Konfirmity
Jamf logo

Secure your Jamf surface

macOS fleet posture, FileVault coverage, and the Macs your MDM has never enrolled. We don’t connect to Jamf to collect evidence for its own sake — we connect to secure it, and the compliance artefacts follow from that work.

Book a Demo

[01] What This Surface Exposes

Where Jamf goes wrong

Jamf goes wrong at the edges of the fleet: the Mac it has never enrolled is the one that matters, and it does not appear in any Jamf report.

  • Devices without FileVault enabled, or with escrowed recovery keys missing
  • Macs running OS versions past Apple's effective security support window
  • Configuration profiles removed locally, silently undoing your baseline
  • Devices assigned to users who have since left
  • Machines in the directory but never enrolled in Jamf at all

[02] What We Secure

What we watch, catch and fix on Jamf

On Jamf we measure encryption coverage against your whole device population, not just the devices Jamf already knows about.

  • Encryption coverage measured against your full device population, not just enrolled devices
  • OS currency tracked against Apple's real support behaviour rather than nominal version numbers
  • Profile drift detected when a baseline is removed on-device
  • Device-to-user binding reconciled with your HR record so leaver hardware is recovered
  • Unenrolled device discovery, because the machine your MDM cannot see is the one that matters

[03] Where It Lands

Where Jamf lands in your registers

Every managed device becomes an asset register entry with its owner, encryption state, and OS currency. Access reviews cover the accounts bound to it, and the risk register carries what an unpatched or unencrypted endpoint actually exposes given the data that person handles. The gap that matters most is the device your MDM has never seen — we reconcile against your directory and HR record to find it.

[04] How We Engage

On Jamf specifically

On Jamf, we push configuration profiles, enforce encryption, and drive OS updates through your rings. Hardware recovery from leavers and re-enrolment of unmanaged machines we project-manage with your IT team.

Platform licence

Everything you need to find and fix it yourself, with no ceiling on the depth of the answer.

  • Every connected tool monitored for misconfiguration and drift, with findings mapped to the assets and risks they affect
  • Remediation guidance that tells you what is wrong and exactly how to fix it — however deep or awkward the issue is. We are engineers running a security company, so the answer is the real one, not a link to vendor documentation
  • Assets, access reviews, and risk register populated from the tools themselves rather than from spreadsheets
  • Unlimited integrations and unlimited users, with anything missing built within two weeks

Managed service

Every tool you connect through Konfirmity comes under our care, with our team doing the work.

  • Continuous misconfiguration and drift monitoring across every connected tool, watched by our analysts rather than by a dashboard waiting for you
  • Incident response led by us, with containment coordinated with your team
  • Remediation performed directly wherever you have granted us the authority to act — and where we cannot act, we project-manage the fix to completion rather than handing you a ticket
  • Decision support on the tools themselves: where something is failing you on capability or costing more than it returns, we will tell you, and help you replace it

[05] Jamf FAQs

What Jamf access does Konfirmity need?

Konfirmity needs a read-only API account with privileges to read computer inventory, configuration profiles and policies. That covers posture, FileVault state and profile drift. We do not need the ability to push policies unless you ask us to remediate directly.

How do you find Macs that Jamf has never seen?

By reconciling Jamf's inventory against your identity provider and HR record rather than trusting it as complete. A device that authenticates to Okta or Google Workspace but appears nowhere in Jamf is unmanaged, and that gap is invisible if you only look inside the MDM.

[06] Related Integrations

Other endpoint & device tools we secure:

View all integrations