Connecting Jamf School (MDM Device Actions)
Connecting Jamf School lets KyberGate send real MDM commands to your iPads — lock, unlock, clear passcode, restart, and more — directly through Jamf School's API. When a teacher locks a device from the dashboard, the lock is enforced by Apple's MDM protocol, so it holds even if the student switches apps.
Jamf School vs. Jamf Pro: These are two different products with different APIs. This guide is for Jamf School (formerly ZuluDesk). If you use Jamf Pro, choose "Jamf Pro" instead.
What You Get
- Real device lock/unlock from the dashboard and Screen View
- Clear passcode, restart, shutdown commands
- Device sync — pull serial numbers, UDIDs, and owners from Jamf School into KyberGate
- Commands enforced by Apple MDM (not just an in-app overlay)
Before You Begin
- You need admin access to Jamf School and the Admin role in KyberGate
- Your iPads should already be enrolled and supervised in Jamf School
Step 1: Create an API Key in Jamf School
- In Jamf School, go to Organization → Settings → API
- Enable the API if it isn't already
- Note your Network ID — it's shown at the top of this page (a 6–7 digit number)
- Click Add API Key
- Grant the key these permissions:
- View Devices
- Manage Devices (send remote commands)
- Lock / Unlock Device
- Clear Passcode
- Restart / Shutdown Device
- View Device Owners
- Save and copy the generated API key
Step 2: Connect in KyberGate
- In your dashboard, go to Settings → MDM
- Select Jamf School as your provider
- Fill in:
- API URL — leave as
https://api.zuludesk.comunless Jamf gave you a region-specific URL (e.g.https://<region>.jamfcloud.com/api) - Network ID — from Step 1
- API Key — from Step 1
- API URL — leave as
- Click Save Configuration
- Click Test Connection — you should see "Connected to Jamf School! N devices found."
If the test fails with "Invalid network ID," double-check the Network ID. If it fails on the key, confirm the API key's permissions and that the API is enabled.
Step 3: Sync Your Devices
- After a successful test, click Sync Now
- KyberGate matches your Jamf School devices to KyberGate devices by UDID, then serial number, then name
- This pulls in serial numbers, UDIDs, models, and device owners — which is what MDM commands use to target the right device
Run a sync any time your device fleet changes.
How Device Locking Works
- A teacher clicks Lock on a device in Screen View
- KyberGate calls the Jamf School API to lock that device (by UDID)
- Jamf School pushes the lock via Apple's MDM protocol
- The device locks instantly — even if KyberGate's app is in the background
Unlock, clear passcode, restart, and shutdown work the same way.
Supported Commands
| Dashboard action | Jamf School command |
|---|---|
| Lock | Lock device |
| Unlock | Unlock device |
| Clear passcode | Clear passcode |
| Restart | Restart device |
| Shutdown | Shutdown device |
| Wipe (erase) | Wipe device |
Troubleshooting
"Invalid network ID" The Network ID is wrong. It's the 6–7 digit number at the top of Organization → Settings → API in Jamf School — not your account name.
Test connects, but a lock command fails
- Confirm the API key has Manage Devices / Lock permissions
- Run Sync Now so KyberGate has the device's UDID and serial
- Confirm the device is enrolled and supervised in Jamf School
"Device has no serial number" Run Sync Now to pull serials and UDIDs from Jamf School. Commands need a device identifier to target.
Some commands don't apply Certain actions require the device to be supervised. Most school-enrolled iPads are supervised by default.
Related Articles
- Complete Deployment Guide
- Enrolling iPads (see the deployment guide's iPad section)
Need help? Open the live chat in your dashboard (bottom-right) — it goes to a real person on our team.