Blueprints - Jamf Pro Blueprints Configuration Guide

Jamf Pro Blueprints Configuration Guide

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US
Important:

This capability requires logging in to Jamf Pro using OIDC-based single sign-on (SSO) configured in Jamf Account. If you do not have an OIDC identity provider (IdP), Jamf ID is available as an SSO option. For more information, see SSO with OIDC Through Jamf Account in the Jamf Pro Documentation.

Blueprints simplify the creation of complex workflows by leveraging declarative device management to ensure devices meet a particular management state. You can use blueprints to scope management settings to devices using customizable components that include payloads and their configurable settings, all in one location. Using declarative device management enables devices to proactively and autonomously apply the scoped management settings and report state changes to the MDM server asynchronously, streamlining the device management workflow.

Jamf provides two options for creating blueprints:
Quick start templates

The Quick start tab provides popular, predefined templates that you can configure.

For example, you can use the Set passcode policies template to create a blueprint that contains passcode policy settings. Then, you can deploy the blueprint to computers and mobile devices in a smart group or static group at the same time.

Blueprint builder

The blueprint builder allows you to create more complex blueprints by selecting various components from a component library. You can organize components into component blocks and configure the settings for each component. Each block can have its own activation condition, which controls when the components in that block activate on a device.

For example, you can create a blueprint to control access to network storage using the Disk management policy component, while also customizing the calculator settings using the Math settings component. In the same blueprint, you can also include a configuration profile payload. You can organize these components into separate blocks to activate under different conditions. For more information, see Scope and Activation Conditions in Blueprints.

When a blueprint is deployed, declaration objects are created and a Declarative Management command is queued for target devices to sync new or modified declarations. The target devices will install the declaration configuration, and the declaration is activated immediately.