Manage AI applications on Mac using Jamf AI governance and Amazon Bedrock

Applications of AI


As organizations expand AI adoption across the workforce, IT administrators need a scalable way to manage how AI applications are configured and used on employee devices. These applications include Claude Code, Claude Desktop, and OpenAI Codex. Meanwhile, users can open approved applications and start working without manual setup.

Jamf is trusted by more than 78,000 organizations to manage and protect Apple devices at scale, and we’re now extending that management model to AI governance. With support from Amazon Bedrock, Jamf’s AI Governance enables organizations to centrally configure and manage these applications on managed Macs.

This post shows you how to use Jamf’s AI governance and Amazon Bedrock to configure, deploy, and validate AI application management settings across your Mac fleet.

How Jamf’s AI Governance works with Amazon Bedrock

AI applications such as Claude Code, Claude Desktop, and OpenAI Codex run locally on users’ devices. Each application uses local configuration files for settings such as inference provider authentication, Model Context Protocol (MCP) server connections, and observability configuration. Managing these applications at an enterprise scale requires control over both where inference is performed and how each application is configured on the device.

Amazon Bedrock provides model inference for these applications through your AWS account, and inference runs from the AWS Region of your choice. Jamf’s AI Governance lets you define settings that connect each application to Amazon Bedrock and distribute applications across your fleet through Declarative Device Management (DDM). The combination of Amazon Bedrock and Jamf AI governance provides a scalable way to manage AI applications while keeping inference within the AWS security perimeter.

The following architecture shows how Jamf’s AI governance, managed Mac endpoints, and Amazon Bedrock work together.

Jamf AI Governance delivers configuration to managed Macs that connect to Amazon Bedrock for inference

Figure 1: Jamf’s AI governance delivers settings to each Mac, which the application uses to connect to Amazon Bedrock for inference.

You can define application configurations with AI Governance in Jamf and deploy them through Jamf Blueprints. Jamf helps protect managed settings from local tampering by distributing them to each device’s operating system via DDM. Users can open the application without editing local configuration files and see policy scope and deployment status in Jamf AI Governance.

Jamf AI Governance and Amazon Bedrock Practices

This section provides an example of deploying your cloud code using Amazon Bedrock. The workflow has three parts: creating a management policy, deploying it to managed Macs, and verifying that the policy is applied. The same pattern applies to other supported applications such as Claude Desktop and OpenAI Codex.

Before you begin, complete the AI ​​Governance Prerequisites for Jamf.

Create a policy for Claude Code in Amazon Bedrock

You can create policies in your Jamf account. AI Governance > AI Policy. In Policy Builder, you configure Amazon Bedrock provider settings such as authentication method, AWS Region, and model access.

This policy defines how Claude Code uses Amazon Bedrock for users across your organization. For example, you can enable Amazon Bedrock prompt caching in Claude Code. For iterative coding workflows, prompt caching can reduce costs by up to 90 percent and latency by up to 85 percent for supported models. You can also configure the behavior of your code, such as effort level, MCP server access, local folder permissions, sandbox settings, and telemetry.

Configuring Claude Code Provider Settings for Amazon Bedrock with Jamf Policy Builder

Figure 2: Setting up Claude Code on Amazon Bedrock

Deploy policies using Jamf blueprints

You can then deploy the policy to targeted Mac groups via Jamf Blueprints. Jamf delivers configurations through DDM as managed configurations. Jamf places settings on the user’s device before the user opens Claude Code. Users can start working with Claude code without manual setup.

Open the Claude Code on a Managed Mac with Jamf Settings Already Applied

Figure 3: Opening the Claude code with managed configuration applied

Deployment validation and monitoring

After deployment, you can use Jamf’s AI Governance to review policy coverage and deployment status. You can also use AI visualization to see AI applications and activity across your fleet and generate reports for governance evidence.

Jamf AI Governance's AI Visibility dashboard displays AI application activity and governance reports

Figure 4: AI Visibility and Governance Report in Jamf AI Governance

conclusion

With Jamf’s AI Governance and Amazon Bedrock, you can maintain inference in your AWS environment while providing your users with managed access to your AI applications. Jamf provides application configuration through DDM, so IT teams can deploy provider settings and application controls across their Mac fleet and validate policy coverage without resorting to manual setup.

To learn more, read Jamf’s AI Governance for Mac blog post, watch the AI ​​Governance on Mac webinar, or get started on AWS Marketplace.


About the author

Kami Parson

Kami Parson

Cami is a Principal Account Manager at AWS, where she partners with independent software vendors to drive value creation through cloud adoption and AI integration. She is focused on accelerating partner revenue growth and large-scale platform modernization. Based in Minneapolis, Cami lives with her husband.

Arun Chandapilai

Arun Chandapilai

Arun is a Senior Cloud Architect passionate about helping customers accelerate their IT modernization through business-first cloud adoption strategies. He specializes in building and deploying AI and generative AI solutions on AWS, from agent workflows to production-ready applications. Arun is a car enthusiast, avid speaker, and has a passion for giving back, believing that ‘you get what you give’.

Sofian Hamity

Sofian Hamity

Sofian is a technology leader with over 12 years of experience building AI solutions and leading high-performance teams to maximize customer outcomes. He is passionate about empowering diverse talent to increase their global impact and achieve their career aspirations.

antonio rodriguez

antonio rodriguez

Antonio is the Principal Generative AI Technology Lead at Amazon Web Services. He helps companies of all sizes use Amazon Bedrock to solve challenges, embrace innovation, and create new business opportunities. Outside of work, I love spending time with my family and playing sports with friends.

Matt Vlasak

Matt Vlasak

Matt is Jamf’s Senior Vice President of Enterprise Product and Solutions Engineering, where he helps shape Apple’s products and solutions in the enterprise. He brings deep expertise in device management, identity, networking, and security with a focus on making enterprise technology secure, scalable, and easy to use.

Josh Stein

Josh Stein

Josh is Jamf’s Vice President of Product Strategy and Security. A former cybersecurity founder and NSA developer, he brings experience across offensive and defensive security with a focus on helping organizations protect Apple devices from evolving threats.

Jen Kaplan

Jen Kaplan

Jen is Jamf’s Vice President of Product Marketing, where she leads product marketing, brand, design, and campaigns. She brings experience across SaaS, cybersecurity, retail, and digital experiences, with deep expertise in go-to-market strategies and a focus on helping organizations implement complex technologies through clear and compelling storytelling.



Source link