Jamf Trust for Windows supports all available Jamf Connect and Jamf Protect capabilities that are administered using the Jamf Security Cloud portal.
To distribute the app to Windows devices via a UEM or MDM solutions, you must obtain and run an MSI file:
Download the latest version of the Jamf Trust from Jamf Account.
Run the file. The installer automatically performs the following steps:
Creates a folder and install files in:
C:\Program Files\JamfTrust.Creates a folder and install files in
C:\ProgramData\JamfTrust.Installs and registers a Jamf Trust Windows Service.
Adds a Jamf Trust task bar icon as the main access point.
Keep the following in mind when distributing Jamf Trust to Windows:
Jamf recommends that you configure Windows to support Split-Horizon DNS or Proxy before you distribute Jamf Trust because the app reads the file once when the app starts. If you configure one of these options after installation, you must restart the app apply the configuration.
For more information, see the following:
If a Windows app or service with a blocked hostname is added to a device, traffic to the app or service will be blocked but the hosted block page will not be displayed. To enable the page, you must create a custom rule for the new app or service.
If you plan to support multi-user device enrollment, only the first user enrollment per device will be managed. Additional users on the same device will appear as Unmanaged in Jamf Security Cloud and will not include complete profile data. For devices that require shared enrollment, such as sharing the device's data limit, include the
SHARED_ENROLLMENT=trueparameter during installation.
The Secure DNS feature is not available with Jamf Trust for Windows on all web browsers, including Google Chrome, Mozilla Firefox, and Microsoft Edge.
security.enterprise_roots.enabled to accept Jamf's root certificate using one of the following methods:You can change the policy manually. For instructions, see Setting Up Certificate Authorities (CAs) in Firefox.
If you use Microsoft Intune, you can change the policy using the OMA-URI ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~Certificates/Certificates_ImportEnterpriseRoots. For instructions, see Managing Firefox with Microsoft Endpoint Manager (Intune).
If you use another UEM solution, you can change the policy with policy.json. For instructions, see mozilla / policy-templates (GitHub).