Why the device management solution you choose matters

When searching for a device management solution for the first time or evaluating your current tool for a potential upgrade, you often get pulled in multiple directions with vendors shouting:

  • “Look over here! We can manage ALL of your platforms with one solution.”
  • “But we’re the cheapest and our tool is good enough to get the job done.”
  • “Wait! Don’t go with them! Why? Well, just because.”

It can be hard to wade through the noise and nonsense to determine which management solution is best for your unique needs.

At Jamf, we want you to succeed with the ecosystem you choose — be it Apple, Microsoft or Google — with the management solution you ultimately select (even if it’s not us). While we obviously want you to choose Jamf, we most importantly want you to be fully informed prior to making any decision. So begins our tutorial on device management philosophies…

Unified endpoint management (UEM) 101

When all of your ecosystems are managed with one tool, this is often referred to as unified endpoint management or UEM. On the surface, the idea of having one solution to tackle any device that hits your network can be appealing.

The problem, and what UEM providers won’t tell you, is that there is such a lack of commonalities in how Apple, Microsoft and Google are intended to be managed that the end result is a lackluster experience for IT and their users.

If the chart is hard to understand, it can’t be easy to manage.

With each ecosystem having its own method of deployment, operating system release cycle, security features and overall device management style — just to name a few — a UEM approach prohibits IT from delivering a seamless and timely technology experience that modern users demand.

Less is not always more

The old adage that “you get what you pay for” tends to hold true in the realm of device management solutions. With a seemingly new vendor popping up daily to undercut the price of the last flavor of the week, it can be difficult to look at the long-term as opposed to an enticing upfront cost.

When considering going this route, ask yourself:

  • Does this vendor have a proven record of support operating system releases and features when they become available?
  • If something goes wrong, do they have a reliable support staff who can assist?
  • Can this company and its solution scale as our needs and environment change?
  • Will this company be around in one, two, five years and there when I need them?

Purchasing software to help you get the most out of your hardware is a big decision and one that shouldn’t be done hastily.

But you already knew that. And now you’re asking yourself, “I’m reading the Jamf blog, where does the best-of-breed argument come in?”

Very perceptive. Yes, we’ve arrived at the point where we discuss the best-of-breed management model and the one Jamf is known for.

Best-of-breed management solutions

Where UEM and dime store tools fall short, best-of-breed solutions reign supreme. By providing full lifecycle management, Jamf’s best-of-breed Apple management solutions are the only way to maximize, streamline and automate:

Deployment and provisioning to build the perfect device for users through a zero-touch, hands-free enrollment process.

Configuration management by leveraging configuration profiles, policies and scripts to customize and personalize each device.

App management to purchase apps in bulk and distribute them directly to a device or make readily available in an on-demand app store.

Inventory so you can collect hardware, software and security configuration details, and take immediate management action as a result.

Security by leveraging native Apple features to restrict malicious software and patch out-of-date devices.

For a much more thorough dive on how best-of-breed solutions differentiate themselves from others and what specific features Jamf offers, download the best-of-breed guide of your choosing.

 

What about Microsoft best-of-breed?

Ah, of course. The other major player in the modern landscape. While Apple has gained significant traction in the enterprise, many organizations will still need to support Windows PCs. To accommodate these organizations, Jamf Pro integrates with Microsoft’s best-of-breed Windows management solution, Intune, to deliver the answer to the challenge of cross-platform management.

This integration provides an automated compliance management solution for Macs accessing applications set up with Azure Active Directory. Through the industry’s only proxy-free conditional access, this partnership ensures that only trusted users, from compliant Mac computers using approved apps are accessing Office 365 and other cloud and on-premises resources.

Microsoft enables Jamf to report Mac information to Intune and provide a simple process to remediate non-compliant devices.

For traditional environments, Jamf offers a plug-in for Microsoft’s Systems Center Configuration Manager (SCCM) — providing a seamless path to work with modern and traditional Microsoft tools.

The management decision is yours

Hopefully this provides insight into the management model that makes the most sense for your organization, staff and users — in the short and long-term.

I’ll leave you with one additional thought. Jamf has been around for over 15 years and been exclusively focused on helping organizations succeed with Apple. This isn’t just a hobby or way to make a quick buck — this is what we pride ourselves on.

With more than 16,000 customers managing over 10 million devices, our best-of-breed model has worked to the tune of a 95 percent customer retention rate. Long story short: when customers choose Jamf, they join a rapidly growing community of Apple experts — and don’t leave.

If you’re interested, we offer a free, no strings attached trial of our best-of-breed solution so you can put our features to the test. Ready?


What is Apple Business Manager?

Whether you are an IT professional or have the task of maintaining your office’s technology, you know that having the ability to enroll devices and purchase applications in volume can feel like a life saver. Chances are, if you have found yourself here, you’re working with Apple devices in your business and may have heard about Apple Business Manager. Let’s take a look at what Apple Business Manager is, a little bit about the change and why you should strongly consider using it to help make your everyday device management tasks easier, faster and more simplified.

What is Apple Business Manager and why was it made?

Apple Business Manager is Apple’s newest way for IT teams and businesses to automate their device deployment, app deployment and purchasing, and content distribution while working seamlessly with a mobile device management (MDM) solution. At this point, some of you may be thinking, “Doesn’t Apple already have a Volume Purchasing Program (VPP) and a Device Enrollment Program (DEP)?” Yes, they do! Apple Business Manager combines the power of DEP and VPP in one consolidated service to allow you to automatically deploy Mac, iPad, iPhone and Apple TV devices directly to users — configured with settings, security controls, apps and books. For a deeper dive, check out our blog on why DEP and VPP gave way to Apple business Manager.

As mentioned, Apple Business Manager helps you quickly and easily deploy your Apple devices to employees, automatically enroll them within Jamf without physically touching or prepping each device, simplify your setup and onboarding process, as well as get more out of your MDM. Apple Business Manager also allows you to create Managed Apple IDs, a special account type that allows you to share your Apple Business Manager account with others in your organization.

What does that mean for you, the user?

You have a few options as you consider how to approach Apple Business Manager. First, if your organization is already enrolled in Apple’s deployment programs (formerly called VPP and DEP), you are able to use your existing tokens until they expire.

Apple has made it clear that Apple Business Manager is the best platform for businesses using their products going forward. The migration to Apple Business Manager is free, fast and easy. Head to deploy.apple.com to begin your migration. Once complete, your new Apple Business Manager account will show your server tokens and other associated content.

Note: Once you make the upgrade to Apple Business Manager, you will no longer have access to the Apple deployment program website.

If you are starting from scratch, enrolling into Apple Business Manager program is also relatively quick and easy. Any business is eligible to enroll in Apple Business Manager at business.apple.com. To get started, you will need to complete the online enrollment process by providing information including name, phone number and a valid D-U-N-S number for your company.

Once you are a part of the program and have downloaded your Apple Business Manager tokens, you are able to upload these tokens into your Jamf account by simply following the onscreen instructions.

Having the ability to enroll devices and manage the content that you have bought in volume all from the same portal location is going to streamline the amount of time you spend enabling your employees to perform at their best.

Depending on your needs, Jamf offers two solutions to help you integrate with Apple Business Manager and start managing your fleet of Apple devices today.

 


Program or be programmed

The future is uncertain. This has always been true, but those words resonate more than ever. The influence of digital technology is moving the goalposts every day, affecting the nature of future employment. According to the Institute for the Future, 85% of jobs in 2030 don't yet exist today. Perhaps it's not that dramatic, but it certainly does make one think.

To flourish in this future, people need to be both creative and technical. Some call this embracing our reflexive nature: a

Lulu Burger, Director of Education, Onsite Group.

recognition that no solution is perfect and that everything develops iteratively. This is very true for technology and skills such as programming, and robotics are the perfect ways to empower learners, says Lulu Burger, Director of Education at Onsite Group.

"Robotics is not as much a ‘subject' as it leads to the practising of essential skills for students when going into the technological world we live in. The principles of creating, building, coding and seeing the results of your efforts are essential to the skillset our students need."

Those skills are important for the future, but not only for employment. Interacting with robots and other digital innovations will be part and parcel of our future lives, so even a basic understanding of the principles involved will be very useful. Imagine how much easier and more affordable your car maintenance would have been if a simple class explained the basics of your vehicle. Robots, programming and all the associated skills are the cornerstones of tomorrow's society – and the learners who aren't introduced to these will be poorer without them.

"It is important for schools and parents to realise that all jobs will contain elements of robotics. These days there are more and more robotics clubs run as an extramural activity in schools. Alternatively, the IT teacher will incorporate coding and robotics into their computer lessons. The concept behind STEAM (Science, Technology, Engineering, Arts and Mathematics) lies within a cross-curricular approach to teaching where the traditional silos are challenged, and students use creative problem-solving techniques to "hack" real world problems. Robotics sits very comfortably inside STEAM as an enabler of the best solutions. For example, students solving an environmental challenge might create, build and code an application to solve the problem."

Most parents and teachers appreciate the importance of such knowledge. The tougher problem is making it a reality by introducing robotics into learning environments. Though there are robot clubs, apps and other means, few cater properly for learning environments and different skill levels within a group.

In the future, we will either program or be programmed.

 


Technology and education: Why outsourcing IT makes sense

Technology holds a lot of promise for education. Learners can access information faster, teachers can interact more easily with their pupils and a world of new educational tools and sources have become available for classes of all levels.

"IT in modern schools have really migrated from old servers and static PC labs to a more cloud-based mobile environment," says

Lulu Burger, Director of Education, Onsite Group.

Lulu Burger, Director of Education at the Onsite Group. "Google Classroom is a perfect example of a very effective workflow between teachers and students. It leads to students being able to access information at any time and teachers being able to provide students with immediate feedback and curated resources. There are fantastic online assessment tools and of course educational video content that enhances learning. If the internet speeds are not fast enough, students miss out on 21st-century learning."

These ideas are a far cry from the staid computer science classrooms with rows of antiquated machines. Yet many schools don't believe they are capable of affording new technologies, despite the many advantages. Some also feel burned by the march of technology - for example, digital textbooks on tablets have not been popular for a variety of reasons. More common is the grudge against technology's delays: slow speeds and unresponsive services drain valuable teaching time and add to the frustrations of keeping the attention of today's pupils.

The need for technology in education

Burger agrees that these problems are valid, serious, and need to be addressed, but noted that not participating in the technology revolution is not really a choice:

"Information Technology has become the driver of a lot of learning that happens in schools. The skill of navigating the internet, creative content creation, spotting fake news and just doing research on-line has become a critical part of learning and teaching."

This has been adding to the pressure for change: "The move towards students bringing their own tablets have forced schools to relook their internet, firewalls and the workflow between teachers and students. IT Infrastructure and internet speed is blamed often for the loss of teaching time because of the slowness or it not working at all."

Managing technology costs

Technology in schools often falls short because there isn't enough focus on it, usually because of lack of training for teachers and budget concerns. But these problems can be addressed organically by using the norms of managed technology services, a very popular choice among small and medium businesses. Even simple steps in modernisation can help open budgets around technology, said Burger:

"Yes, technology is expensive, but if a school cut down on their printing, for example, those funds could be used to get proper IT infrastructure installed and managed. Schools spend between R200 000 – R700 000 per year on printing. Once your workflow is working, printing will become less and the maintenance of the printers and ink will also be reduced. Think about your budget and allocate enough funds towards IT infrastructure and training prior to even considering rolling out student owned mobile devices."

Local schools that have matured their digital pedigree are taking full advantage of this, running everything from administration to class lists and timetables through a central digital platform. This is made possible with modern software platforms, which do not require the same type of up-front cost ownership as traditional software, and the expertise of managed service providers.

In the managed service models, schools don't keep a permanent IT department on staff. Instead this responsibility goes to an IT provider such as Onsite, which then works within the budgets and service requirements of the school. Other than being a boon for cost savings, it also gives the school access to the insights and skills of the service provider. So a school no longer has to ask why its network is slow - it can simply expect it to work and hold the managed services provider to account if it does not.

Managed Services vs Outsourcing

Managed services is not outsourcing. It takes care of the operational burdens but leaves the school firmly in charge and able to benefit deeply from the relationship. An external service provider of this sort should consult with the school first, map out a phased plan and then implement. Training your teachers is the most important part of any technology roll-out, Burger explains:

"I believe that there is not enough emphasis on teacher training. The teachers are the ‘gatekeepers' to technology innovation in schools and if they are not supported, very little will change. The importance of phasing technology and innovation into a school will fail if there is no effective professional development for the teaching staff."

Unfortunately schools miss sight of all these other advantages and drive IT purely as a cost centre. The result is often paying the cheapest price for an under-qualified reseller that simply installs equipment - and often does so badly. When there are problems, the reseller simply charges more.

Managed services is entirely different. It does not simply sell technology, but instead looks at the school's requirements, then designs a way forward that the school and provider walk together. The absolute value of this reflects in lower costs. Managed service providers are also always on call, ready to act, and don't simply swing by once a week for a mandatory site visit.

It's an approach that can be scaled based on the institution, public and private, regardless of where their current IT level is. Schools can start small, gain quick wins and build their technology pedigree.

"It is really important to get educational experts in to plan, structure and install your IT infrastructure," Burger concluded. "Information Technology is used extensively to speed up administrative processes and in making communication more effective between all parties involved. All of these need to be managed and maintained properly and continuously as a lot of what the school is about is now driven by technology. But it shouldn't cost a fortune. Once schools realise they can think beyond cost paradigms, all kinds of doors open up both for them and the future of their students."


Jamf Now or Jamf Pro: Which is right for you?

by Daniel Weber

You may know Jamf as the standard for Apple device management. If not, very nice to meet you.

With Mac, iPad, iPhone and Apple TV devices becoming commonplace in organizations, hospitals and schools around the globe, many are discovering that a purpose-built Apple management solution is necessary to accomplish their goals with Apple.

Any of this sound familiar?

  • We purchased Macs, now how do we get the right stuff on them for our employees?
  • How can I turn my iPad into a point-of-sale terminal?
  • How do I ensure students’ privacy is protected when using education technology?
  • Can my staff get the resources they need without bugging IT every time?

Yeah, you need management.

Since expertise, goals, requirements and scenarios vary, we didn’t want to shoehorn you in to one management solution. So, we created two distinct tools — both of which will always support Apple releases and features on day one — to address your unique needs: Jamf Now and Jamf Pro.

Who is Jamf Now for?

Most commonly used by small to mid-sized businesses, Jamf Now is streamlined Apple device management; no IT required. When IT is not your day job, or you have a more simplified environment, Jamf Now is for you.

What do the “basics” get you?

For starters, here’s what you won’t get: a sales pitch, software training or product documentation. There’s no need! We’ve designed Jamf Now so that you can, well, start now. Jamf Now walks you through every stage of your account creation to ensure you have all the necessary pieces in place to start managing devices. Tailor-made for small to medium-sized organizations, Jamf Now helps you:

Setup: Enroll devices into Jamf Now via user-initiated enrollment or zero-touch through Apple’s Device Enrollment Program (DEP) — now part of Apple Business Manager. Once enrolled, configure Wi-Fi, email, calendar and contacts, and set basic iOS restrictions on your devices. You can enjoy ongoing device customization by leveraging a Jamf Now Blueprint. Create multiple Blueprints to define settings and apps, then deploy a Blueprint to a device or set of devices. For example, XYZ organizations can use the XYZ blueprint to automatically apply settings 1, 2 and 3, along with the most commonly used apps.

Inventory: Keep track of device settings and details by viewing inventory status within Jamf Now or by exporting inventory reports to spreadsheets to demonstrate compliance.

Manage: Jamf Now can help you purchase Volume Purchase Program (VPP) apps and centrally deploy them to the appropriate devices. VPP is now part of Apple Business Manager, as well. Single App Mode through Jamf Now allows you to lock your iOS device to a single app, turning it into a point-of-sale or kiosk in retail locations.

Protect: Require that a passcode be on all Jamf Now enrolled devices and enforce native Apple security features such as FileVault 2 for Mac. If a device is lost or missing, disable and locate and/or remotely lock and wipe to ensure the device, user and data remain secure.

Who is Jamf Pro for?

Organizations that have scaled beyond basic Apple device management, and need a more robust tool to help manage employee or student devices turn to Jamf Pro. When you have a dedicated IT admin or team, you require enterprise-level features and functionality. Jamf Pro offers everything Jamf Now does and so much more in the form of:

Deployment: Aside from offering zero-touch deployment to provision the perfect Apple device right out of the box, Jamf Pro also integrates with Apple School Manager or Apple Configurator — allowing you to truly choose the manner in which you enroll Apple devices. If you already have Macs on your network (or think you do), Jamf Pro provides a network scan to identify any unmanaged Macs. Once located, quickly enroll the devices into management. For traditional environments that are not yet leveraging zero-touch enrollment, macOS imaging tools are available to help these organizations meet their deployment needs.

Inventory: When default inventory collection is not enough, Jamf Pro empowers you to build Smart Groups based on inventory criteria without using complex query language. Smart Groups update every time a device checks into Jamf Pro, so they’re always up to date. Group membership can trigger policies for automated management actions or be used in reports. Reports can be run on any inventory category (and even make a dashboard view for instant report visibility) to make informed business decisions and demonstrate compliance. If a device falls out of compliance, get an alert so you can take swift action.

Device management: Go beyond basic configuration profiles and use policies and scripts to truly customize your devices. Want to modify account permissions? No problem! Need to have a custom script run every time a user logs in? Easy! No macOS or iOS restriction is off limits. Run custom scripts and advanced configuration profiles to open the door for infinite device management capabilities. Plus, Jamf Pro provides full Apple TV support, so you can manage them just like an iPhone or iPad.

App management: Looking to develop your own in-house apps or leverage apps outside of Apple’s App Store, such as Adobe Creative Suite? Jamf Pro is for you. With Jamf Pro, you can purchase App Store apps in bulk using Apple’s deployment programs, pre-configure App Store, third-party or In-house apps, and distribute them in the manner of your choosing.

Self Service: Create your own custom app catalog and offer tier-zero self-help tools to users — all without them ever submitting a help ticket. You load Jamf Self Service with resources, content and trusted apps, and users access them on demand. To encourage adoption, brand Self Service with your banner, logo or dock icon.

Security: Beyond enforcing native Apple security settings to restrict malicious software and protect personal and corporate data, Jamf Pro gives you the tools to secure VPN configuration, manage local macOS accounts and administer management privileges at a granular level. Manage FileVault and Gatekeeper settings, block specific software from running, enforce restrictions – like disabling the camera or iCloud — and even manage kernel extensions all with Jamf Pro.

Patch management: Software and data breaches often start by attacking out-of-date software. To combat this vulnerability, Jamf Pro offers patch management functionality to identify and automatically deploy software and OS patches to eligible computers and bring them into compliance. You define user interactions and set deadlines to update. Jamf Pro is the only solution with automated patch alerts for third-party apps built right into the platform. No other tool allows you to identify, package, distribute and report on patches the way Jamf Pro does.

Integrations: Leverage your existing tools and seamlessly integrate Jamf Pro with the management tools, network access controllers, and other IT services and technologies you already have. If you utilize Apple deployment programs, Active Directory, Single Sign-on, Microsoft System Center Configuration Manager (SCCM), Microsoft Intune, Cisco ISE (and many more), Jamf Pro can pair with it. From cross-industry integrations to specific solutions, visit the Jamf Marketplace to see the 200+ providers Jamf Pro integrates with.

Services: To ensure success, all sales of Jamf Pro include new customer primer sessions and a personal training and implementation engagement. Through remote and on-site sessions, you’re equipped with the tools necessary to immediately begin implementing solutions to the challenges you face in the ever-evolving Apple ecosystem. Following your initial engagement, Premium Services are available to focus on your priorities in the form of enhanced workflow design, implementation strategies, security management and much more.

Support: When you purchase Jamf Pro, you join a customer community and have access to a team of experts versed in Jamf and Apple technology. Support is available via chat, email or phone during business hours, and there’s no max number of support cases you can create. Premium Support is also available should you desire round-the-clock support, priority escalation, product issue reports and a dedicated Jamf expert.

Training: Basic, intermediate and expert level training courses are offered to provide Jamf Pro customers with hands-on experience and in-person access to Jamf and Apple experts.

Still not sure which is right for you?

Don’t worry, with 96 percent of Jamf Pro customers renewing their contracts every year, you can’t go wrong. And you’ve really got nothing to lose by trying our solutions, because hey, they’re free to test drive. As an added bonus, the first three devices with Jamf Now are always free.

Let us help you get the most out of your Apple devices. It’s what we do best.

 


Privacy Preference Center