note that only workspace domains can utilize site scoping. An alternative for non-workspace domains is to use the VantaNoAlert group, a special group for removing computers from scoping.

    • Privilege Set: Custom

unnamed (1).png
  • Hold on to the username/password– you’ll need to add them to Vanta

  • Navigate to Privileges and grant the following read-only privileges

    • If you selected Full Access:

      • User accounts and groups

      • Computers

      • macOS Configuration Profiles

    • If you selected Site Access:

      • Computers

      • macOS Configuration Profiles

  • Fill in the remaining details with your full name, email address, and password. Remember to save the password.

  • Return to Vanta

  • Enter the credentials for this account and your *.jamfcloud.com domain into the Vanta connections flow.

  • Select Validate credentials

  • You will receive either a confirmation that the credentials are configured correctly or an error message explaining how they’re misconfigured.

  • Please remember that Machines not managed by Jamf Pro should still use the Vanta Device Monitor

  • Currently, Vanta does not support the on-prem deployment of Jamf Pro.

  • Currently, Vanta does not support Jamf Now or Jamf Business

  • Currently, Vanta only supports integrating one Jamf instance at a time.

Controlling Scope through Jamf Pro

Vanta’s Jamf integration enables you to control which computers and accounts should be automatically marked in and out of scope in Vanta by creating and managing Vanta groups within Jamf.

  • Log in to Jamf Pro and click Settings in the left sidebar

  • Navigate to Network followed by Sites.

  • Click the New button at the top right corner to create a site for scoping accounts and computers, both within and outside of Vanta. The name should start with 'Vanta' followed by any text, e.g., 'Vanta Employees'.

  • Assign the group in Vanta to the desired accounts and computers. For more detailed instructions, visit the Jamf Pro product documentation.

For Workspace customers, please visit Control Scope with Jamf for Workspace.