Jamf deploys AgenShield with the same two objects as every other MDM: the
campaign’s configuration profile and the signed installer package. Jamf Pro and
Jamf Now differ only in how those are grouped and scoped.
Get both artifacts from your install campaign first.
Jamf Pro
1. Upload the configuration profile
Computers → Configuration Profiles → Upload, and selectdeployment.mobileconfig.
- Level: Computer Level.
- Jamf re-signs uploaded profiles. That is expected and fine.
- Scope it to the smart or static group you are rolling out to.
Upload the file as-is — it already pairs every payload with the correct
extension identifiers, so there is nothing to rebuild in Jamf-native payload
editors. Because it carries no enrollment token, you upload it once and it
stays valid across campaign rotations and new releases.
2. Run the install command from a policy
-
Settings → Computer Management → Scripts → New — paste the campaign’s
install command as a shell script. Jamf runs scripts as
root. -
Computers → Policies → New:
- Triggers: Enrollment Complete and Recurring Check-in.
- Execution Frequency: Once per computer.
- Scripts payload: add the script above.
- Scope: the same group as the profile.
3. Scope with a smart group
A smart group keyed on the AgenShield application makes both the rollout and the reporting self-maintaining:
Invert it (
is not) to get “managed Macs still missing AgenShield” — a useful
scope for the install policy and a useful dashboard for the rollout.
Jamf Now
Jamf Now groups everything into a Blueprint, and has no script object — so this is the package route, with the all-in-one profile that carries the enrollment token.1
Add the installer
Apps → Add App → Custom App — upload the campaign’s
.pkg and enable
automatic installation.2
Add the profile
In the Blueprint, add a Custom Profile and upload
agenshield.mobileconfig — the all-in-one, because without a script there is
nothing else to deliver the enrollment token.3
Assign the Blueprint
Assign it to the Macs you are enrolling. Jamf Now applies both objects on the
next check-in.
Verify
On a managed Mac:- System Settings → General → Device Management lists the AgenShield profile.
AgenShield.appin/Applications.- The device under Devices in the Frontegg Portal (
https://portal.frontegg.com/<environment>/agen/shielded/devices), within a minute of the package installing — before anyone logs in.
Troubleshooting
Everything else is on the MDM enrollment reference.
Next
Enrolled devices
Reading fleet health once devices land.
Rollout playbook
Monitor first, then promote rules one at a time.