Computer Inventory and Criteria Reference
This section lists the inventory attributes you can view for a computer. These attributes can be used as criteria for your smart computer groups and advanced computer searches. Attribute labels are the same in inventory information and in criteria lists unless otherwise noted. Inventory attributes with a minimum macOS version requirement are noted in the Jamf Pro interface. Some attributes are editable.
The following categories of inventory information are only displayed if the Computer Inventory Collection settings are configured to collect them:
-
Local User Accounts
For more information, see "Local User Accounts Category" below.
-
Printers
-
Active services
-
Last backup date/time for managed mobile devices that are synced to computers
-
User and location information from an external directory service, such as an LDAP server or Cloud Identity Provider.
Note:This is only available if an external directory service is configured in Jamf Pro. User and location data from Inventory Preload may also populate this category.
-
Package receipts
-
Available software updates
-
Application usage information
For more information, see "Applications Category" below.
-
Fonts
-
Plug-ins
-
iBeacon regions
General Category
The General category includes the following information for a computer:
Inventory Attribute/Criteria |
Notes |
---|---|
Computer Name | |
Site | |
Last Inventory Update | |
Last Check-in | |
IP Address |
To learn how these inventory attributes are collected and how you can manually retrieve the reported IP address, see the Collecting the IP Address and Reported IP Address in Jamf Pro article. |
Reported IP Address (Last Reported ID Address criteria) | |
jamf binary Version | |
Platform | |
Managed (Managed By criteria) |
A computer is considered managed when it has the Jamf management framework installed and enrolled with Jamf Pro. The Managed By criteria returns the name of the management account on the computer. |
Supervised |
For more information about supervision, see the following documentation from Apple: https://support.apple.com/guide/deployment-reference-macos/ior7ba06c270/ |
Enrollment Method | |
Last Enrollment | |
MDM Capability |
Whether the computer has the MDM profile installed |
Enrolled via Automated Device Enrollment |
Displays whether a computer was enrolled via Automated Device Enrollment. |
User Approved MDM |
Displays the status of User Approved MDM enrollment. For information about User Approved MDM and Jamf Pro, see the Managing User Approved MDM with Jamf Pro article. |
Jamf Pro Computer ID | |
Asset Tag | |
Bar Code 1 | |
Bar Code 2 | |
Bluetooth Low Energy Capability |
Possible values are the following:
|
Supports iOS and iPadOS App Installations | |
Logged in to the App Store |
This value reports as “Active” when a user-level configuration profile is installed from Self Service using MDM-enabled credentials. |
Management Account Username | |
Management Account Password | |
MDM Profile Expiration Date (criteria only) | |
MDM Profile Renewal Needed - CA Renewed (criteria only) |
Hardware Category
The Hardware category includes the following information for a computer:
-
Make
-
Model
-
Model Identifier
-
UDID
-
Serial Number
-
Processor Speed
-
Number of Processors
-
Number of Cores (Total Number of Cores criteria)
-
Processor Type
-
Apple silicon
-
Architecture Type
-
Bus Speed
-
Cache Size
-
Primary MAC Address (MAC Address criteria)
-
Primary Network Adapter Type
-
Secondary MAC Address
-
Secondary Network Adapter Type
-
Total RAM (Total RAM MB criteria)
Note:Capacity is reported using the decimal system (base 10), which calculates 1GB as 1 billion bytes.
-
Available RAM Slots
-
Battery Capacity
-
SMC Version
-
NIC Speed
-
Optical Drive
-
Boot ROM—As criteria, this includes computers based on their specific boot ROM, based on the ROM's release number (Example: "10.2.1 [29006] rev 0").
Operating System Category
The Operating System category includes the following information for a computer:
-
Operating System
-
Operating System Version
-
Operating System Build
-
Software Update Device ID
-
Active Directory Status
-
Master Password Set
-
FileVault Users
-
Service Pack
User and Location Category
All User and Location category inventory attributes are editable and can be populated automatically by assigning a user to a computer. For more information, see User Assignments. The User and Location category includes the following information for a computer:
-
Username
-
Full Name
-
Email address
-
Position
-
Department
-
Building
-
Room
-
To collect User and Location information for computers, the Collect User and Location Information from LDAP setting must be enabled in the Computer Inventory Collection settings. For more information, see Computer Inventory Collection Settings.
-
If the computer is re-enrolled via a PreStage enrollment, there are settings that can affect the user and location information for that computer. For more information, see Computer PreStage Enrollments and Re-enrollment Settings.
Security Category
The Security category allows you to view the following information for a computer:
-
System Integrity Protection
-
Gatekeeper
-
XProtect Definitions Version
-
Disable Automatic Login
-
Remote Desktop Enabled
-
Secure Boot Level
Note:This attribute displays whether the computer allows or disallows booting from external media. It is only collected on compatible computers with macOS 10.15 or later.
-
Bootstrap Token Allowed (macOS 11 or later)
-
Recovery Lock password (Apple silicon/M1 chip with macOS 11.5 or later)
-
Firewall
For more information about the reporting capabilities for some attributes in the Security category, see the Jamf Pro Reporting Capabilities for Apple's macOS Security Features article.
Purchasing Category
You can look up and populate purchasing information from Apple’s Global Service Exchange (GSX) if you have a GSX connection set up in Jamf Pro. For more information, see GSX Connection. The Purchasing category allows you to view the following information for a device:
-
Purchased or Leased
-
PO Number (PO criteria)
-
PO Date
-
Vendor
-
Warranty Expiration
-
AppleCare ID
-
Lease Expiration
-
Purchase Price
-
Life Expectancy
-
Purchasing Account
-
Purchasing Contact
You can choose
as criteria in your smart groups and advanced searches.Extension Attributes Category
This category displays a list of custom data fields collected using extension attributes.
Extension attributes are displayed in device inventory information in the category in which they are configured to display.
Storage Category
The Storage category includes the following information for a computer:
-
Model
-
Revision
-
Serial Number
-
Drive Capacity (Drive Capacity MB criteria)
-
S.M.A.R.T. Status
-
Number of Partitions
Note:The value for the FileVault 2 State of a partition will be reported as “Unknown” if inventory was not updated since the last Jamf Pro upgrade or if Jamf Pro is unable to detect encryption status due to an error.
You can also use the following storage criteria in your smart groups and advanced searches:
-
Boot Drive Available MB
-
Boot Drive Percentage Full
-
Core Storage Partition Scheme on Boot Partition
-
Partition Name
-
Last iCloud Backup
Disk Encryption Category
This category displays disk encryption information for partitions on a computer. The Disk Encryption category includes the following information:
Inventory Attribute/Criteria |
Notes |
---|---|
Name | |
Last Inventory Update | |
FileVault 2 Partition Encryption State |
Possible values are:
As criteria, this can be coupled with the “Partition Name” criteria to report on the encryption state of a specific partition you specify by name. |
Personal Recovery Key Validation ("FileVault 2 Individual Key Validation" criteria) |
Displays whether the personal (also known as "individual") recovery key on a computer matches the personal recovery key escrowed for that computer in Jamf Pro. This value will be reported as “Unknown” when any of the following conditions are met:
Other possible values are:
|
Personal Recovery Key |
To view the recovery key, click Show Key. |
Device Recovery Key |
To view the recovery key, click Show Key. |
Disk Encryption Configuration |
Displays the name of the disk encryption configuration if the computer is encrypted via policy. If the computer is encrypted via configuration profile or locally on the computer, this field is left blank. As criteria, this includes computers with a specified FileVault disk encryption configuration in Jamf Pro. |
FileVault 2 Enabled Users |
You can also use the following disk encryption criteria in your smart groups and advanced searches:
Criteria |
Notes |
---|---|
FileVault Status |
Includes computers based on the number of FileVault-enabled users out of the number of users that can be FileVault enabled. Possible values are:
This criteria applies to both FileVault 2 and Legacy FileVault-enabled users. |
FileVault 2 Recovery Key Type |
Includes computers based on the recovery key types that are reported in their Jamf Pro inventory. Possible values are the following:
|
FileVault 2 Institutional Key |
Includes computers based on whether an institutional recovery key exists on a computer. Possible values are:
|
FileVault 2 User |
Includes computers where the specified user is a FileVault enabled user. For example, to report on computers on which John Smith is a FileVault enabled user, you would enter the criteria FileVault 2 User has "John Smith". |
FileVault 2 Eligibility |
Possible values are the following:
For all values other than “Eligible”, the search returns the first ineligible reason found, based on this order of priority:
|
FileVault 2 Status |
The partitions that are FileVault 2 encrypted. Possible values are:
|
Applications Category
This category includes information about the applications installed on a computer. You can use the following applications criteria in your smart groups and advanced searches:
-
Application Title
-
Application Version—This criteria can be used in tandem with Application Title to include computers based on a specific version of a specific application.
-
iTunes Store Account
Profiles Category
This category includes information about the configuration profiles installed on a computer. You can use the following profiles criteria in your smart groups and advanced searches:
-
Profile Name
-
Profile Identifier
Certificates Category
The Certificates category displays a list of certificates installed a device. You can use the following certificates criteria in your smart groups and advanced searches:
-
Certificate Issuer
-
Certificate Name
-
Certificates Expiring
Package Receipts Category
This category includes information about the packages installed on a computer. You can use the following packages criteria in your smart groups and advanced searches:
-
Cached Packages
-
Packages Installed by Casper (Jamf Pro)
-
Packages Installed By Installer.app/SWU
Local User Accounts Category
This category displays a list of local user accounts and information about them. You can access commands to remotely unlock a local user account, or remotely remove a local or mobile user account by clicking Manage for a user. For more information, see Remote Commands for Computers.
This information is only displayed if the Computer Inventory Collection settings are configured to collect it. For more information, see Computer Inventory Collection Settings. The following table lists the Local User Accounts category inventory attributes that you can view for a computer:
Inventory Attribute/Criteria |
Notes |
---|---|
UID | |
Username | |
Password Type |
Only displayed if Jamf Pro can identify the user account type (e.g., “Local", “LDAP", or "Mobile LDAP") |
Minimum Passcode Length (Required Passcode Length criteria) | |
Maximum Passcode Age | |
Minimum Number of Complex Characters | |
Password History | |
Full Name | |
Admin | |
Home Directory | |
Legacy FileVault Enabled | |
FileVault 2 Enabled | |
User Azure Active Directory ID |
Unique identifier within Microsoft Azure for users that registered their computers with Azure AD. If the user registers many local accounts or multiple computers, their User Azure Active Directory ID is always the same. |
Computer Azure Active Directory ID |
Unique identifier within Microsoft Azure for the computer local account. The Computer Azure Active Directory ID is unique across each computer and each local user account. Every time a user registers a computer with Azure AD that local account will be given a unique identifier. |
Conditional Access Inventory State (previously named "Azure Active Directory ID") |
Displays one of the following values when the macOS Intune Integration is enabled:
|
Scheduled Tasks (criteria only) |
Attachments Category
You can upload and delete attachments to the inventory record using this category. To upload an attachment, click Upload. To delete an attachment, click Delete.
Content Caching Category
The Content Caching category is only collected for computers with macOS 10.15.4 or later. For more information on content caching reporting capabilities, see Apple's documentation.
The Content Caching category allows you to view the following information for a computer:
-
Activated (Content Caching - Activated criteria)
-
Active (Content Caching - Active criteria)
-
Actual Cache Used
-
Alerts
-
Cache Details
-
Cache Free
-
Cache Limit (Content Caching - Cache Limit bytes criteria)
-
Cache Status (Content Caching - Cache Status criteria)
-
Cache Used (Content Caching - Actual Cache Used bytes criteria)
-
Data Migration Completed
-
Data Migration Error
-
Data Migration Progress
-
Max Cache Pressure in Last Hour
-
Parents
-
Personal Cache Free
-
Personal Cache Limit
-
Personal Cache Used
-
Port
-
Public Address
-
Registration Error
-
Registration Response Code
-
Registration Started
-
Registration Status
-
Restricted Media
-
Server GUID
-
Startup Status
-
Tetherator Status (Content Caching - Tetherator Status criteria)
-
Total Bytes are Since
-
Total Bytes Dropped
-
Total Bytes Imported
-
Total Bytes Returned to Children
-
Total Bytes Returned to Clients
-
Total Bytes Returned to Peers
-
Total Bytes Returned from Origin
-
Total Bytes Returned from Parents
-
Total Bytes Returned from Peers