JAMF logo

JAMF

AccessPeopleVulnerabilities
Device Management (MDM)

Mycroft reports FileVault encryption, screen lock, patch level and enrolment coverage across your Apple fleet.

Endpoint controls have to cover the whole fleet rather than a sample, and laptops move and get replaced. Mycroft reads Jamf inventory per device and reconciles assignment against the HR roster to surface devices still held by former staff.

How Mycroft connects to Jamf

How it connects
You create an API client in Jamf for Mycroft, which authorizes with client credentials against the Jamf API gateway for your region.
What Mycroft can access
Read-only inventory. Mycroft reads device and user records and does not issue management commands, lock or wipe devices.

Which controls Jamf evidence maps to

Each row is a control an auditor tests and the specific artifact Mycroft collects from Jamf to satisfy it. Collection runs on a schedule and every result is timestamped.

JAMF compliance control mappings and the evidence Mycroft collects for each
FrameworkControlWhat it requiresEvidence collected from Jamf
SOC 2CC6.7Information is protected during storage and on removable media and endpoints.FileVault encryption status for every enrolled Mac, with unencrypted devices listed by name and assigned user.
SOC 2CC6.1Logical access controls restrict access to information assets.Screen lock timeout, password complexity and automatic login settings enforced through configuration profiles, reported per device.
SOC 2CC6.8Controls prevent and detect unauthorized or malicious software.Endpoint protection and firewall state per device, plus installed application inventory for detecting unapproved software.
SOC 2CC7.1Vulnerabilities are identified through monitoring.OS and application version inventory measured against current releases, with patch lag per device and time-to-remediate tracked.
ISO 27001A.8.1User endpoint devices are protected.Enrollment coverage across the fleet, with the configuration baseline applied and any device outside management identified.
ISO 27001A.8.7Protection against malware is implemented.Endpoint protection deployment and status per device, with gaps reported by assigned user.
ISO 27001A.8.8Technical vulnerabilities are managed.OS patch level per device against current releases, with the age of each outstanding update.
ISO 27001A.5.11Assets are returned on termination of employment.Device assignment reconciled against the HR roster, surfacing devices still assigned to departed staff.
HIPAA§164.310(d)(1)Device and media controls govern hardware handling and disposal.Full device inventory with assignment, enrollment status and encryption state, plus records of wiped or retired devices.
HIPAA§164.312(a)(2)(iii)Automatic logoff terminates sessions after inactivity.Screen lock and inactivity timeout settings enforced by configuration profile, reported per device.

What Mycroft collects automatically

Gathered from Jamf on a schedule, dated and stored against the controls above.

  • Full device inventory with model, serial, OS version and assigned user
  • FileVault encryption status per Mac, with unencrypted devices identified
  • Screen lock timeout, password policy and automatic login configuration
  • Firewall and endpoint protection status per device
  • OS and application patch level with lag measured against current releases
  • Enrollment coverage, identifying company devices outside management
  • Configuration profile assignment showing which baseline each device received
  • Device assignment reconciled against the HR roster for asset return evidence

Manual work this removes

The tasks that disappear from someone's quarter once Jamf is connected.

  • Screenshotting the Jamf console at audit time
  • Confirming FileVault status with employees individually
  • Maintaining a spreadsheet of which employee holds which laptop
  • Identifying devices that were not returned after a departure
  • Checking OS versions across the fleet to assess patch level

Jamf and Mycroft: frequently asked questions

No. The API account is read-only: Mycroft reads inventory, security configuration and profile assignment, and cannot issue management commands, lock, wipe or push profiles. Device actions stay with your Jamf administrators, and Mycroft records that they happened.
By covering the whole population rather than a sample. Mycroft reports FileVault status for every enrolled device, names the ones that are unencrypted and attaches the assigned user. That is what CC6.7 and HIPAA §164.310(d) ask for: fleet-wide assurance rather than a photograph of one laptop.
Jamf manages Apple endpoints. For mixed fleets, device evidence is assembled from Jamf for macOS and iOS alongside device compliance signals from your identity provider, so the endpoint controls are evidenced across the combined population. Devices outside any management system are surfaced as coverage gaps.
Yes. OS and application versions are compared against current releases, so patch lag is measured per device and tracked with a time-to-remediate against your SLA. Endpoint patching is one of the most commonly sampled vulnerability management controls and one of the hardest to evidence by hand.
Because ISO 27001 A.5.11 asks you to prove assets were returned. Reconciling Jamf's assigned-user field against your HR roster surfaces devices still assigned to people who left. That is both an asset return finding and, if the device still holds credentials, an access one.

We turn the compliance nightmare into a dream

Talk to us