The Jamf Cloud environment allows for the grouping of devices both organizationally and administratively, while maintaining some items globally. Within ISC's managed Jamf Cloud instance, what Jamf calls "Sites" are used to organize and silo each School and Center within the tenant.
Sites
Each organization that joins ISC's Jamf Cloud will be granted access to a Site. Under this site, you will be able to enroll and manage your devices and users. Individual Site Admin accounts can be created for each IT staff member who will be administering devices or users within the organization.
Items managed and controlled at the Site level include:
- Devices
- Users
- Policies
- Configuration Profiles
- Pre-Stage Imaging and Enrollment
- Patch Management
- App Management and Apple Volume Purchasing Program (VPP) Applications
- Device Groups (Smart and Static)
Global Items
While much of the Jamf environment can be managed at the Site level, some items are exclusively global in nature. Generally, these items, once created, can be applied and managed by Site Admins using Policies, Configuration Profiles, and Device Groups. However, the creation and editing of these items must be done by a Global Admin.
Globally created items include:
- Packages
- Scripts
- Directory Bindings
- LDAP Servers
Since Global access is required to create these, each organization is also provided with a modified Global Admin account that provides access to create and edit these items, without providing access to items such as the ability to edit Admin account permissions. This also allows for simplified sharing of items that may be useful across organizations, without granting anyone the ability to delete anyone else's work. More detailed information about these custom permissions and the expectations among organizations can be discussed during the onboarding process.
Custom Roles Within Sites
Some organizations may wish to have support providers who perform some device management tasks, without giving them full Site Admin access. In these cases, ISC can facilitate the creation of custom roles within a Site.