After purchase, Jamf will send an introduction email inviting you to set up your encryption keys. The email is sent to your designated recipient, who can be designated during the sales process.
Requirements
Jamf Standard Cloud-hosted or Jamf Premium Cloud-hosted environment
Note:BYOK is not available in Jamf Premium Cloud Plus or StateRAMP environments.
Jamf Pro 11.26.0 or later
A customer-managed key (CMK) managed by one of the following KMS providers:
Amazon Web Services (AWS) KMS
Note:AWS IAM role assumption is not supported.
Google Cloud KMS
Microsoft Azure Key Management
Thales CipherTrust Manager
- In the introduction email, click the Get Started button.
The Jamf BYOK portal will open in your web browser.
Note:Because Jamf's BYOK architecture is powered by IronCore Labs, the credentials you use to log in are separate from your Jamf Account or Jamf Pro credentials.
- Follow the instructions in Jamf's BYOK portal to set up your organization and user account.
- After logging in, click Manage Admins in the sidebar and invite additional administrators. Jamf recommends having at least three admins assigned to your organization.
Note:Optionally, you can configure a supported identity provider (IdP) for single sign-on (SSO) access to the Jamf BYOK portal.
- Click KMS Configs in the sidebar and add a KMS configuration from one of the supported KMS providers.
- After you have added your KMS configuration, click Enable Key Leasing on the associated KMS configuration card.
Take note of the KMS Config ID for use in subsequent setup steps.
- Click KMS Config Assignments in the sidebar, and then click Add Config Assignment.
- Associate the previously noted KMS Config ID to Jamf using the Organization and KMS Config ID pop-up menus.
- On the newly created Config Assignment card, click Set Primary.
- Contact your Jamf representative to complete your BYOK implementation.
After Jamf completes your BYOK implementation, your data will be encrypted using your customer-managed key.