Skip to main content
Question

Monitoring User Activity After Privilege Elevation via Jamf Connect

  • September 3, 2026
  • 2 replies
  • 48 views

a_govind.sharma

Hello Team,

We are currently using Jamf pro + Jamf Connect for privilege elevation on our macOS devices. From an audit and compliance perspective, we are looking for a solution that can monitor and track user activity after elevated privileges are granted and can Alert .

Specifically, we are interested in capturing and reporting on:

  • Commands executed using elevated privileges (sudo/admin actions)
  • Applications launched while elevated
  • System configuration changes
  • Software installations/removals
  • Security-related modifications
  • Detailed audit logs for compliance and forensic investigations

We would like to understand how other organizations are addressing this requirement in their macOS environments.

  1. Are there native Jamf Pro, Jamf Connect, capabilities that provide this level of auditing?
  2. If not, what third-party solutions are commonly integrated with Jamf pro for monitoring privileged user activity?
  3. Has anyone implemented this using CrowdStrike, SIEM/EDR platform?
  4. What has been your experience balancing audit visibility with user privacy and performance?

Any recommendations, best practices, or architecture examples would be greatly appreciated.

Thank you in advance for your insights.

Best regards,
Govind Sharma

2 replies

Chubs
Forum|alt.badge.img+26
  • Jamf Heroes
  • September 3, 2026

I believe all of this can be had with Jamf Protect.  Do you have jamf protect by chance?


GovindSharma
Forum|alt.badge.img+1
  • New Contributor
  • September 3, 2026

I believe all of this can be had with Jamf Protect.  Do you have jamf protect by chance?

No we do not have jamf protect Yet.