Guide to automating device lockouts with Jamf and Ravenna

Share this article

Most orgs don't have a real handle on their device identity governance, and offboarding is where it really shows. In one recent study, 68% of respondents reported they lack a proper program for it. 

This might look like a harmless oversight until it isn’t. In fact, the Non-Human Identity Management Group flags idle devices with unrevoked credentials as exactly the kind of thing that turns into a stolen credential, and stolen credentials are behind nearly half of the data breaches according to Verizon. The average credential-related breach takes 246 days to identify and contain. That's eight months for someone to do real damage with a login nobody switched off.

This is why every org, regardless of size, needs device lockout policies that actually hold up, and Jamf is a solid place to start rolling that out. But the catch is Jamf becomes one more console for you and your IT team to log into every time a ticket comes in, and the bigger the company, the faster that gets out of hand. 

The good news is you don't have to choose between having a great MDM and keeping your team in one place. This is where Ravenna comes in.

So how do you bring Jamf into Slack?

We’ve worked with Jamf to build a native integration, so teams can connect their Jamf Pro tenant over OAuth. Once it's wired up, Ravenna can do the following, all from inside Slack: 

  • Device lookup: Instead of hunting through the Jamf Pro console to map a user to their hardware, Ravenna automatically identifies all assigned Apple devices as soon as a request hits Slack. It creates a direct link between the person asking for help and the specific hardware they’re using, eliminating the manual cross-referencing that usually slows down ticket intake.

  • Security compliance checks: Proactively verify the security posture of any device during a support interaction. Ravenna checks for critical indicators like active MDM enrollment and FileVault disk encryption status. Your team catches non-compliant devices right away, before they turn into a blind spot.

  • Inventory management: Surface the hardware and software details that matter (OS version, serial numbers, installed configurations) right in the ticket sidebar. No more "what version of macOS are you running?" back-and-forth. Agents have the full picture from the first message.

  • Remote lock: When a device is reported lost or stolen, every minute counts. This feature lets your team fire a Remote Lock command instantly from within the support thread. The less time between the report and the lockout, the smaller the window anyone has to touch your data.

  • Remote erase: For offboarding or high-stakes security containment, Remote Erase wipes the device to a factory state. Because this is a destructive, irreversible action, it is best paired with Ravenna’s approval workflows, ensuring your team maintains a clear, logged audit trail of exactly when and why a device was wiped.

  • FileVault recovery key retrieval: Pull FileVault recovery keys securely, on demand. Your team can unlock or decommission hardware without digging through Jamf's menu structure, which speeds up both recovery and offboarding prep.

How does this look in practice? 

To understand how Ravenna and Jamf work together, let’s look at a few common scenarios:

  • Scenario 1: Employee offboarding  

With legacy ITSM, employee offboarding was one of the most manual and time consuming workflows for the IT team. It usually involves the HR team notifying IT about offboarding employees, then IT deactivating their Okta, which in turn revokes SaaS entitlements app by app, then IT logs into Jamf, finds the device and initiates a device wipe, escrows Filevault key and updates the tickets once the wipe is done. This takes hours of coordination and ends up in a split audit trail. Now just imagine how much it takes to go through the same workflow for each offboarding. This is why most organizations don’t revoke access and erase devices within 24 hours of the employees departure, only 44% do

Ravenna collapses all of that into a single HRIS termination event. As soon as the Ravenna agents get that signal, they work in the background to automatically:

  1. Deactivate in Okta / Google / Entra

  2. Revoke SaaS entitlements

  3. Retrieve FileVault recovery key first (this order matters: you want it before you wipe)

  4. Fire Jamf Remote Erase

  5. Log everything to one ticket

And Ravenna's per-tool execution policies let you require human confirmation before a destructive action fires, which is exactly what you want on the step that grabs the FileVault key before the wipe. Get that order wrong and you've bricked the data. 

  • Scenario 2: When a laptop goes missing 

Work laptops are very important pieces of hardware but you'd be surprised at how often they go missing or get stolen. According to industry reports, a laptop gets stolen every 53 seconds and it takes an average of 25 hours just to report a stolen laptop, while only about a third have full disk encryption. That's a wide-open door for anyone who wants the data on it. 

With Ravenna, the entire incident reporting and incident response happens right in Slack (or Teams). Because agents already hold context on each user's assigned device, Ravenna identifies the person, pulls the matching device from the Jamf inventory, and fires a remote lock in minutes.

Jamf's Remote Lock produces a six-digit PIN, and Jamf does not store it for you. On Apple Silicon Macs, that PIN lives in the Secure Enclave; if it's lost and the device record is deleted, the Mac can end up needing an Apple Store visit with proof of purchase to recover, and trust me you don’t want that to happen. A properly built Ravenna workflow auto-escrows the PIN to the ticket or Vault the moment it's generated. 

Scenario 3: When a device drifts out of compliance

Not every non-compliance issue requires an immediate wipe. More often than not, it requires a graduated response strategy: restrict → quarantine → lock → wipe. A heavy-handed approach often leads to excessive support tickets, and we’re pretty certain nobody on your team wants to handle more support tickets.

Let’s see how this works in practice. When an employee opens a ticket for an unrelated issue, Ravenna's agent can auto-run a compliance check to verify that FileVault is enabled, the device is MDM-enrolled, and the OS is up to date. If FileVault is off, the agent walks the user through remediation directly in the thread; if remediation fails after a set window, the agent automatically restricts their access to sensitive apps via Okta group changes. If the device remains non-compliant, you then lock the device.

Every step of this process is logged to the ticket automatically, which solves a major compliance burden. SOC 2 auditors want continuous evidence of endpoint controls, not annual screenshots. ISO 27001 A.8.1 explicitly requires the leaver process to provide proof that a device was returned or wiped. Ravenna’s workflow run history and admin audit logs provide this evidence as an exportable record. 

Ready to move from theory to practice? 

Use this checklist to ensure your Jamf and Ravenna integration provides maximum security with minimal operational friction.

  • Connect your Jamf Pro tenant: Use OAuth client credentials with a scoped API Role. You will need Jamf Pro version 10.49.0 or higher.

  • Escrow the Remote Lock PIN: Ensure every generated PIN is saved automatically to the ticket. Never let it live only in someone’s memory, as you will need that specific key if the device record is ever deleted.

  • Retrieve FileVault recovery keys first: Always secure the keys before you execute a wipe. Sequence is everything. Wipe the device without the key and you lose the data and make the hardware much harder to recover.

  • Gate destructive actions behind approvals: Use per-tool execution policies to keep your response speed fast without sacrificing human safety. You want the speed of automation, but you also want a human gatekeeper for irreversible actions.

  • Trigger from the source of truth: Launch workflows directly from the event. Use an HRIS signal for offboarding, a Slack request for incidents, or a compliance trigger for drift. Do not wait for someone to remember to open the Jamf console manually.

Frequently Asked Questions

What's the difference between Jamf Remote Lock and Remote Erase?
Remote Lock disables the device and requires a six-digit PIN to unlock; you use it for lost or stolen devices you expect to get back. Remote Erase wipes the device to factory state; you use it for offboarding, or when the device is gone for good. Erase is irreversible. Lock isn't.

What happens if we lose the Remote Lock PIN?
On Intel Macs, recovery is possible via reset. On Apple Silicon Macs, a lost PIN can require an Apple Store visit with proof of purchase, and sometimes even that isn't enough. This is why a good automated lockout workflow escrows the PIN to the ticket or credential vault the moment it's generated.

Does the Ravenna–Jamf integration work with iPhones and iPads?
Device lookup and inventory work across Mac, iPhone, and iPad. Action-level capabilities (Remote Lock, FileVault, Erase) are documented against Mac computers today. Check Ravenna's docs for the current scope before assuming mobile-device actions.

Do I need Jamf Pro, or does Jamf Now or Jamf School work?
Ravenna's current integration is with Jamf Pro specifically. Setup requires Jamf Pro 10.49.0+ and the ability to create an API Role and API Client.

Modernize and automate your
service desk with Ravenna

Modernize and automate your
service desk with Ravenna

Ravenna Software, Inc., 2026

Ravenna Software, Inc., 2026

Ravenna Software, Inc., 2026

Ravenna Software, Inc., 2026