Back to blog

Jamf Pro: detect unmanaged apps on iPhone and iPad

Article created September 7, 2026 · Source reviewed September 7, 2026 · Official source: Jamf Pro 11.31 · Topic: MDM, mobile apps and compliance

Jamf Pro 11.31 adds an App Management Status criterion to mobile-device Smart Groups and advanced searches. IT teams can now find iPhones and iPads with managed or unmanaged apps and combine that status with an app name. This visibility is useful when it feeds an explicit compliance policy, not an automatic removal rule.

1. What Jamf adds to mobile inventory

The official documentation lists two values for the new criterion: Managed and Unmanaged. Used alone, it can list devices that have at least one unmanaged app installed. Combined with another criterion, Jamf gives the example of matching an app name with an unmanaged status.

The signal therefore answers a precise question: is the observed app under management control? It does not prove that the app is malicious, that its data is exposed or that the device is automatically noncompliant.

2. Turn an inventory result into an actionable rule

A useful Smart Group should separate business apps that must be managed, personal apps allowed in a BYOD model and software prohibited by a documented policy. Without this taxonomy, a global list of unmanaged apps mostly creates noise and may trigger disproportionate action.

Remediation then depends on the scenario: offer the app through the internal catalogue, reinstall its managed version, remove only corporate data or open a ticket. Teams should verify actual behavior with a pilot group before connecting the criterion to compliance, notifications or automation.

3. What does this change for a Belgian or French organization?

A small business can identify the few business apps installed manually and still outside MDM control. A mid-sized or large enterprise can design controls by population, country, subsidiary or risk level, with consistent criteria across Belgium and France. A public body can better separate institutional apps from permitted personal use.

Management status and app inventory remain data that require governance. In a GDPR context, collection, access and retention should be limited to the defined business purpose; users should receive information appropriate to the enrollment model; and the presence of a personal app should not become a security conclusion without analysis.

4. Underside analysis: connect catalogue, identity and compliance

Our view is that this criterion should close an operational loop: Apple Business Manager provides licences, Jamf distributes the managed app, inventory confirms its status and compliance triggers proportionate remediation. The value is not the Smart Group alone, but evidence that the expected app reaches the right user and remains managed.

This approach complements the governance framework for an MDM app catalogue and data separation in Apple managed apps. It must also account for enrollment type: a supervised corporate device and a personal device do not justify the same visibility or response.

5. Recommended implementation plan

Objective: turn app-management status into a reliable and auditable control without confusing inventory, risk and compliance decisions.

Audit your Apple app management

Official source: Jamf Pro 11.31 Release Notes — Mobile Device Smart Group/Advanced Search Criteria (accessed September 7, 2026).