As organizations expand AI adoption across the workforce, IT administrators need a scalable way to manage how AI applications are configured and used on employee devices. These applications include Claude Code, Claude Desktop, and OpenAI Codex. Meanwhile, users can open approved applications and start working without manual setup.
Jamf is trusted by more than 78,000 organizations to manage and protect Apple devices at scale, and we’re now extending that management model to AI governance. With support from Amazon Bedrock, Jamf’s AI Governance enables organizations to centrally configure and manage these applications on managed Macs.
This post shows you how to use Jamf’s AI governance and Amazon Bedrock to configure, deploy, and validate AI application management settings across your Mac fleet.
How Jamf’s AI Governance works with Amazon Bedrock
AI applications such as Claude Code, Claude Desktop, and OpenAI Codex run locally on users’ devices. Each application uses local configuration files for settings such as inference provider authentication, Model Context Protocol (MCP) server connections, and observability configuration. Managing these applications at an enterprise scale requires control over both where inference is performed and how each application is configured on the device.
Amazon Bedrock provides model inference for these applications through your AWS account, and inference runs from the AWS Region of your choice. Jamf’s AI Governance lets you define settings that connect each application to Amazon Bedrock and distribute applications across your fleet through Declarative Device Management (DDM). The combination of Amazon Bedrock and Jamf AI governance provides a scalable way to manage AI applications while keeping inference within the AWS security perimeter.
The following architecture shows how Jamf’s AI governance, managed Mac endpoints, and Amazon Bedrock work together.

Figure 1: Jamf’s AI governance delivers settings to each Mac, which the application uses to connect to Amazon Bedrock for inference.
You can define application configurations with AI Governance in Jamf and deploy them through Jamf Blueprints. Jamf helps protect managed settings from local tampering by distributing them to each device’s operating system via DDM. Users can open the application without editing local configuration files and see policy scope and deployment status in Jamf AI Governance.
Jamf AI Governance and Amazon Bedrock Practices
This section provides an example of deploying your cloud code using Amazon Bedrock. The workflow has three parts: creating a management policy, deploying it to managed Macs, and verifying that the policy is applied. The same pattern applies to other supported applications such as Claude Desktop and OpenAI Codex.
Before you begin, complete the AI Governance Prerequisites for Jamf.
Create a policy for Claude Code in Amazon Bedrock
You can create policies in your Jamf account. AI Governance > AI Policy. In Policy Builder, you configure Amazon Bedrock provider settings such as authentication method, AWS Region, and model access.
This policy defines how Claude Code uses Amazon Bedrock for users across your organization. For example, you can enable Amazon Bedrock prompt caching in Claude Code. For iterative coding workflows, prompt caching can reduce costs by up to 90 percent and latency by up to 85 percent for supported models. You can also configure the behavior of your code, such as effort level, MCP server access, local folder permissions, sandbox settings, and telemetry.

Figure 2: Setting up Claude Code on Amazon Bedrock
Deploy policies using Jamf blueprints
You can then deploy the policy to targeted Mac groups via Jamf Blueprints. Jamf delivers configurations through DDM as managed configurations. Jamf places settings on the user’s device before the user opens Claude Code. Users can start working with Claude code without manual setup.

Figure 3: Opening the Claude code with managed configuration applied
Deployment validation and monitoring
After deployment, you can use Jamf’s AI Governance to review policy coverage and deployment status. You can also use AI visualization to see AI applications and activity across your fleet and generate reports for governance evidence.

Figure 4: AI Visibility and Governance Report in Jamf AI Governance
conclusion
With Jamf’s AI Governance and Amazon Bedrock, you can maintain inference in your AWS environment while providing your users with managed access to your AI applications. Jamf provides application configuration through DDM, so IT teams can deploy provider settings and application controls across their Mac fleet and validate policy coverage without resorting to manual setup.
To learn more, read Jamf’s AI Governance for Mac blog post, watch the AI Governance on Mac webinar, or get started on AWS Marketplace.
About the author
