Jamf Protect
Improved threat visibility has transformed how my team detects and responds to macOS attacks
What is our primary use case?
My primary use case for Jamf Protect is endpoint detection and response and threat monitoring for macOS devices. I use it to gain visibility into endpoint activity, detect malicious behavior, monitor security events, and investigate potential threats. It also helps me to enforce security policy, identify risky applications or processes, and support incident response activity. Additionally, I use Jamf Protect alongside my broader security stack to improve overall security posture and maintain compliance requirements across my macOS fleet.
A recent example of how I use Jamf Protect in my day-to-day work was during the investigation of a suspicious process execution on several managed MacBooks. Jamf Protect generated an alert for an unsigned application attempting to execute and establish outbound network connections. Using the telemetry and process visibility provided by Jamf Protect, I quickly identified the affected devices, reviewed the process tree, and determined the activity originated from unauthorized software installed by the user. I used the alert data to validate the threat, isolate the impacted endpoints through my security workflow, remove the application, and update my security policy to prevent similar installation in the future. Jamf Protect played a key role by providing real-time visibility into endpoint activity and reducing the time required to investigate and respond to the incident. On a day-to-day basis, I also use Jamf Protect to monitor security alerts, review endpoint behavior, validate compliance with security policy, and investigate any anomalous activity detected on macOS devices.
In addition to threat detection and incident investigation, I use Jamf Protect for security posture monitoring and compliance support across the macOS environment. It helps me identify potential risky behavior, monitor application activity, detect outdated software, and ensure endpoints comply with internal security standards.
What is most valuable?
The best features that Jamf Protect offers are basically real-time visibility. It gives insights into suspicious activity, attacker techniques, and helps to detect emerging threats and unusual behavior. It has behavior-based threat detection that is really helpful. Another valuable offering from Jamf Protect is integration with SIEM tools and SOAR workflows.
The behavior-based detection is particularly valuable because it focuses on suspicious activities rather than relying solely on malware signatures. In my environment, this helps me identify emerging threats, unauthorized tools, and potentially malicious behavior that traditional signature-based solutions might miss. For example, Jamf Protect can alert on unusual process execution, privilege escalation attempts, persistent mechanisms, or suspicious network connections. This gives my security team early visibility into potential threats and reduces the risk of undetected compromise.
Regarding SIEM and SOAR integration, I forward Jamf Protect telemetry and alerts into my centralized SIEM platform, which is QRadar, where they correlate the logs from EDR, identity, cloud, and network security tools. This provides a complete view of security events across the organization and helps analysts investigate incidents more efficiently. On the SOAR side, I have automated workflows to enrich alerts, assign incidents to appropriate teams, and trigger predefined responding actions.
Jamf Protect has had a very positive impact on my organization. It has improved my visibility into endpoint activity across my macOS fleet, strengthened my security detection capabilities, and reduced the time required to investigate and respond to security incidents. The centralized monitoring and integration with my security operation tools have increased operational efficiency as well. Overall, it has enhanced my security posture while allowing me to manage and secure macOS devices more effectively at scale.
What needs improvement?
Overall, Jamf Protect is a strong product, but there are a few areas where it could be improved. First, I would like to see more advanced reporting and dashboard customization options. While existing reporting is useful, having greater flexibility to build executive-level and operational dashboards would make it easier to track trends and communicate security metrics. Second, the alerting experience could be enhanced by providing more contextual information and investigative guidance directly within the alerts. Third, although the integrations are solid, out-of-the-box integration with security and IT operational platforms could be simplified to reduce the customization efforts on my end.
For how long have I used the solution?
I have been using Jamf Protect for four to five years.
What do I think about the stability of the solution?
In my experience, Jamf Protect has been very stable. Over the four to five years I have been using it, I have had few issues related to platform availability, agent reliability, or data collection. The endpoint agent has generally performed well without causing noticeable impact on system performance, which is important from both a security and end-user perspective.
What do I think about the scalability of the solution?
Since I am using a SaaS-based model, Jamf Protect's scalability has been very good in my experience. The platform is designed to support organizations ranging from small businesses to large enterprises, and I have found it capable of handling a growing number of macOS endpoints without significant operational challenges.
How are customer service and support?
In my experience, Jamf Protect's customer support has been very positive overall. The support team is knowledgeable, responsive, and generally able to resolve issues in a timely manner. When I have opened support cases, I have typically received clear guidance and useful troubleshooting steps. I also appreciate that support engineers have strong knowledge of both macOS and the Jamf ecosystem, which helps me deal with more complex deployment and security-related questions.
Which solution did I use previously and why did I switch?
Before Jamf Protect, I relied primarily on a combination of traditional endpoint security tools and native macOS security controls. While those solutions provided baseline protection, they did not offer the same level of macOS-specific visibility, behavior analytics, and threat detection capabilities. I evaluated Jamf Protect because my Mac footprint is growing, and I needed a solution that was purpose-built for Apple devices and integrated well with my existing management and security ecosystem. The main reasons I switched were improved visibility into endpoint activity, stronger macOS-focused threat detection, better integration with my security operations workflow, and the ability to gain deeper telemetry for investigation and threat hunting.
What was our ROI?
I have seen a positive return on investment from Jamf Protect, although the biggest benefits have been risk reduction and operational efficiency rather than direct headcount reduction. From a time-saving perspective, I have reduced the time required to investigate macOS security alerts by roughly 30 to 40%. Analysts can quickly access the endpoint telemetry and contextual information without manually gathering data from multiple sources.
Which other solutions did I evaluate?
I evaluated several endpoint security options before choosing Jamf Protect. The products I looked at included CrowdStrike Falcon, Microsoft Defender for Endpoint, SentinelOne, and VMware Carbon Black.
What other advice do I have?
Based on my experience, the accuracy and reliability of Jamf Protect detection are very good. The platform produces actionable alerts with sufficient context, and I have found that the majority of high-severity detections are relevant and worthy of investigation.
Jamf Protect's AI-related governance and security capabilities are solid, particularly how the platform approaches threat detection and behavior analytics. I appreciate that the platform provides transparency into the events and indicators that trigger alerts, which helps my security team validate findings and maintain confidence in the detection process. From a governance perspective, the centralized visibility, auditability, and reporting capabilities support security oversight and compliance requirements. The platform allows organizations to monitor endpoint activity consistently and maintain accountability for security events.
My advice would be to clearly define your security objectives and understand how Jamf Protect fits into your broader security strategy before deployment. The platform provides a lot of valuable telemetry and detection capabilities, so it is important to spend time tuning policies, alerts, and integration to align with your organization's risk profile. I would also recommend integrating Jamf Protect with your SIEM and incident response workflows from the beginning. Doing so allows you maximum visibility, correlates endpoint data with other security sources, and gets more value from the platform. I would rate this product an 8 out of 10.
Security for mac devices has improved and protects users from malware and ransomware
What is our primary use case?
I installed Jamf Protect on my Mac devices and set it up to protect them from malware and other issues. I use Jamf Protect in Jamf Pro as part of our antivirus solution. Jamf Protect is deployed in my organization on public cloud. We were using MS Defender before Jamf Protect. I decided to switch from MS Defender to Jamf Protect because of the Jamf Pro integration and Jamf Protect being specifically for macOS. As it is already integrated with Jamf Pro, Jamf Protect is always good for me, so I do not have any kind of recommendations for improvement.
What is most valuable?
Jamf Protect offers next-generation antivirus and Apple specific defense features. The next-generation antivirus and specific defense features of Jamf Protect get updated in real time with new issues, and then they block or look for any malicious software on the device, Trojans, or other crypto miners and protect my devices from those. We use Jamf Protect as an antivirus, so people feel secure, and we feel secure as an administrator that things are working fine on the end users and they are protected from ransomware and other kinds of malicious software.
What needs improvement?
I do not have much information about Jamf Protect's AI capabilities regarding its governance and security. I have no information about Jamf Protect's AI capabilities, including its accuracy and reliability of output.
For how long have I used the solution?
I have been using Jamf Protect for the last three to five years.
What do I think about the stability of the solution?
Jamf Protect is working fine with no downtime so far. Everything is working as intended and no issues have been found. Jamf Protect is stable.
What do I think about the scalability of the solution?
I have no information about Jamf Protect's scalability, but I am satisfied with it.
How are customer service and support?
The customer support for Jamf Protect is good. I rate the customer support for Jamf Protect a 10 because it is really good and very efficient.
Which solution did I use previously and why did I switch?
We were using MS Defender before Jamf Protect.
How was the initial setup?
With Jamf Protect it is easy to manage, so fewer employees are needed, with just one administrator managing the whole product, and it is easy to deploy and manage.
What was our ROI?
We are an MSP, so we got Jamf Protect from a vendor.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing for Jamf Protect was fine, but I am not aware of the pricing since we have a resource who manages that, while customers are happy with it.
Which other solutions did I evaluate?
I decided to switch from MS Defender to Jamf Protect because of the Jamf Pro integration and Jamf Protect being specifically for macOS.
What other advice do I have?
My advice to others looking into using Jamf Protect is that it is an easy application to deploy and easy to manage. We are all satisfied with Jamf Protect. I would rate this review a 10.
Automated Mac threat response has cut remediation time and delivers faster, safer user support
What is our primary use case?
My main use case for Jamf Protect is to provide purpose-built endpoint detection and response, antivirus, and mobile threat defense specifically for macOS and Apple devices. Jamf Protect guarantees day-one operating system upgrade and network layer threat defense while providing cellular cost savings.
What is most valuable?
The best features Jamf Protect offers include the unified endpoint security framework integration, Mac-specific behavioral analytics, integrated mobile threat defense, and web filtering.
The unified endpoint security framework integration and Mac-specific behavioral analytics help my organization because both of these features work together to solve what used to be a massive headache for our IT and security team. Mac security tools had to use kernel executions or KEXTs, which essentially provide deep system access that resides in the most sensitive layer of the operating system. If the security agent had a bug, conflict, or any error, it would cause a kernel panic, and the Mac would experience a kernel panic, which is similar to the blue screen of death in Windows, causing the user's computer to crash instantly.
Jamf Protect impacts my organization positively by creating an ecosystem that delivers a massive shift in both risk reduction and operational speed.
What needs improvement?
Jamf Protect can be improved by addressing the steep learning curve for the custom analytics engine. If I want to write a custom rule to watch for a specific or nuanced behavior in our environment, I cannot simply click a few intuitive toggles; I need to build complex logical structures using predicates or JSON formatting. If my formatting has a slight syntax error, this rule fails.
For how long have I used the solution?
I have been using Jamf Protect for about four months.
What do I think about the stability of the solution?
Jamf Protect is stable.
What do I think about the scalability of the solution?
Jamf Protect handles scalability exceptionally well. When we were working in an environment with about 2,000 Mac devices, it required almost zero extra effort from our team; Jamf Protect handles everything in a very effective manner.
How are customer service and support?
The customer support is very responsive and eager to help customers.
What was our ROI?
I have seen a return on investment because, as I mentioned before, when I receive an alert, Jamf Protect works to solve the alert. It saves a lot of time.
What's my experience with pricing, setup cost, and licensing?
I have very little experience regarding pricing, setup cost, and licensing, but I know it costs about five to six dollars per device for one month.
What other advice do I have?
A quick, specific example of how I use Jamf Protect in my environment is when a user downloads a fake update, Jamf Protect blocks the execution, and I receive an alert from Jamf Protect about the user device. Jamf Protect puts the user device in quarantine, and after that, the automated policy triggers. We can isolate the network and prompt the user to go to Jamf Self Service, and it runs the remediation script.
A specific example of metrics related to risk reduction or operational speed is that we have achieved about 80% reduction in remediation time. Before putting an automated system in place, the security alert usually meant a multi-step manual fire drill. As admins, we would get a ticket, locate the user, remote into their machine, locate the malicious files or launch the scripts, delete them, and check the system logs. This manual triage easily drains multiple hours of our time for one incident.
Regarding Jamf Protect's AI capabilities, I find its governance and security to be slightly trustworthy because the company treats that as an enterprise architecture challenge rather than simply adding a trendy chatbot to their dashboard. Jamf Protect approaches AI from two distinct angles, both handled with a strict and compliance-first mindset.
When I evaluate the accuracy and reliability of Jamf Protect's AI capabilities, specifically looking at how well it catches threats versus its false positive rate, it is useful to separate that into the main analytical engines: the zero-day network threat engine and the behavioral analytics engine. They score high on accuracy and reliability by threat detection, high accuracy via RAG and the machine learning feature, and the false positives are exceptionally low because it is a native framework advantage.
My advice for others looking into using Jamf Protect is that if they have a lot of Mac devices, they must use Jamf Protect. I give this review a rating of 10 out of 10.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Integrated Apple security has strengthened threat detection and protected our remote workforce
What is our primary use case?
My main use case for Jamf Protect is endpoint security and threat detection for Apple devices: iPad, iPhone, and Macs. We use it to monitor, detect, and respond to Mac threats.
What is most valuable?
Jamf Protect offers protection for Mac devices among its best features.
I find especially valuable aspects in threat protection, deep scans, and deep native macOS integration with Apple's own security firmware.
Jamf Protect has positively impacted my organization by reducing malware, spam, and these kinds of threats from our company. It saves time for our IT team when we deploy this, as it reduces the noise and we do not have to worry about those threats.
What needs improvement?
Jamf Protect can be improved because iOS and iPad protection is still limited compared to macOS coverage. Reporting dashboards need more customization, and third-party SIEM integration can be complex to configure. There is no Windows or Android support, so expanding to Windows on that side would be beneficial.
Regarding needed improvements, support should be enhanced, as well as integration with iPad and iOS. Additionally, if Jamf Protect could support Android, that would be beneficial.
For how long have I used the solution?
I have been using Jamf Protect for five to six years.
What do I think about the stability of the solution?
Jamf Protect is stable.
What do I think about the scalability of the solution?
The scalability of Jamf Protect is good.
How are customer service and support?
Customer support from Jamf Protect is good.
Which solution did I use previously and why did I switch?
We did not use a previous solution; we still use different solutions such as CrowdStrike, Defender, and SentinelOne.
How was the initial setup?
Jamf Protect is deployed in my organization as a SaaS-based portal.
I would describe the ease of integration of Jamf Protect with our existing IT infrastructure as very easy, since Jamf Protect integration with Jamf is very natively supported.
What was our ROI?
I have not seen a return on investment because I do not have metrics.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing is positive. Per-device annual licensing is acceptable, depending on your volume. The setup cost is low, depending on whether you deploy it via Jamf distributor or automatically.
Which other solutions did I evaluate?
We did evaluate other options before choosing Jamf Protect. Those were CrowdStrike Falcon for Mac, SentinelOne, Defender, and Kandji. We chose Jamf Protect because it was a native Apple ecosystem fit.
What other advice do I have?
The features I would add to Jamf Protect include scanning, endpoint security, real-time behavioral threat detection, and seamless sync with Jamf Pro for device management.
Regarding the accuracy and reliability of output from Jamf Protect's AI capabilities, I find it good.
The user interface and user experience of Jamf Protect are great. It is simple and has everything you need. Sometimes you have to navigate through multiple menus, but it is acceptable as long as you find the right information.
Jamf Protect handles updates and maintenance seamlessly.
Jamf Protect helps us meet compliance requirements because you can set up policies and procedures in Jamf portal. You can apply configuration profiles, and using Jamf Protect, you can protect yourself effectively.
Jamf Protect supports remote work and distributed teams because it is mainly used for security, such as malware detection and policy violation monitoring across the Apple fleet, which secures the remote workforce.
Jamf Protect has impacted our incident response times positively, making it faster. The response and detection is faster when you have something which is natively supported compared to other antivirus solutions.
Regarding cost and value, we have used other solutions, but we normally use Jamf Protect with Jamf Pro product, so it is bundled. The price is different, and as it is a native product of Jamf, it has better integration, better response, and better threat analysis. This is why we always prefer that combination.
My advice to others looking into using Jamf Protect is that it is best suited for organizations already using Jamf Pro. If you are using Jamf Pro, the combined Pro plus Protect stack is extremely powerful. However, if you have a mixed environment with both Windows and Mac devices, you should consider pairing Jamf Protect with CrowdStrike or another Windows coverage solution alongside Jamf for Apple devices, so you can match your needs appropriately.
I would rate this product eight out of ten.
Security monitoring has protected our school devices and supports proactive threat response
What is our primary use case?
I work at a school and I'm managing the entire school with Jamf Protect, so we're managing about 1,000 plus computers, and I'm in the IT department.
What is most valuable?
The features I find most valuable in Jamf Protect are amazing because any malware or any viruses can harm the entire fleet. Jamf Protect takes action and protects against any alerts, and we are safe from any viruses and any attacks from the entire world.
The real-time monitoring of Jamf Protect has helped to identify threats swiftly as this morning I just got about 200 alerts from ChatGPT. Recently, they announced that they have some revokes, and fortunately, Jamf Protect was able to detect this threat and take action immediately, blocking the ones that would harm the machine and alerting us for those that have warnings.
I assess Jamf Protect's endpoint telemetry data as enhancing our threat detection process a lot because without Jamf Protect, we would be unsafe at all.
I use Jamf Protect's advanced analytics to get reports about future threats and any malware detections coming in the tech field, so it helps me analyze and see if we need to be more protective and apply more rules to the clients to be safer.
I assess the integration with Jamf Pro for improving security policy enforcement as great because the reports I'm getting from Jamf Protect help me take action in Jamf Pro.
Jamf Protect's compliance automation has helped us adhere to industry standards, as for our standards, it matches very well. I have tailored some of the policies and rules based on the environments we are in, but in general, it's very compliant for our environment.
What needs improvement?
I think Jamf Protect can be improved because I submitted a report this morning about some features I want to get for Jamf Protect, so it will be more enhanced. The AI capability is still in the beginning stage, so it would be better to enhance the AI capability and the AI assistance within Jamf Protect to take more actions and control it more.
I think they could improve their technical support because sometimes for emergency needs, I require one-to-one support and can't wait even 24 hours to resolve my issue. Some cases require immediate action, so it's not always available with direct technical support. However, with the reseller, I set appointments, meet with them, and work with them directly, which resolves the issue.
I would like to see additional features in the next release to make it even better, including enhancements to AI capabilities and quicker technical support. We have a minor number of Windows computers, about 60, and if they could manage those, that would be awesome. It would be great to manage them through the Jamf Protect product and have everything in one platform as they are currently isolated from management.
For how long have I used the solution?
I have been working with Jamf Protect for four years now.
How are customer service and support?
I would rate their technical support as a 9 because I am actually working with a reseller in South Africa who is amazing and helps me a lot. My experience with direct technical support is good as far as sending a support ticket, but online support is not always available.
How was the initial setup?
My initial setup of Jamf Protect was straightforward because we started with a piloting group and then moved to deploy to the entire school.
What about the implementation team?
For the deployment of Jamf Protect, it was just me and the tech support, but I had the computer service department to help with any issues raised. On my side, I pushed the package from Jamf Pro to the entire fleet, and any issues can be handled by the computer service department, so it wasn't complicated.
What was our ROI?
I have not seen return on investment since our school is a nonprofit organization, but from the security perspective, I have. If you imagine you have 1,000 computers to protect, if any harm happened to these 1,000 computers, that is an ROI because it would damage our assets, affect our environment, and impact the budget as well.
What's my experience with pricing, setup cost, and licensing?
Regarding the current pricing, we just got a quotation for next year, actually, and it's the same as last year. There's no increase, but I still know the price is high, and it's worth the investment.
Which other solutions did I evaluate?
I think Jamf Protect is the best option on the market thus far for the Mac ecosystem. If we were in another ecosystem like Windows, I don't think Jamf Protect would work since it doesn't actually work in the Windows environment.
What other advice do I have?
The implementation took just one month, and then we started getting information and taking more actions from that information, which was completely missed, so it was quite an addition to our security layer at school.
I purchased Jamf Protect directly from the reseller called Onsite.
I would rate this product overall as a 9.
Granular telemetry has strengthened compliance and simplified USB control for large Mac fleets
What is our primary use case?
I initially started using Jamf Protect for telemetry and auditing purposes. However, because we have other DLP products and antivirus in our organization, we have slowly and gradually started using a few more features of Jamf Protect, including DLP, which has made the process much smoother. The earlier process of DLP was quite complex in our environment, but since we started using Jamf Protect, it has become much easier for us to use those features that were very complex before. The first example I can give you is using a third-party USB. Previously, whitelisting the USB in our environment was a significant challenge because we are a large organization with approximately 10,000 Macs. Every now and then, people come to us saying they need a specific USB to work for a client. Since we started using Jamf Protect, that has become quite easy for us to handle. There are other compliance features that we are trying to use. I have just completed my certification with Jamf Protect, so we are trying to implement some compliance features using Jamf Protect. However, as of now, we are using very limited features of Jamf Protect.
What is most valuable?
Jamf Protect offers good telemetry and auditing capabilities. We can use Jamf Protect for auditing purposes and for meeting our minimum compliance requirements. We can also use Jamf Protect for whitelisting USB devices. The one limitation is that you cannot replace the antivirus completely with Jamf Protect, so you cannot consider it as a complete antivirus solution. However, you can use a few features of Jamf Protect.
We use Jamf Protect for telemetry and auditing because we collect telemetry data and hand it over to the security team. Regarding how beneficial it is, the security team has said that the previous application we were using for auditing and telemetry did not provide data that was as granular. I do not audit anything myself because I am in the engineering part. However, the security team has been continuously saying that the data we get from Jamf Protect is quite granular and quite helpful. After using Jamf Protect, they have been able to put many restrictions in place that they previously thought were not necessary. They have come to us asking whether we can implement this feature or that feature into the process. There were many things that we were previously allowing, thinking they would not cause any issues in the environment. However, using the data from Jamf Protect, they came to the conclusion that certain features could be a big issue in the coming days or could be a threat. They have asked us to stop those features on the Mac. I am not sure about the specifics of how they are using the data because there is a specific security team that manages all of these details.
If some other organization is using Jamf Pro, they should definitely go for Jamf Protect. That will streamline many things for them.
What needs improvement?
The first thing I would like to improve is Jamf's technical assessment on any product. When we were talking with Jamf about Jamf Protect features, they were not able to share all the features with us completely at that time. This was the first time I was involved in this type of conversation, and there is an architect in my team who normally takes care of these matters, but he had other things to do, so I was involved. I had to invest a lot of time going back and forth to understand what features of Jamf Protect we could use. I would say that Jamf should come up with a very clear picture of what all features we can use. Since we are an old customer of Jamf, they should be aware that these features are not being used in the environment and they should come to us and tell us how those features can be beneficial for us.
I would just want Jamf Protect to be included in Jamf Pro, the same way compliance and blueprints have been included. I do not want to go into three different portals. For Jamf Connect, I have to go to a different portal. For analytics, there is another portal, radar.vandera.com, which is also related to Jamf Protect analytics. I have to go to that portal for analytics. Jamf Protect and Radar portal are both connected, but I just want them to streamline everything into Jamf Pro so I can use one portal for everything rather than going to three or four different portals.
For how long have I used the solution?
I have been using this solution for about one and a half years.
What do I think about the stability of the solution?
I would say it was good. Initially, we had a few issues when we started our alpha testing on Jamf Protect. For some reason, it was causing a lot of CPU usage. Generally, it should hardly take any CPU usage and must be at zero CPU usage about ninety to ninety-five percent of the time. However, in the alpha phase, we found out that it was taking twenty to thirty percent of CPU usage, and in some of the Macs, it was taking even more than seventy percent of CPU usage. We had a discussion with Jamf about that, and Jamf helped us resolve it. Since then we have conducted two pilot phases and we have not had any issues. The integration was very good. I would not say it was excellent, but it was very good, though not excellent.
How are customer service and support?
The customer service rating is four out of ten.
Which solution did I use previously and why did I switch?
I have not been working with MetaDefender. I think someone took me wrong in a previous conversation. I have been working with Defender for quite long, about three to three and a half years. However, I have not worked on any Meta products. I have worked with Microsoft Defender, not MetaDefender.
How was the initial setup?
The initial setup was not complex; it was simple.
What other advice do I have?
Jamf Protect and Radar portal are both connected, and I would just want them to streamline everything into Jamf Pro so I can use one portal for everything rather than going to three or four different portals.
We have a very large number of client-facing Mac users, and we cannot simply put something on their Mac. We have to be very conscious when we start using any security stack in our environment. When we get rid of any security stack in our environment, we need to put it in a very clear picture to the leadership explaining why we are doing it and what impact it will have, as well as how beneficial it will be for the users. We have gotten rid of a few things in the past and it was very difficult for us to remove those applications. That is why using all the features of Jamf Protect instantly in our environment is a bit difficult, but we have slowly and gradually shifted a few things to Jamf Protect. The first thing is using USB. We will obviously include analytics in the coming time, but as of now, we are not using it.
We are using three Jamf products: Jamf Protect, Jamf Connect, and Jamf Pro. I would rate this review an eight out of ten.
Security platform has reduced malware risk and has strengthened compliance for macOS endpoints
What is our primary use case?
I have been using Jamf Protect for four years and have utilized it for Apple assets to protect against threats and suspicious activity.
Jamf Protect provides multiple levels of telemetry collection, allowing me to select how sensitive I want to be on event triggers. Jamf Protect allows me to monitor against specific threat categories aligned to the MITRE ATT&CK framework. In addition to protection, I utilize Jamf Protect to monitor our endpoint compliance with the CIS critical security control baseline.
If the environment is predominantly Apple based, Jamf Protect is a strong solution for providing EDR capabilities to endpoints. The detection capabilities are on par with other leading EDR tools, and it integrates well with Jamf MDM. The compliance telemetry, log forwarding, and USB device management included as part of Jamf Protect provide a good return on investment.
I use Jamf Protect as our main security endpoint for all our macOS devices, which are Apple devices. It was very easy to implement by following Jamf's documentation, and our security team is very happy with how it monitors threats. The compliance feature is also very useful to them, and it constantly helps them monitor and ensure our devices comply with our security policies.
What is most valuable?
Jamf Protect provides multiple levels of telemetry collection, allowing me to select how sensitive I want to be on event triggers. Jamf Protect allows me to monitor against specific threat categories aligned to the MITRE ATT&CK framework. In addition to protection, I utilize Jamf Protect to monitor our endpoint compliance with the CIS critical security control baseline.
If the environment is predominantly Apple based, Jamf Protect is a strong solution for providing EDR capabilities to endpoints. The detection capabilities are on par with other leading EDR tools, and it integrates well with Jamf MDM. The compliance telemetry, log forwarding, and USB device management included as part of Jamf Protect provide a good return on investment.
Jamf Protect has had a positive impact on my organization, as it has been one of the best tools that protects against malware. It offers better detection of malware, reducing downtime and risk to our network by approximately 30 to 50 percent. Implementing it is straightforward, although there can be a steep learning curve in general, especially for less technical users. The competitive pricing included in the business package is great, and compliance with our security standards has been maintained.
What needs improvement?
To improve Jamf Protect, I suggest enhancing the end user onboarding user experience, expanding out-of-the-box support for additional SIEMs, and noting that the user interface takes some getting used to. More inline instruction prompts for new admins would also be beneficial.
For how long have I used the solution?
I have been using Jamf Protect for four years and have utilized it for Apple assets to protect against threats and suspicious activity.
What do I think about the stability of the solution?
Jamf Protect is very stable, and I have not seen any downtime.
What do I think about the scalability of the solution?
Jamf Protect is very scalable, enabling me to manage a large number of devices seamlessly and easily.
How are customer service and support?
The customer support is very proactive, helpful, and knowledgeable.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I previously used Microsoft Defender for Endpoint.
I switched from Microsoft Defender for Endpoint to Jamf Protect because I find that Microsoft Defender for Endpoint has the same features; however, Jamf Protect is specifically tailored for managing macOS devices. With Jamf Protect, it is one license that covers all features without requiring additional licenses for features such as USB device control, making it very cost-effective.
How was the initial setup?
It is easy to implement and easy to manage.
It was very easy to implement by following Jamf's documentation, and our security team is very happy with how it monitors threats.
What was our ROI?
The compliance telemetry, log forwarding, and USB device management included as part of Jamf Protect provide a good return on investment.
What's my experience with pricing, setup cost, and licensing?
The pricing, setup cost, and licensing have been very effective.
Jamf Protect includes a number of features that other EDR solutions charge additional fees for, such as compliance and device control. It has helped us lower the cost per endpoint compared to other EDR solutions, and it is easy to manage since it is centrally managed with strong integration with Jamf MDM.
Which other solutions did I evaluate?
I evaluated other options before choosing Jamf Protect, specifically CrowdStrike Falcon.
What other advice do I have?
My advice to others looking into using Jamf Protect is that it is easy to manage and offers a separate interface from Jamf MDM, which is beneficial for security operations teams. It allows security teams to manage only the security aspects without having to navigate through all the MDM configurations, saving a lot of time. Additionally, if your environment is predominantly Apple or macOS based, Jamf Protect is a strong solution for providing EDR capabilities to endpoints. I would rate this solution an 8 out of 10.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Secure access to company sites has protected our devices and now runs quietly in the background
What is our primary use case?
My main use case for Jamf Protect at my organization is that we use it for VPN to access company websites through VPN. A specific example of how we use Jamf Protect for VPN access is that my organization uses it to secure the MacBook devices that have been provided to us. When we were signing up for this, we received our laptop devices and with the initial setup, Jamf Protect was configured to avoid breaching any sensitive information.
What is most valuable?
The best features Jamf Protect offers, in my opinion, is that the one we are using currently is excellent for helping secure the devices, but other than that, I do not have any idea of what other features Jamf Protect offers.
I am confident that Jamf Protect has impacted my organization positively because we have been using it for quite a while now. Since I joined this company recently, I have not noticed any security-related changes. Regarding productivity and peace of mind, I do not see much work around this, so I would say that Jamf Protect is doing an excellent job securing the devices.
I can think of having a general sense that Jamf Protect makes me and my team feel more secure because I have not noticed or seen any security-related breaches with me or with any of my other colleagues.
What needs improvement?
Regarding improvements for Jamf Protect, I receive the warnings related to insecure website accesses through mail at a later stage, so if they could be flagged the moment I visit them, that would be great because I would know exactly which website was causing the warnings.
Regarding how Jamf Protect communicates these alerts, I think it is useful as it is now, the way they inform us through emails. However, when I use this office device to access some personal websites, I do not receive any alert at that time and later on in the evening when I am checking my emails, I receive this email from Jamf Protect saying that there was a website I accessed which had a threat level of medium or minor. At that time, I do not know which website caused this, so it would be more helpful if the device itself could flag it at the point when I access the website. Other than that, I think it is still useful because it is mostly company-related activities and there are very few personal websites, so I can still identify the suspects.
For how long have I used the solution?
I have been using Jamf Protect since I joined my last company. We use this for VPNs and VPN connections.
What do I think about the stability of the solution?
In my experience, Jamf Protect is very stable right now, and I have not faced any issues related to it to date.
What do I think about the scalability of the solution?
I believe Jamf Protect's scalability is effective because we have been using it in our organization since the start, and our numbers have recently risen by a large amount, so we are still using it.
How are customer service and support?
I have not faced any issues with Jamf Protect, so I have no feedback on customer support from my or my team's experience.
How was the initial setup?
A specific example of how we use Jamf Protect for VPN access is that my organization uses it to secure the MacBook devices that have been provided to us. When we were signing up for this, we received our laptop devices and with the initial setup, Jamf Protect was configured to avoid breaching any sensitive information.
What other advice do I have?
My advice for others looking into using Jamf Protect is that it is an excellent tool to use to secure your devices, so I would recommend moving forward with it.
I give Jamf Protect a rating of eight out of ten. I gave it an eight out of ten because it is working behind the scenes, and I do not have any data as a client, so that might be related to authorization accesses since I am just a Level 3 employee at my company. The senior folks or the security folks might be having more detailed access to that, and apart from that, the shortcoming regarding the warnings received through emails is another point. Regarding our relationship with this vendor, my company is just a customer, and we do not have a business relationship other than that. My overall review rating for Jamf Protect is eight out of ten.
Experience agile user-centric security with AI-powered endpoint protection
What is our primary use case?
I use Jamf Protect for myself, especially for POC demonstration purposes. It is also used as part of our consultation services, where I recommend it to customers.
How has it helped my organization?
Jamf Protect gives you Apple built-in native support for endpoint security. It supports zero-day protection in the Apple ecosystem and is agile, user-centric, and lightweight for macOS.
What is most valuable?
The behavioral detection is valuable. It also includes built-in network protection that is powered by our AI called Medium. It provides telemetry and signature-based detection, which offer comprehensive endpoint security.
What needs improvement?
For how long have I used the solution?
I have been using it for the last four years.
How are customer service and support?
The technical support is good and proactive. That said, it can be improved. There is some scope to enhance the response and resolution time. From an Indian perspective, I would rate their support at seven point five out of ten.
Which solution did I use previously and why did I switch?
I have an understanding of CrowdStrike and certain security solutions from Forcepoint.
What other advice do I have?
I would recommend inbuilt remediation for behavior-based threats and less dependency on third-party tools.
I'd rate the solution eight out of ten.
Effective device management, enhance threat detection and smooth integration
What is our primary use case?
Jamf Protect manages all Apple devices, deploys and upgrades applications, and enforces security features like blocking data transfers and improving security profiles.
How has it helped my organization?
Compliance is ensured through encryption, like with DEP.
Jamf Protect adapted to evolving security threats specific to macOS. We integrated with Microsoft Defender for added protection.
Compared to on-premises solutions, there are a lot of features improved in cloud-based solutions. The performance after implementation is better than with on-premises solutions.
Integration is also easy. Nothing complex about it. I never found any issues with it.
What is most valuable?
Jamf Protect's most effective features for threat detection include managing devices and applications, deploying and upgrading the OS, and its overall security features.
We can block data transfer and manage other security aspects through profiles.
What needs improvement?
Beginners need initial training and have basic/essential knowledge.
For how long have I used the solution?
I used it for five years. I moved to the cloud version two years ago. Before that, it was on-premises. It was Jamf's own cloud (private cloud).
What do I think about the stability of the solution?
I would rate the stability a ten out of ten.
What do I think about the scalability of the solution?
I would rate the scalability a ten out of ten.
How are customer service and support?
The customer service and support are good.
How was the initial setup?
I would rate my experience with the initial setup a ten out of ten, with ten being easy.
Initially, the deployment took 15 days for the pilot phase, and then another 15 days for production. However, the actual deployment itself only took 15 days, as it was preconfigured.
So it took around one month in total. Stakeholder approval caused a delay, but the actual deployment for the facility department was only 15 days.
No maintenance is required because everything is associated. It's a cloud solution, so we only need to modify applications for the services.
So, 99.9% of the time, it's working fine.
What was our ROI?
There are many financial benefits because everything is managed in a single cloud for Apple devices, with no need for third-party software.
What other advice do I have?
Everything is working well for me; it also supports single sign-on. Jamf Protect is very good and excellent.
Overall, I would rate the solution a ten out of ten. I would recommend it to other users. Beginners should have basic knowledge. If they have normal, basic knowledge, they can use the resources provided with the solution.