Lesson 21: Policy Overview

Jamf 100 Course

Solution
Application
Content Type
Training Content
Utilities & Services
ft:locale
en-US

Goal

Explore Jamf Pro policies for Mac computers, including what they are, how they are created, and what makes them special.

Video

Key points

  • Policies can be run on managed computers using Jamf Pro.

  • Common management tasks available with policies include:

    • Installing software packages

    • Running scripts

    • Adding printers

  • The jamf binary is used to run policies and does not require the Apple Push Notification service (APNs).

  • One policy is configured by default in every new instance of Jamf Pro: Update Inventory.

    • This policy determines computer inventory collection frequency.

  • Policies consist of four fundamental components:

    • Content: configured payloads

    • Trigger: when the policy is configured to run

    • Execution Frequency: how often the policy runs

    • Scope: the computers/users for which the policy is configured to run

  • Policies can be configured to run automatically, made available in Jamf Self Service, or both.

  • Jamf Pro keeps logs to monitor the users/computers for which a policy has run, is pending, or has failed.

    • Flushing the most recent log entry for a user/computer allows the policy to be run again at the next trigger event.

  • Policies can be added to the Jamf Pro Dashboard, a tool that allows administrators to easily monitor the status of many policies at once.

Review

To view answers, click arrow next to each question.

  1. The four fundamental components of a policy are configured payloads, a trigger, an execution frequency, and scope.
  2. The jamf binary checks for policies on enrolled computers.
  3. Yes, a policy can be both triggered automatically and made available in Self Service.

Practice

  1. Navigate to Computers > Policies.

  2. Create a new policy.

    1. Configure the policy:

      1. Trigger: Recurring Check-in

      2. Execution Frequency: Once per Computer

      3. Scope: Deploy to a test computer enrolled in your Jamf Pro instance.

    2. Click the Maintenance payload and configure:

      1. Update Inventory: Deselected

      2. Reset Computer Names: Selected

    3. Save the policy.

  3. Verify the policy has run by checking the policy log in Jamf Pro.

Resources

Jamf 100 Course

Jamf Pro Documentation