Skip to main content
See All Integrations

Iru Endpoint, formerly Kandji

Use selected Iru Endpoint Management device data in Pomerium policy through a custom external data source.

Custom customer-owned connector

Categories
Context Data Sources, Device Management

Overview

Iru Endpoint Management, formerly Kandji, manages Apple, Windows, and Android endpoints. Its API can expose selected device inventory and status records. A customer-owned adapter can map approved fields to Pomerium Enterprise external data.

Selected Iru Endpoint data can add organization, inventory, or security context to an access decision. A small, reviewed record set is easier to understand and protect than a broad export of the source system.

Pomerium can evaluate selected Iru Endpoint records after a customer-owned adapter maps them to supported request or user keys. Pomerium does not call the vendor API directly and does not manage the source system.

How it works

Create an Iru API token with only the required permissions. Read selected device records with pagination. Use the current tenant URL and current API limits.

Map only the fields that policy needs. Each imported record must use a Pomerium-supported foreign key: user.id, user.email, request.ip, or request.client_certificate.fingerprint.

Publish the records through a protected JSON, CSV, tar, or ZIP source. Configure Pomerium Enterprise to poll that source. Evaluate the imported fields with a Pomerium Policy Language record matcher.

Example

An adapter reads a selected Iru Endpoint inventory field and associates it with a verified user email in the organization record. Pomerium can evaluate that user record. It does not treat the endpoint record as a cryptographic assertion from the current device.

Considerations

  • Iru documentation and API hosts can still use Kandji names. Follow the current tenant URL, pagination rules, and API limits.
  • This is a customer-owned connector pattern, not a built-in Pomerium connector.
  • External data sources need Pomerium Enterprise and update on a polling schedule.
  • A vendor device or asset ID does not prove which device made the current Pomerium request.

Sources and official resources

  • Use selected Jamf Pro device data in Pomerium policy through a custom external data source.

  • Use selected Microsoft Intune device data in Pomerium policy through a custom external data source.

  • Use selected Kolide inventory records in Pomerium policy through a customer-owned external data source.

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo