Hello Team,
We are currently using Jamf pro + Jamf Connect for privilege elevation on our macOS devices. From an audit and compliance perspective, we are looking for a solution that can monitor and track user activity after elevated privileges are granted and can Alert .
Specifically, we are interested in capturing and reporting on:
- Commands executed using elevated privileges (sudo/admin actions)
- Applications launched while elevated
- System configuration changes
- Software installations/removals
- Security-related modifications
- Detailed audit logs for compliance and forensic investigations
We would like to understand how other organizations are addressing this requirement in their macOS environments.
- Are there native Jamf Pro, Jamf Connect, capabilities that provide this level of auditing?
- If not, what third-party solutions are commonly integrated with Jamf pro for monitoring privileged user activity?
- Has anyone implemented this using CrowdStrike, SIEM/EDR platform?
- What has been your experience balancing audit visibility with user privacy and performance?
Any recommendations, best practices, or architecture examples would be greatly appreciated.
Thank you in advance for your insights.
Best regards,
Govind Sharma
