Skip to main content
Jamf Pro cover — one profile, one policy. Jamf deploys AgenShield with the same two objects as every other MDM: the campaign’s configuration profile and the signed installer package. Jamf Pro and Jamf Now differ only in how those are grouped and scoped. Get both artifacts from your install campaign first.

Jamf Pro

1. Upload the configuration profile

Computers → Configuration Profiles → Upload, and select deployment.mobileconfig.
  • Level: Computer Level.
  • Jamf re-signs uploaded profiles. That is expected and fine.
  • Scope it to the smart or static group you are rolling out to.
Upload the file as-is — it already pairs every payload with the correct extension identifiers, so there is nothing to rebuild in Jamf-native payload editors. Because it carries no enrollment token, you upload it once and it stays valid across campaign rotations and new releases.

2. Run the install command from a policy

  1. Settings → Computer Management → Scripts → New — paste the campaign’s install command as a shell script. Jamf runs scripts as root.
  2. Computers → Policies → New:
    • Triggers: Enrollment Complete and Recurring Check-in.
    • Execution Frequency: Once per computer.
    • Scripts payload: add the script above.
    • Scope: the same group as the profile.
The script exits non-zero if the device does not finish enrolling, so the policy log tells you the truth rather than just “script ran”. Push order does not matter — see how a device joins your fleet.
Prefer Jamf’s package workflow, or need Jamf to report install state from its own inventory? Upload the campaign’s .pkg to Settings → Computer Management → Packages and use a Packages payload instead of the Scripts payload, with the all-in-one profile in step 1. See If you cannot run a script.

3. Scope with a smart group

A smart group keyed on the AgenShield application makes both the rollout and the reporting self-maintaining: Invert it (is not) to get “managed Macs still missing AgenShield” — a useful scope for the install policy and a useful dashboard for the rollout.

Jamf Now

Jamf Now groups everything into a Blueprint, and has no script object — so this is the package route, with the all-in-one profile that carries the enrollment token.
1

Add the installer

Apps → Add App → Custom App — upload the campaign’s .pkg and enable automatic installation.
2

Add the profile

In the Blueprint, add a Custom Profile and upload agenshield.mobileconfig — the all-in-one, because without a script there is nothing else to deliver the enrollment token.
3

Assign the Blueprint

Assign it to the Macs you are enrolling. Jamf Now applies both objects on the next check-in.
Jamf Now reports Settings applied on the device row once the Blueprint has landed.

Verify

On a managed Mac:
You should also see:
  • System Settings → General → Device Management lists the AgenShield profile.
  • AgenShield.app in /Applications.
  • The device under Devices in the Frontegg Portal (https://portal.frontegg.com/<environment>/agen/shielded/devices), within a minute of the package installing — before anyone logs in.

Troubleshooting

Everything else is on the MDM enrollment reference.

Next

Enrolled devices

Reading fleet health once devices land.

Rollout playbook

Monitor first, then promote rules one at a time.