About This Architecture
Enterprise device management network topology integrating Jamf Pro, FortiClient, Microsoft Defender, and Entra ID across DMZ, core, distribution, and access layers. Traffic flows from WAN through edge router, perimeter firewall, and WAF to VPN gateway, core load balancer, and DNS resolver, then to distribution routers serving server and support VLANs, and access switches managing macOS and Windows endpoints. Managed devices communicate with cloud services—Jamf Pro with APNs and ABM, FortiClient agents with EMS server and cloud, Defender ATP with security center, and certificate clients with Windows CA via Jamf connector. This architecture demonstrates defense-in-depth with segmented VLANs, centralized identity via Entra ID, endpoint protection agents, and ServiceNow integration for IT operations. Fork and customize this diagram on Diagrams.so to adapt VLAN ranges, add additional security controls, or integrate alternative MDM platforms. The design supports hybrid cloud and on-premises device management while maintaining compliance and least-privilege access.