You can install theJamf Trust app for Windows to enroll devices with Jamf Safe Internet.
The Windows app uses a client-side agent that syncs with the Safe Internet cloud infrastructure. The client's web protection policy configurations and mobile usage reports are provided entirely within Safe Internet.
If a Windows app or service with a blocked hostname is added to a device, traffic to the app or service will be blocked but the hosted block page will not be displayed. To enable the page, you must create a custom rule for the new app or service.
Sufficient hardware specifications (CPU and memory) to run Windows and associated software
Location permissions to allow for location based policy, if necessary per policy
Date and time set automatically by Windows
To install Jamf Trust on a Windows device, you must use a Unified Endpoint Management (UEM) solution or a similar package to install the app using the MSI installer.
Download the latest version of the Jamf Trust from Jamf Account.
Run the file. The installer automatically performs the following steps:
Creates a folder and install files in:
C:\Program Files\JamfTrust.Creates a folder and install files in
C:\ProgramData\JamfTrust.Installs and registers a Jamf Trust Windows Service.
Adds a Jamf Trust taskbar icon as the main access point.
After Jamf Trust is installed, a task bar icon for the app is created.
When the app is launched, if the activation was successful, "Active" will appear in the upper-left corner of the window. Click Network to display a status screen of technical information about policy and current configuration.
The device will also appear as "Active" in the Safe Internet portal.
Jamf Trust for Windows is unable to secure your device when Secure DNS is enabled on a web browser, including Google Chrome, Mozilla Firefox, and Microsoft Edge. Disable Secure DNS in your web browser to prevent unexpected issues with Jamf Trust.
security.enterprise_roots.enabled to accept Jamf's root certificate using one of the following methods:You can change the policy manually. For instructions, see Setting Up Certificate Authorities (CAs) in Firefox.
If you use Microsoft Intune, you can change the policy using the OMA-URI ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~Certificates/Certificates_ImportEnterpriseRoots. For instructions, see Managing Firefox with Microsoft Intune.
If you use another UEM solution, you can change the policy with policy.json. For instructions, see mozilla / policy-templates (GitHub).