Dex
Jamf Pro logo
Device Management

Jamf Pro

Run your Apple fleet from chat - Jamf Pro computer and mobile inventory, MDM commands, groups, policies, patching, and secrets, with approvals pinned to the exact device.

Dex connects to Jamf Pro across both its Jamf Pro API and Classic API so admins can manage Apple devices conversationally - search computer and mobile inventory, send MDM commands like lock, restart, and lost mode, manage smart and static groups, review policies and configuration profiles, drive patching and managed software updates, and retrieve high-sensitivity secrets like FileVault keys and LAPS passwords. Destructive actions such as erase, unmanage, and delete route through their dedicated endpoints so approvals are pinned to the exact device you approved. This app is admin-only: it ships with Dex Go disabled, because the secret-retrieval endpoints are GET requests that platform guardrails do not block. MSPs can deploy Jamf Pro as a global app; per-customer isolation on a shared instance is enforced with a site-limited Jamf Pro user account, since Jamf itself is the boundary.

What Dex does with Jamf Pro

Dex handles both admin workflows and employee self-service — all policy-guardrailed and audit-logged.

A

For admins (Dex Pro)

  • Search computer inventory with RSQL - by serial, name, user, OS version, FileVault status, Apple silicon, department, or building
  • Search and view mobile device inventory (iPhone, iPad, Apple TV) across all detail sections
  • Update editable computer and mobile device records - asset tag, user and location, purchasing data
  • Send MDM commands (lock, restart, shut down, lost mode, inventory refresh) with approval pinned to the exact device
  • Erase, unmanage, or delete a computer through their dedicated endpoints - with approval
  • Manage smart and static computer group membership, reading current membership before a PUT that replaces it
  • Review policies, scripts, packages, and macOS configuration profiles
  • Drive patch management and create managed software update plans for OS updates - with approval
  • Retrieve high-sensitivity secrets (FileVault key, Recovery Lock password, Device Lock PIN, LAPS password) on explicit request - with approval
  • Redeploy the Jamf management framework to a computer that stopped responding
  • List computer prestage enrollment configurations
  • Deploy as an MSP global app - per-customer isolation on a shared instance uses a site-limited Jamf Pro user account

Just ask Dex

Your team types a request in plain language. Dex investigates, plans, and executes — with the right guardrails.

Admin prompts

  • >Find the Mac with serial C02XY1234567 and show its OS version and last check-in
  • >Which Macs have not contacted Jamf in over 30 days?
  • >Send a lock command to the MacBook assigned to dlevi with a message to contact the IT desk
  • >Add computer 204 to the "Finance Macs" static group
  • >Who is out of date on Google Chrome according to patch reports?
  • >Create a managed software update plan to install the latest minor macOS on computer 12
  • >Retrieve the FileVault recovery key for the Mac named "Orchard" - confirm the device first

Policy actions

Every action Dex can take on Jamf Pro is declared, scoped, and guardrailed. Admins control which apply, who approves them, and whether they're limited to self-service.

ActionWhat it does
jamf_list_computersList and search computer inventory in Jamf Pro
jamf_view_computerView all inventory sections for one computer
jamf_update_computer_recordUpdate editable inventory fields on a computer record
jamf_delete_computer_recordDelete a computer record from Jamf Pro
jamf_erase_computerErase (wipe) a Mac via its dedicated erase endpoint
jamf_remove_mdm_profileRemove the MDM profile, unmanaging the computer
jamf_redeploy_frameworkRedeploy the Jamf management framework to a computer
jamf_send_mdm_commandSend an MDM command (lock, restart, shut down, lost mode, inventory refresh). Erase must use jamf_erase_computer instead
jamf_list_mobile_devicesList and search mobile device inventory
jamf_view_mobile_deviceView all detail sections for one mobile device
jamf_update_mobile_deviceUpdate editable fields on a mobile device record
jamf_list_groupsList computer and mobile device groups
jamf_manage_static_group_membershipChange static computer group membership (PUT replaces the whole membership)
jamf_manage_smart_groupChange a smart computer group's criteria
jamf_list_policiesList Jamf Pro policies
jamf_list_scripts_packagesList scripts and packages available for deployment
jamf_list_configuration_profilesList macOS configuration profiles
jamf_view_patch_statusView patch software title configurations and patch reports
jamf_manage_patch_policyChange a patch policy
jamf_deploy_software_updateCreate a managed software update plan for devices
jamf_list_prestagesList computer prestage enrollment configurations
jamf_view_filevault_keyRetrieve a computer's FileVault personal recovery key
jamf_view_recovery_lock_passwordRetrieve a computer's Recovery Lock password
jamf_view_device_lock_pinRetrieve a computer's Device Lock PIN
jamf_view_laps_passwordRetrieve the current LAPS local admin password for a device. Viewing rotates the password

How to configure Jamf Pro

Onboarding takes minutes. Dex validates your credentials before saving them.

Setup steps

  1. 1
    Decide the auth mode: an API Client (Settings > System > API Roles and Clients, Jamf Pro 10.49.0+) is preferred, but cannot be limited to a Jamf Site. Use a Jamf Pro user account instead when the credential must be site-limited.
  2. 2
    For an API Client, create an API Role with the privileges Dex needs, then create an API Client bound to that role and generate its client secret (shown once).
  3. 3
    Note the bare host from your Jamf Pro URL, e.g. acme.jamfcloud.com (no https://, no trailing path).
  4. 4
    In Dex, enable the Jamf Pro integration and paste jamf_domain plus either client_id and client_secret, or username and password.
  5. 5
    Dex validates the credential with GET /api/v1/auth before saving, which reports what the token is authorized to do. For MSPs, deploy as a global app and use a site-limited user account per customer on a shared instance.

Credentials required

jamf_domain
Bare host from your Jamf Pro URL, e.g. acme.jamfcloud.com (no https://, no trailing path)
client_id
API Client ID (Settings > System > API Roles and Clients). Preferred; requires Jamf Pro 10.49.0+. Cannot be site-limited
client_secret
API Client secret, shown once when generated
username
Jamf Pro user account. Use instead of client_id/client_secret when the credential must be limited to a single Jamf Site
password
Password for the Jamf Pro user account

Requirements

  • A Jamf Pro instance with either an API Client (10.49.0+) or a Jamf Pro user account
  • API Role privileges matching the actions you enable - a 403 names the missing privilege, and adding a role to an existing API Client requires rotating its client secret
  • Admin-only: the app ships with Dex Go disabled because the secret-retrieval endpoints are GET requests that platform guardrails do not block
  • For MSPs on a shared Jamf Pro instance, per-customer isolation requires a site-limited Jamf Pro user account - an API Client sees the whole instance

See Dex run Jamf Pro

Book a 30-minute walkthrough with our team and see how autonomous IT works in your environment — or get started for free.