Isaac Davenport
IT Systems Engineer
Specializing in identity and access management, endpoint administration, and SaaS infrastructure.
Featured Projects
Extension Attribute: Which Accounts Can Actually Unlock the Disk
CompleteA Jamf Pro extension attribute that enumerates every secure-token-enabled user on a Mac — the state FileVault depends on, that nothing in standard inventory reports.
Config Profile: Time-Boxed Admin Rights with Mandatory Justification
CompleteA Jamf Connect Temporary User Permissions profile that grants admin for 15 minutes, expires it automatically, and refuses to elevate anyone until they type a reason.
Config Profile: Blocking AI Coding Assistants in VS Code
CompleteA managed-preferences profile that enforces an extension allowlist in Visual Studio Code — permitting extensions broadly while denying the AI assistants that would send source code to unapproved vendors, and switching telemetry off.
Jamf Compliance Bridge
CompleteAutomation service that syncs Jamf Pro smart group membership into Okta and Microsoft Entra ID groups, so Conditional Access and authentication policies gate on live device compliance.
Platform SSO Rollout and Enrollment Remediation
CompleteRolled out Platform SSO across a 300+ device Mac fleet at Ontinue using staged pilot rings, then built and open-sourced a remediation script that detects and recovers devices where enrollment silently never completed.
Sanitized for public disclosure
Jamf Toolkit
In ProgressProduction-tested bash scripts, Extension Attributes, and configuration profiles for Jamf Pro, drawn from managing macOS fleets from 300 to 2,800+ endpoints.
Extension Attribute: Turning App Auto-Patch Receipts Into Patch Evidence
CompleteA Jamf Pro extension attribute that reads every App Auto-Patch receipt on a Mac and reports each title's version, timestamp and exit code into inventory — split into successes and failures, so a silently failing patch is visible.
Jamf Onboarding Automation
CompleteAutomated macOS onboarding at Ontinue with department-based paths, Jamf Setup Manager, and AutoPKG, cutting compliance time from 2+ hours to a self-service process across 300+ devices.
Sanitized for public disclosure
MDM Compliance Improvement
CompleteBuilt compliance verification and remediation scripts across 2,800+ endpoints at Infoblox, raising MDM compliance from 82% to 98%.
Sanitized for public disclosure
GCC High Federal Tenant Administration
CompleteBuilt and administered the separate GCC High environment for Infoblox federal operations — custom Windows imaging for 60+ federal users, Jamf Connect and Intune in dedicated federal tenants, and zero audit findings across two consecutive review cycles.
Sanitized for public disclosure
Okta Identity and Access Administration
CompleteServed as lead Okta subject-matter expert for a global IT organization — SSO and MFA configuration, app onboarding, and the full user lifecycle from provisioning through role change to offboarding across a 2,800+ endpoint environment.
Sanitized for public disclosure
Latest Writing
- Pelican: What I Learned Running My Own Infrastructure A homelab built on Unraid — separated storage tiers, redundant DNS, real backups, and monitoring. The same decisions I make at work, at a scale where I own every consequence.
- The Best Security Sensor We Had Was the Ticket Queue A credential-stuffing attack that showed up as a run of ordinary account lockouts — and why the shape of the victim list mattered more than the volume.
- Everyone Was Logging In Twice and I Just Accepted It A FileVault and Jamf Connect behavior that made every reboot a two-password event — why it happens, why turning it off means overriding Jamf's own recommendation, and the version of this problem people mix it up with.