Skip to main content
Question

Jamf Now wont deploy apps when behind a Firewall

  • January 22, 2026
  • 5 replies
  • 51 views

Forum|alt.badge.img+2

Hi all

 

I have a fleet of Mac Pros all sitting behind a firewall.

 

All traffic - IPs, ports have been allowed as per the Jamf documentation.

 

All Macs can sync and restart however apps can't be deployed or updated.

 

Am I missing something? I even have the entire APNS IP range allowed but still nothing.

 

Any help or advice would be much appreciated

5 replies

h1431532403240
Forum|alt.badge.img+6

Since your Macs can sync and restart but not deploy apps, the issue is likely with connectivity to Apple's CDN serversrather than APNs. App deployments require access to Apple's content delivery network hosts like *.mzstatic.com*.phobos.apple.com, and *.itunes.apple.com.

APNs only handles push notifications to wake the device - the actual app download comes from Apple's servers.

Recommended steps:

  1. Download and run Jamf Check on one of the affected Macs. This tool will test connectivity to all required Jamf and Apple endpoints, showing you exactly which FQDNs or IPs are being blocked.
  2. Ensure the following hosts are allowed (TCP 443):
    • *.mzstatic.com
    • *.itunes.apple.com
    • *.apple.com
    • appldnld.apple.com
    • configuration.apple.com
    • iosapps.itunes.apple.com
  3. As a quick test, try connecting the Mac to a mobile hotspot and deploying an app. If it works, it confirms the firewall is blocking something.

Reference: Use Apple products on enterprise networks


Forum|alt.badge.img+2
  • Author
  • New Contributor
  • January 23, 2026

Hi

 

Thank you very much for your advice, I will be sure to try what you have suggested and report back.

 

Thanks again


Forum|alt.badge.img+12
  • Contributor
  • January 26, 2026

Running Mac Evaluation Utility will show you the state of the currently allowed network connetions required for Apple devices and services. I find this a very good tool for these situations.


Forum|alt.badge.img+2
  • Author
  • New Contributor
  • January 26, 2026

Thank you both very much for your suggestions

 

Both of these tools are a huge help in getting me where I need to be, they provide so much more info and assistance than anything ive been using so far.

 

Once again thanks


Forum|alt.badge.img+2
  • Author
  • New Contributor
  • February 18, 2026

Hi

 

So thanks to the above suggestions things are working much better than before. Im able to install App Installers, which I assume are coming from the App Store?

 

The remain issue is that I am unable to install custom apps.

 

Both Jamf Check and Mac Evaluation utility show connectivity to all required FQDNs.

Im seeing a whole bunch of IPs still being blocked and they relate to Cloudfront and AWS.

 

Des anyone know if custom apps get saved or stored on one of these cloud providers?