Deploying Jamf Protect
- Last UpdatedOct 16, 2025
- 3 minute read
You can deploy Jamf Protect to computers in your organization using one of the following methods:
- (Jamf Pro) Directly from Jamf Pro—
If you use Jamf Pro, you can deploy the latest Jamf Protect PKG and scope plans directly from Jamf Pro. Jamf recommends this method for Jamf Pro users.
For more information about this integration, see Automatically Deploy Jamf Protect Using Jamf Pro in the Jamf Trusted Access Solution Guide for Business.
- (Other MDM solutions) Manually download and upload—
If you use another MDM solution, you can download the latest Jamf Protect PKG and plans from your Jamf Protect tenant and upload them to your MDM solution for deployment. The PKG or unique download URL are available in your Jamf Protect macOS Security portal.
The following diagram shows how Jamf Protect is deployed:
If your Jamf Protect portal is registered with Jamf Pro, your plans and the Jamf Protect PKG are automatically available. To access your Jamf Protect assets in Jamf Pro, navigate to .

Keep the following in mind when deploying Jamf Protect:
If Enable auto update is enabled in a plan on computers, Jamf Protect agent updates will automatically be installed. If this setting is disabled, you must download the latest package and upload it to your MDM solution to deploy updates.
The plan configuration profile and Jamf Protect agent should be deployed simultaneously with your MDM solution. If the Jamf Protect agent is deployed without a plan configuration profile, the agent will not work as intended.
You can manually download plan configuration profiles and the latest Jamf Protect PKG for deployment via an MDM solution.
You must have one or more plans in Jamf Protect.
The Jamf Protect PKG and plan configuration profiles are deployed to computers the next time they check in with your MDM solution.
The Root CA may appear as untrusted on computers when installed via a plan configuration profile.