Integrate Jamf Protect
You can integrate Jamf Protect with Sophos XDR so that it sends data to Sophos for analysis.
Key steps
The key steps in a Jamf Protect integration are as follows:
- Create an API client in Jamf Protect and save the details.
- Configure the integration in Sophos XDR.
Requirements
The following is required for Jamf Protect configuration:
- Access to the Jamf Protect console.
Add a Jamf Protect integration
To integrate Jamf Protect, you must first gather certain details from Jamf, then provide them in Sophos XDR.
Create a client and get API details
To create the Jamf Protect API client you need for integration, do as follows:
- In Jamf Protect, go to Administrative > API Clients.
- Click Create API Client.
- Enter a name for your API client.
- Assign a custom role to the API client with permissions to read alerts.
-
Copy the API client password immediately to use later in Sophos XDR.
The API client password won't be shown again.
-
Your API client configuration and endpoint information is shown. Copy the Client ID.
Next, you configure an integration in Sophos XDR.
Configure the integration in Sophos XDR
To integrate Jamf Protect with Sophos XDR, do as follows:
- In Sophos Fusion, go to Security Operations > Integrations > Marketplace.
-
Click Jamf Protect.
The Jamf Protect page opens. You can configure integrations here and see a list of any you've already configured.
-
In Configured integrations, click Add new.
-
In Add an integration, do as follows:
- Enter a name for the integration.
- Enter the Base URL, which is in the form
https://<your-organization>.protect.jamfcloud.com. - Enter the Client ID and Password you got from Jamf Protect.
-
Click Done.
The new integration appears under Configured integrations. If its status icon is a green tick, your data should appear in the Sophos Data Lake after validation.
Additional resources
For more information on configuring Jamf Protect, see the following documents: