Managing a Suite of Mac Admin Tools with Jamf Pro

(aka: The cobbler has new shoes.)

For the longest time, the Mac admin-specific utilities I used were randomly found in my Downloads folder and haphazardly updated. In the last year this has changed: my Mac admin tools are properly managed applications. Two changes helped bring about this improvement. First, our team brought on a junior engineer, and I wanted him to have the same toolset as me when administering Macs. Also, a number of these tools have appeared in Jamf App Installers. Wanting to have consistent tooling across just two Macs/admins and a reduced barrier to entry made it worth it to get started.

I prefer Jamf App Installers and the Mac App Store for deploying and maintaining these titles because I can largely “set it and forget it.” While it’s a small number of computers, it’s a medium-sized set of applications to manage and I want to have to software maintenance with the minimum of effort. In JAI and MAS, once the titles are set up in Jamf Pro, the updates are performed automatically. However, we have some titles that can’t be installed by those mechanisms, and I’ll cover how we handle them at the end.

Group(s)

To get started, create a Jamf group that defines your Mac admins’ Macs. Our group is called Mac Admin Tools. While it could be static or smart, Jamf App Installers requires a smart group. (Tip: You can wrap a static group in a smart group by using a criterion that matches membership in the static group.) A smart group could be based on job position, or even a non-script extension attribute. Remember that admins often get assigned to test computers and other devices that aren’t their own.

With the group defined, you can start using it to scope app titles or policies. It might seem like overkill if you have a small number of admins or even a solo admin, but it quickly shows its ability to scale. Jamf Pro is now managing 11-13 (depending on how one counts) Mac admin tools for us.

This summer, I used a 2nd Mac as a daily driver to test macOS 27 without risking a beta on my primary Mac. I put the 2nd Mac into the Mac Admin Tools group and got all these apps installed. It saved the manual work of finding, downloading, and installing them, which is made more tedious because I work in a standard user account. The same time-saving works when you upgrade to a new Mac.

Apps and their sources

Here are the apps we’ve deployed to our small Mac admin team.

Mac App Store

For the Mac App Store titles, we “purchased” 10 licenses in Apple Business and assigned them to our Jamf Pro instance. (All the apps are free.) We automatically install and force updates.

Jamf App Installers

In Jamf App Installers, we automatically install and automatically select new versions.

(Installomator) policies

Because we already have Installomator in our Jamf Pro instance, it’s easy to use for deploying the other titles not supplied in JAI or MAS. There one title, noted below, that we can’t use Installomator for.

  • DFU Blaster Pro – An Installomator-based policy that runs weekly. Installomator will exit early if the latest version matches the installed version.
  • Jamf Connect Configuration – Installomator supports deploying this app even though it’s a secondary asset in the Jamf Connect Login dmg download. We also scope this policy to IdP admins. We run the policy once per computer when we deploy a new version of Jamf Connect Login.
  • Mac Evaluation Utility – This is not an Installomator policy as the pkg is only available for download after logging into AppleSeed for IT. When we’re aware of a new MEU, we upload the new package to Jamf Pro and re-run the policy.
  • SF Symbols – An Installomator-based policy that runs weekly.

Your turn

The Mac admin’s toolset is worth managing well, as one would end-user applications. (whispers: The Mac admin is an end-user too.) Hopefully, this has inspired you to take control of your admin tool deployment and management. Let me know what tools you would add!

Leave a comment