Description
Starting April 28, customers are able to participate in an open beta for Next Generation Threat Prevention (NGTP). This article provides more information on what NGTP is and how customers can participate in the beta.
Note: The NGTP beta rollout for the *.edu.protect.jamfcloud.com stack will be enabled at the end of the week, on May 1, 2026, at 10am CDT.
What is Next Generation Threat Prevention?
The current threat prevention offering is being upgraded with new, outcome-specific engines that enable detection and protection capabilities currently underserved by report-only analytics.
An engine is a modular detection capability that focuses on a specific category of threats or techniques. Each engine represents a distinct detection strategy, such as static file analysis, behavioral monitoring, or fileless attack detection, and is designed to be independently configurable, reportable, and explainable.
The available engines in the NGTP open beta are:
Malware and riskware
This engine uses a combination of static and behavioral analysis to detect malware, riskware, adware, unwanted software, and more.
Adversary tactics
This engine detects attacker behaviors in real time by monitoring system, user, and process activity. Aligned with the MITRE ATT&CK tactics, and enriched for macOS-specific attacker techniques.
System tampering
This engine protects the integrity of the Jamf Protect agent from tampering and removal.
Fileless threats
This engine detects memory or runtime threats that bypass traditional file-based defenses, including trusted tool abuse and stealthy memory-based execution techniques.
When using NGTP, administrators can enable a Jam Managed threat prevention strategy, which sets all engines to block and report, or a custom strategy that lets them choose between disabled, report-only, or block-and-report for each engine.
For more information on the engines, see the Learning Hub documentation for the beta.
The following features are not supported in the NGTP beta:
Jamf-managed exceptions
Details and exceptions for beta analytics
Custom analytic sets
Analytic remediation with Jamf Pro smart groups
Beta Details
Requirements
Jamf Protect agent version 8.12.0 or later must be installed on the destination computers.
This beta feature can be enabled by any user who is assigned permission to edit plans on the tenant.
Enablement Steps
Customers can enable the beta and create a plan with NGTP directly in the Jamf Protect macOS Security portal, following the steps below.
In the macOS Security portal, go to Plans and click Create Plan.
Provide a name and description for the plan.
Click Enable beta under Threat Prevention.
Check the box to agree to the terms of the beta agreement and click Agree.
Select which Engines to enable, Managed or Custom.
Save the plan after all other settings are configured.
Deploy the plan to a test device.
Note - Once the beta is enabled, additional plans can be created using either Managed or Custom threat prevention strategies. Each tenant only agrees to participate in the beta once.
Feedback and Assistance
If customers reach out to Jamf Support for assistance with the NGTP beta, the two options below exist:
Beta forum: We can direct customers to post in the available beta forum on Jamf Nation.
Slack: #ask-public-beta-ngtp can be used to get assistance with customer questions on the program.
Resources
Learning Hub:
Internal Only:
Confluence
Next-Gen Mac Threat Prevention (may be slightly outdated but still provides a good overview)



