Jamf, run the way
Apple intended.
ParityFox designs, migrates, deploys and operates Jamf across Mac, iPhone and iPad — Jamf Pro, Connect, Protect and School — as a project when you need one, and as a standing engineering function when you need that instead.
Macs arrive in the enterprise the way they arrive anywhere: someone senior asks for one, then a designer, then a whole engineering team. By the time anyone treats them as a fleet there are two hundred of them, no consistent build, and a Windows-shaped policy set half of them quietly ignore.
Jamf exists because Apple management is genuinely different. It follows Apple's own frameworks — declarative device management, Apple Business Manager, supervised enrollment — rather than approximating them, and supports new features the week they ship. We treat it as an operational platform, not an enrollment exercise: packaging, patch cadence, identity and compliance all decay when nobody owns them, and a Mac estate degrades quietly.
Part of managed operations, alongside Microsoft Intune for the Windows estate.
Jamf consulting
and architecture.
We review the Jamf environment you have, or design the one you do not. Both start from the same question: what should a Mac at this company actually be?
Current-state assessment
A structured read of the instance: smart group logic, policy inventory, patch state, and the gap between what is scoped and what actually installed.
- Instance and licence review
- Policy and smart group inventory
- Patch and macOS version compliance
Scoping architecture
Most Jamf estates fail on scoping, not settings. Overlapping groups, policies scoped to All Computers because it was quicker, no way to predict what a change touches.
- Smart and static group design
- Scoping and exclusion strategy
- Naming and change standards
Enrollment and identity
Which path each population takes, what supervision it carries, and how the Mac account ties back to your cloud directory.
- Apple Business Manager and ADE
- BYOD and supervision boundaries
- Jamf Connect, Entra ID or Okta
From unopened box
to working Mac.
A device ships from Apple or the reseller straight to the person using it. They sign in with their work identity, and everything else arrives on its own. No imaging, no build bench, no laptops routed via an office first.
Instance and foundation
Jamf Pro set up properly at the start: Apple Business Manager linked, push certificates and their renewal dates recorded, groups and standards defined.
- Instance configuration
- Apple Business Manager integration
- APNs certificate tracking
Zero-touch deployment
Automated Device Enrollment with a PreStage that sets supervision, account type and the Setup Assistant panes a user actually sees, so a new Mac is productive at first login.
- ADE and PreStage configuration
- Setup Assistant customisation
- FileVault at first login
Configuration and Self Service
Profiles for Wi-Fi, VPN, certificates and the privacy controls macOS now requires — plus a Self Service catalogue that makes the sanctioned route the easy one.
- Configuration profiles and PPPC
- Software update policy
- Self Service catalogue
Move to Jamf
without re-imaging.
Apple migrations carry a constraint Windows migrations do not: you usually cannot re-enroll a Mac without the user's cooperation, and on older devices you may not be able to supervise it at all without a wipe. That single fact shapes the plan.
So we sequence around it — discovery, a pilot that genuinely represents the estate, then waves scheduled so the awkward cases are handled deliberately rather than discovered late. We do not translate an old policy set line for line: much of any mature Mac estate is enforcing something macOS now does natively.
- Unmanaged Macs to Jamf
- The common case: a real fleet that grew without anyone deciding it was one.
- Intune to Jamf for Apple
- Where Apple-specific depth has become the constraint, usually with Intune retained for Windows.
- Other MDM to Jamf
- Kandji, Mosyle, Workspace ONE and legacy platforms, with re-enrollment planned around users.
- Jamf instance consolidation
- Multiple instances from acquisitions or departments merged into one governed estate.
- On-premise to Jamf Cloud
- Self-hosted instances migrated, with the upgrade and certificate burden handed back to Jamf.
- Imaging to zero-touch
- Retiring the build bench and the golden image in favour of Automated Device Enrollment.
Application packaging
and patch cadence.
The most operationally repetitive work in Apple management, and the most visible when it slips. It suits specialist delivery precisely because it never stops.
Packaging
Applications packaged for Jamf delivery, signed and notarised where required, with install logic that behaves the same on the two hundredth Mac as the first.
- PKG and DMG packaging
- Signing and notarisation
- Volume Purchasing apps
Patch management
Third-party applications tracked and updated on a defined cadence rather than whenever someone notices, with test rings ahead of broad release.
- Third-party patch policies
- Test rings and validation
- Patch compliance reporting
OS updates and scripting
macOS and iOS releases managed with declarative software update and deferral windows, plus extension attributes and remediation scripts for the recurring faults.
- Declarative software updates
- Major upgrade readiness
- Extension attributes and scripts
Managed Jamf
operations.
Jamf should not become another console someone opens when a ticket arrives. Run properly it is a standing engineering function: something in the estate changes every week, and most of it should be noticed before a user notices it.
Daily operations
Enrollment, policy and profile administration, Self Service updates and the steady flow of change requests — routine work rather than escalations.
- Enrollment and re-enrollment
- Policy and profile changes
- Smart group and scoping changes
Patch and update cycle
Third-party patching and OS updates driven on a cadence, with test rings ahead of broad release and reporting on what actually landed.
- Third-party patch cycle
- macOS and iOS updates
- Compliance reporting
Certificates and renewals
The APNs certificate and Apple Business Manager tokens all expire, and each one silently breaks part of the estate. We renew them before that happens.
- APNs certificate renewal
- ADE and VPP token renewal
- Jamf Pro version upgrades
Escalation and investigation
L2 and L3 engineering for what a service desk cannot close: policies that will not run, profiles that will not install, faults tied to specific hardware or OS versions.
- Failed policy investigation
- Enrollment and check-in failures
- Jamf support case handling
Fully managed
We own the platform end to end and report against it.
Co-managed
Your team keeps ownership; we take the engineering depth and the escalations.
Project-based
A defined piece of work — an assessment, a migration, a zero-touch rollout — with a defined end.
Capacity
Named engineers working inside your delivery model, for a fixed period or an open one.
Managed is not
the same as secure.
An enrolled Mac is an inventoried Mac. It is not necessarily an encrypted one, a patched one, or one whose access you could revoke this afternoon. Those are separate decisions, and plenty of estates have quietly made none of them.
The pieces fit in order. Jamf Pro enforces configuration and reports device state. Jamf Connect ties the local account to cloud identity, so a leaver loses their Mac login. Jamf Protect watches behaviour on macOS using Apple's own security framework. Your identity provider consumes the compliance signal and decides what the session reaches.
- Jamf Pro
- Enforces configuration and reports what the device actually is.
- Jamf Connect
- Binds the local Mac account to cloud identity, at the login window.
- Jamf Protect
- Behavioural detection and telemetry, built on Apple's endpoint security framework.
- Microsoft Entra ID or Okta
- Establishes user identity and holds the access policy.
- FileVault
- Full-disk encryption, with recovery keys escrowed and actually retrievable.
Four products.
Different jobs.
Jamf is a family, not a single thing, and the licensing conversation goes better when you know which parts you actually need. Most estates need one of these. Some need three.
Jamf Pro
The core platform, and what people mean when they say Jamf. Enrollment, configuration, packaging, patching, inventory and Self Service across Mac, iPhone and iPad.
- Device management and configuration
- Application packaging and patching
- Inventory and reporting
Jamf Connect
Identity at the login window. The Mac account is provisioned from and stays in step with your cloud directory, so passwords do not drift and a leaver's access ends where it should.
- Cloud-identity account provisioning
- Password sync with Entra ID or Okta
- Single sign-on to company resources
Jamf Protect
Endpoint security built for macOS on Apple's own security framework rather than a ported Windows agent — which is why it tends not to cost the performance users notice.
- Behavioural threat detection
- Endpoint telemetry and visibility
- Compliance monitoring (CIS benchmarks)
Jamf School and Jamf Now
The lighter products. Jamf School for education with classroom and shared iPad workflows; Jamf Now for small estates that need management without a full Jamf Pro practice.
- Jamf School for education
- Shared iPad and classroom workflows
- Jamf Now for small estates
We will tell you plainly when you do not need a product. Plenty of estates buy Protect before they have finished configuring Pro properly, which is the wrong order and an expensive way to feel secure.
Jamf or Intune?
Often both.
We run both practices, so we have no stake in the answer. This is rarely an either-or, and organisations that force it into one usually regret the direction they picked.
Intune manages Apple devices competently, and if your estate is mostly Windows with a modest number of Macs, a second platform is a cost with no obvious return. Jamf earns its licence when Apple is a first-class part of the estate — macOS feature currency, packaging built for the platform, and Self Service instead of telling Mac users to file tickets.
The arrangement we deploy most often is neither: Intune for Windows, Jamf for Apple, both feeding compliance into Microsoft Entra ID so Conditional Access sees one signal. Two management planes, one access policy.
The other half of this is our Microsoft Intune practice.
- Mostly Windows, few Macs
- Intune. A second platform is hard to justify until Apple is a real population.
- Apple as a first-class platform
- Jamf. Feature currency, packaging depth and Self Service start paying for themselves.
- Mixed estate at scale
- Both, with compliance from each feeding one Conditional Access policy in Entra ID.
- Design and creative teams
- Jamf, usually. This population notices management friction faster than any other.
- Education
- Jamf School, for the classroom and shared iPad workflows Intune does not attempt.
Jamf delivery for
technology partners.
Need Apple capacity without hiring for it?
We work behind MSPs, consulting firms, IT service providers and system integrators as specialist engineering capacity — inside your delivery model, your process and your customer relationship. The work carries your name.
Apple is the gap in most partner benches. It is a narrow enough discipline that a dedicated hire is hard to justify before the pipeline exists, and different enough from Windows that a capable generalist will lose days to problems a Mac specialist has already seen.
Project engineering
Implementation and migration delivery on your customer engagements — architecture through to cutover, working to your plan or helping you build one.
- Implementation and migration
- Customer assessments
- Zero-touch rollouts
Ongoing capacity
BAU Jamf administration and L2/L3 escalation for estates you hold the contract on, staffed by named engineers rather than a ticket queue.
- BAU administration
- L2 and L3 escalation
- Packaging at volume
Documentation and handover
Every engagement ends with your team able to run what we built. Documentation and a handover session are deliverables, not favours.
- As-built documentation
- Runbooks and procedures
- Knowledge transfer
- NDA first. We sign before scope, not after.
- Your customer relationship stays yours. We do not approach, market to, or contract with your customers — during an engagement or after it.
- Partner-led communication by default. We join customer calls as your team when you want us there, and stay off them when you do not.
- Customer confidentiality maintained across engagements, with access scoped to what the work requires.
- Capacity that flexes — a short project, a named engineer for a quarter, or a standing allocation.
Assess. Design.
Implement. Operate.
The same four movements as every ParityFox engagement, applied to Apple. Nothing gets built before somebody has explained what is already there.
Assess
Understand the estate as it is — devices, enrollment state, policies, identity, applications and who currently owns which part of it. Findings before recommendations.
Design
Architecture, scoping standards, enrollment paths, security baselines and the migration approach: written down, reviewed with you, and agreed before anything moves.
Implement
Pilot, validate, then deploy in waves. Every wave has an exit condition, and re-enrollment is scheduled around users rather than sprung on them.
Operate
Patch, package, renew, remediate and review. The estate keeps changing, and Apple ships a major release every year, so the engineering does not stop at go-live.
Frequently
asked.
What Jamf services does ParityFox provide?
Can ParityFox manage an existing Jamf environment?
Do you migrate from another MDM to Jamf?
Should we use Jamf or Microsoft Intune?
Do you work with Jamf Connect and Jamf Protect?
Can you set up zero-touch deployment?
Do you support Jamf School or Jamf Now?
Do you provide Jamf engineers to MSPs or technology partners?
Need your Apple estate run properly?
A first real Mac deployment, a migration you would rather not run alone, a patch backlog you have been carrying for months, or an estate that needs someone to own it. Tell us what you run and what is hurting — a senior engineer replies, not a sales script.
Talk to our Jamf teamNeed additional Jamf delivery capacity?
Specialist Apple engineering behind your customer relationship — project delivery, BAU administration, packaging at volume, or L2/L3 depth. Under NDA, inside your delivery model, under your name.
Discuss a partner engagement