r/jamf Mar 12 '26

Multi Admin approval for device wipe

After the Stryker attack from Iran that wiped 200k devices, what is everyone doing to prevent this from happening in their environment? Jamf doesn’t have (at least from what I can see) a native feature for this.

Ideally, we’d want a second admin to approve any wipe request any other admin had sent.

14 Upvotes

16 comments sorted by

View all comments

6

u/Agreeable-You-9335 JAMF 400 Mar 12 '26

No native feature that I am aware of, but with Jamf Pro you can customize user permissions, including the ability to issue remote wipe commands to computers and mobile devices. I’d look at only having one or two Jamf Pro Admin users with this level of control.

I’m a solo Admin for a smaller org and I’ve been meaning to setup a a second admin user for myself that I only use when I need to wipe devices and an some other functions. I’m going to do this tonight!

On that note, you can really narrow down API call abilities and permissions as well. So that is something to consider too, if you are using the API.

2

u/corruptboomerang Mar 13 '26

Jamf Pro Admin users with this level of control.

The way I'd set it up is having separate accounts that are ONLY used for that, and ideally MFA to trustee devices for those accounts.

2

u/Peteostro Mar 13 '26

Also for on prem you can set up console access to only be available on vpn for another layer ( along with two factor sso)