Presented Friday, July 10, 2026, at Mac Admins Conference 2026, Penn State University. Co-presented with Justin Gianelloni.

Watch on YouTube | Download the slides (PDF)

Description

Justin Gianelloni and I needed managed Macs to request temporary admin access through JumpCloud, but we did not want a JumpCloud API token stored on every Mac. We built Hookshot to keep that credential on a server instead. The Mac proves it is enrolled, Hookshot decides whether the request is allowed, and only then does Hookshot call JumpCloud.

JIT admin is the example we use throughout the talk. A user chooses a reason in SwiftDialog and requests a twenty-minute window. The Mac applies the local group and sudo changes immediately, a LaunchDaemon revokes them automatically, and the JumpCloud access request provides a second control. During the elevated session, eslogger captures process, file system, and authentication events for Elastic.

Hookshot is a Python service built with FastAPI. Its API is deliberately small: managed devices can ask for specific approved operations, not make arbitrary JumpCloud calls. FastAPI’s generated OpenAPI documentation also gives us a concrete list of what the fleet is allowed to request.

We walk through the request and revocation flow, the Jamf profiles and PPPC settings it depends on, and the work still in progress. Device identity is moving to MDM-issued SCEP certificates and mutual TLS, and Hookshot now has to be monitored like any other production dependency. JIT admin is one use for this design; the same boundary can protect other directory operations that would otherwise require placing a broad API token on an endpoint.