Jamf Pro
Run your Apple fleet from chat - Jamf Pro computer and mobile inventory, MDM commands, groups, policies, patching, and secrets, with approvals pinned to the exact device.
Dex connects to Jamf Pro across both its Jamf Pro API and Classic API so admins can manage Apple devices conversationally - search computer and mobile inventory, send MDM commands like lock, restart, and lost mode, manage smart and static groups, review policies and configuration profiles, drive patching and managed software updates, and retrieve high-sensitivity secrets like FileVault keys and LAPS passwords. Destructive actions such as erase, unmanage, and delete route through their dedicated endpoints so approvals are pinned to the exact device you approved. This app is admin-only: it ships with Dex Go disabled, because the secret-retrieval endpoints are GET requests that platform guardrails do not block. MSPs can deploy Jamf Pro as a global app; per-customer isolation on a shared instance is enforced with a site-limited Jamf Pro user account, since Jamf itself is the boundary.
What Dex does with Jamf Pro
Dex handles both admin workflows and employee self-service — all policy-guardrailed and audit-logged.
For admins (Dex Pro)
- Search computer inventory with RSQL - by serial, name, user, OS version, FileVault status, Apple silicon, department, or building
- Search and view mobile device inventory (iPhone, iPad, Apple TV) across all detail sections
- Update editable computer and mobile device records - asset tag, user and location, purchasing data
- Send MDM commands (lock, restart, shut down, lost mode, inventory refresh) with approval pinned to the exact device
- Erase, unmanage, or delete a computer through their dedicated endpoints - with approval
- Manage smart and static computer group membership, reading current membership before a PUT that replaces it
- Review policies, scripts, packages, and macOS configuration profiles
- Drive patch management and create managed software update plans for OS updates - with approval
- Retrieve high-sensitivity secrets (FileVault key, Recovery Lock password, Device Lock PIN, LAPS password) on explicit request - with approval
- Redeploy the Jamf management framework to a computer that stopped responding
- List computer prestage enrollment configurations
- Deploy as an MSP global app - per-customer isolation on a shared instance uses a site-limited Jamf Pro user account
Just ask Dex
Your team types a request in plain language. Dex investigates, plans, and executes — with the right guardrails.
Admin prompts
- >Find the Mac with serial C02XY1234567 and show its OS version and last check-in
- >Which Macs have not contacted Jamf in over 30 days?
- >Send a lock command to the MacBook assigned to dlevi with a message to contact the IT desk
- >Add computer 204 to the "Finance Macs" static group
- >Who is out of date on Google Chrome according to patch reports?
- >Create a managed software update plan to install the latest minor macOS on computer 12
- >Retrieve the FileVault recovery key for the Mac named "Orchard" - confirm the device first
Policy actions
Every action Dex can take on Jamf Pro is declared, scoped, and guardrailed. Admins control which apply, who approves them, and whether they're limited to self-service.
| Action | What it does |
|---|---|
jamf_list_computers | List and search computer inventory in Jamf Pro |
jamf_view_computer | View all inventory sections for one computer |
jamf_update_computer_record | Update editable inventory fields on a computer record |
jamf_delete_computer_record | Delete a computer record from Jamf Pro |
jamf_erase_computer | Erase (wipe) a Mac via its dedicated erase endpoint |
jamf_remove_mdm_profile | Remove the MDM profile, unmanaging the computer |
jamf_redeploy_framework | Redeploy the Jamf management framework to a computer |
jamf_send_mdm_command | Send an MDM command (lock, restart, shut down, lost mode, inventory refresh). Erase must use jamf_erase_computer instead |
jamf_list_mobile_devices | List and search mobile device inventory |
jamf_view_mobile_device | View all detail sections for one mobile device |
jamf_update_mobile_device | Update editable fields on a mobile device record |
jamf_list_groups | List computer and mobile device groups |
jamf_manage_static_group_membership | Change static computer group membership (PUT replaces the whole membership) |
jamf_manage_smart_group | Change a smart computer group's criteria |
jamf_list_policies | List Jamf Pro policies |
jamf_list_scripts_packages | List scripts and packages available for deployment |
jamf_list_configuration_profiles | List macOS configuration profiles |
jamf_view_patch_status | View patch software title configurations and patch reports |
jamf_manage_patch_policy | Change a patch policy |
jamf_deploy_software_update | Create a managed software update plan for devices |
jamf_list_prestages | List computer prestage enrollment configurations |
jamf_view_filevault_key | Retrieve a computer's FileVault personal recovery key |
jamf_view_recovery_lock_password | Retrieve a computer's Recovery Lock password |
jamf_view_device_lock_pin | Retrieve a computer's Device Lock PIN |
jamf_view_laps_password | Retrieve the current LAPS local admin password for a device. Viewing rotates the password |
How to configure Jamf Pro
Onboarding takes minutes. Dex validates your credentials before saving them.
Setup steps
- 1Decide the auth mode: an API Client (Settings > System > API Roles and Clients, Jamf Pro 10.49.0+) is preferred, but cannot be limited to a Jamf Site. Use a Jamf Pro user account instead when the credential must be site-limited.
- 2For an API Client, create an API Role with the privileges Dex needs, then create an API Client bound to that role and generate its client secret (shown once).
- 3Note the bare host from your Jamf Pro URL, e.g. acme.jamfcloud.com (no https://, no trailing path).
- 4In Dex, enable the Jamf Pro integration and paste jamf_domain plus either client_id and client_secret, or username and password.
- 5Dex validates the credential with GET /api/v1/auth before saving, which reports what the token is authorized to do. For MSPs, deploy as a global app and use a site-limited user account per customer on a shared instance.
Credentials required
- jamf_domain
- Bare host from your Jamf Pro URL, e.g. acme.jamfcloud.com (no https://, no trailing path)
- client_id
- API Client ID (Settings > System > API Roles and Clients). Preferred; requires Jamf Pro 10.49.0+. Cannot be site-limited
- client_secret
- API Client secret, shown once when generated
- username
- Jamf Pro user account. Use instead of client_id/client_secret when the credential must be limited to a single Jamf Site
- password
- Password for the Jamf Pro user account
Requirements
- •A Jamf Pro instance with either an API Client (10.49.0+) or a Jamf Pro user account
- •API Role privileges matching the actions you enable - a 403 names the missing privilege, and adding a role to an existing API Client requires rotating its client secret
- •Admin-only: the app ships with Dex Go disabled because the secret-retrieval endpoints are GET requests that platform guardrails do not block
- •For MSPs on a shared Jamf Pro instance, per-customer isolation requires a site-limited Jamf Pro user account - an API Client sees the whole instance
Related integrations
- Device Management
Microsoft Intune
Manage Intune-enrolled devices, compliance, and apps from plain-language requests.
Learn more →
Device ManagementAddigy
Manage Addigy-enrolled Macs, iPhones, and iPads from plain-language requests.
Learn more →- RMM & Endpoint
Mac Device Agent
On-device diagnostics, scoped shell scripts, and APFS-aware disk forensics for macOS endpoints managed by Dex.
Learn more →
See Dex run Jamf Pro
Book a 30-minute walkthrough with our team and see how autonomous IT works in your environment — or get started for free.