Integrations
Connect Arbiter to your existing MDM, identity and SIEM tooling.
Available now

Arbiter reads device compliance state from Intune and enforces it at the network layer. Compliant devices authenticate normally; non-compliant devices are quarantined to a remediation VLAN automatically.
- Compliance-based VLAN assignment via RADIUS attributes
- No additional agent required on endpoints
- Works alongside 802.1X and MAB policies
- Supports Azure AD joined and hybrid-joined devices
Arbiter reads managed-device status and inventory from Jamf Pro and uses it in access policy, so Macs and mobile devices enrolled in Jamf can be treated differently from unmanaged ones. The policy signal is managed state rather than a compliance verdict.
- Managed-device status as an access policy condition
- Mac, iPhone and iPad inventory, including serial numbers
- OAuth client credentials (Jamf Pro 10.49 and later) or legacy basic auth
- Change of Authorization when a device leaves MDM enrolment
Outbound HTTPS push of Arbiter security events into your SIEM. Per-tenant destination configuration with vendor-specific adapters over a shared transport. No inbound ports on your firewall.
- Microsoft Sentinel via Data Collection Rule (OAuth client credentials)
- Elastic / Elasticsearch via the _bulk API with an API key
- Syslog over TLS (RFC 5424 / RFC 6587) for Graylog, Wazuh, QRadar, Rapid7 InsightIDR and the rest
- Splunk HEC token-auth, native batch payload over 8088 or 443
- Generic HTTPS webhook with a configurable auth header covers Datadog, New Relic and custom collectors
Coming soon
The following integrations are in development.
REST API for policy management and log export.