Get Support
Recently active
Hey Jamf Nation! We're kicking off regular Product Office Hours: your chance to hear directly from our Product and Leadership teams - live - every week. Each session runs 45 minutes and centers on a theme. Think behind-the-scenes looks at Jamf, product how-tos or big-picture thinking. Speakers will walk through the topic and provide live examples, where applicable. When? Every Thursday, starting Aug 13th — 9am CDT / 3pm BST / 4pm CESTWhere? Register for the upcoming sessions here: https://jamf.it/ProductOfficeHoursYou can pop in for just 10 minutes or stay the full session each week! How your questions get answered:Unlike a free-for-all Q&A, we run this one community-style. Drop your question on this week's post before the session, then like 👍 the ones you most want covered. The most-upvoted questions get tackled live. Anything we don't get to, we'll answer right here on Jamf Nation within 24 hours. Why stop by?Hear straight from the people building what you use Get real answers
Cisco Secure Client (CSC): Version 5.1.12.146MacOS: Tahoe 26.5Current issue we are facing is that when enrolling new MacBooks into our environment we are seeing that Cisco Secure Client is no longer passing through deviceID to azure to pass through conditional access policies. Previously our environment was running JAMF conditional access, and our devices were enrolling without a problem. All applications were passing deviceID and going through conditional access policies (CAPs) without any blockers. Recently we have shifted over to platform SSO as per many people’s recommendation as the old method was being deprecated. Since then, we have noticed that most applications are still working without issues, but unfortunately Cisco Secure Client is failing to pass deviceID and is now being blocked by our Azure CAPs. The main difference that I'm seeing is that the previously enrolled devices also received a WJP certificate, while the new enrollment method no longer utilizes this check. We or
Hi Nation,Product Office Hours #1 - AI Governance: What is it and what can we do with it?Next session: Thursday, 13th August - 9am CDT / 3pm BST / 4pm CESTSpeakers: Sam Johnson, Akash Kamath & Matt BenyoRegister here: https://jamf.it/ProductOfficeHours 🧵 Before the call, this is on you: drop your question in the comments below, and like the ones you want to see answered. Q&A is built entirely from what gets submitted and upvoted here, so if you don't ask it, it doesn't get covered live.No questions, no Q&A, it's that simple. Anything we don't get to, we'll follow up right here within 24 hours.See you Thursday 13th!
If not, you really should check out https://github.com/Jamf-Concepts/Jamf-Extender (and take a look at the other repos under Jamf-Concepts while you're there). Versions for Safari, Firefox, and Chrome/Edge are available.I’m not going to list all of the capabilities of the current version, but a few that I’ve found to be _extremely_ useful are:The capabilities of MUT accessible directly from the Jamf Pro console Identify how may times a Smart Group is used as a Target or an Exclusion Convert unused Smart Groups to Advanced Computer Searches A Compare Profiles command to view the scope summary and which payloads are shared or unique (the settings in each payload are not displayed in the comparison however)Other areas where the extension adds capabilities are Blueprints, Jamf Security Cloud, and Jamf ProtectThanks to @Tribruin for calling out this very useful tool in the MacAdmins Slack #jamf-concepts-discussion channel
We have been testing 27 beta with every version and I'm not sure why so late in the beta cycle during beta 5 apple decided to add new pop ups. Currently I do not see a way to manage these.
Hi, I want to ask something about this issue. I’ll describe the test I’m performing.I have a macBook Pro enrolled with in Jamf Pro with Jamf connect. Authentication is done through MS Entra/Azure.The first user, user A, that logins gets a prompt to enable Filevault. User A is now a filevault enabled user.When restarting user A has to unlock the disk as expected.User A is logging out and user B logs in. Now this user is also able to unlock the filevault encrypted disk.User B is logging out and user A logs in again. User A shuts downs the macBook.And now comes the issue I’m facing. When restarting the macBook user B needs to unlock the disk. The name of user B is pre-filled and you have to enter B’s password. When pressing ‘option + enter’ you can choose for another user.So I thought, maybe because user B is the last user that was enabled for Filevault this user shows up. Still strange but let’s give it a try with user C. So after user A or B logs in and logs out again I log in with user
Hi All,Has anyone seen Jamf Self Service fail to run an otherwise-valid policy? Been looking at this for a whileWe use Alectrona Patch to install 99% of our Self Service apps with the below script. Whenever i run one of these policies through JSS i get an “Item Failed.” notification. The symlink sudo patch install <id> works perfectly when run manually as root, so i think this is a Jamf error rather than a patch error, though i am speaking to them about it.#!/bin/zsh# Variablespatch="/Library/Application Support/Alectrona/Patch/patch"appName=$4# Check script parameter valuesif [[ -z "$4" ]]; then echo "Missing Application parameter" exit 1fi# Install App${patch} install ${appName} --silentif [[ $? == 0 ]]; then echo "$appName installed successfully" exitelse echo "Install failed - error $?" exit 1fiThe Jamf policy itself looks completely normal: enabled, no exclusions, no site restriction, ongoing frequency, Running jamf policy -id X -verbose from terminal thr
Today we are releasing Jamf Pro 11.31; highlights include:App Management Status Criteria for Mobile DevicesThis release adds an App Management Status criteria for mobile device smart groups and advanced searches. You can use it to find devices with unmanaged apps (e.g., App Name is X AND App Management Status is Unmanaged), or on its own to list all devices with any unmanaged app. For additional information on what's included in this release, review the release notes via the Jamf Learning Hub. Subscribe to Jamf Learning Hub contentWhen logged in to the Learning Hub, click the Subscribe button (bell icon) on the release notes page to receive email when that content is updated (i.e., a new version of Jamf Pro is available). For more information about the Subscribe feature, see Jamf Learning Hub Watchlist. To access new versions of Jamf Pro, log into Jamf Account with your Jamf ID. The latest version is located in the Solutions section under Jamf Pro. Cloud Upgrade ScheduleYour Jamf Pro s
Engage. Empower. Elevate.When we started Mac Admins India, the vision was simple: create a place where Apple IT professionals across India could learn from one another, build meaningful connections, and strengthen the enterprise Apple ecosystem.On 1 August 2026, the Apple IT community came together at Radisson Blu Hotel, Outer Ring Road, Bengaluru, for the second edition of Mac Admins India Connect. What began as an idea to bring Apple IT professionals together has quickly grown into India’s largest community-driven conference dedicated to Apple enterprise professionals.What began as an idea has now become India’s largest community-driven conference dedicated to Apple IT professionals.Community FirstTechnology conferences are often measured by attendance numbers, sponsors, or session counts. While those are important milestones, the true success of a community event is measured by the conversations that happen between the sessions.This year we welcomed 370+ attendees from across India
With Jamf Pro 11.31, use app management status as criteria in smart groups and advanced searches, group blueprint components into component blocks, and control the layout of Self Service+. Be sure to check out the Jamf Pro release notes for all of the exciting new features and enhancements.Thank you for your continued support and feedback!
Running RSA MFA Agent on macOS Tahoe in a Jamf-managed fleet. At the screensaver unlock, a legacy `SFAuthenticationController` "macOS wants to make changes" dialog appears before RSA's own OTP prompt. RSA has pointed us at Apple and Jamf, with no clear next step yet.While isolating it, one test stood out. Writing a stock right to `system.login.screensaver`:```sudo security authorizationdb write system.login.screensaver authenticate-session-owner-or-admin```gives the modern unlock UI (wallpaper + password) on a managed Mac, but the legacy black-screen unlock prompt on an unmanaged one — same right, same OS, only variable is management. So the legacy unlock path still exists in Tahoe; something on the managed side is suppressing it.Anyone seen this, or know what MDM-side setting (profile, restriction, DDM) would cause it? Trying to work out whether this is an Apple thing or a Jamf thing before going back to either vendor.
It would be a useful feature in ‘Classes’ if, when adding members by specifying a group, that user group were synchronised.Currently, if you add teachers and enter a complete group at the top of the selection window (‘Member of group’), only the current status of that user group is recorded. Annoyingly, it is not updated or synchronised when new teachers are added.
Need to identify and generate a report of Intel-based applications installed on Mac devices.As this is required to know application compatibility and identify software that still relies on Intel architecture, especially in preparation for future macOS 28.0 releases and Apple's ongoing transition away from Intel-based technologies such as Rosetta 2.
Happy Monday! So I just came across this issue. When a user tries to change their password using Jamf Connect, they get this Kereberos error 4.So they go into Okta and change it there. Later Jamf prompts them that the Local Password and Network password don’t match. They are able to enter the old and new passwords and get the local mac password changed to match. But Jamf still shows “password expires in 0 days”.I didn’t do the Jamf Connect setup, it was here when I joined the company, so I’m not sure exactly how to start fixing this. I’m hoping you have some tips, maybe someone has seen this before, really anything. I’ll keep doing my research, but It’s always nice to get some expert advice.-Pat
In macOS Tahoe, the command to get the current AirPort network is not working as expected, and the SSID value is showing as <redacted>.Could you please suggest any alternative script or method to retrieve the currently connected Wi-Fi SSID name?This is required to help us deploy the Network Configuration Profile only when the Mac is connected to an out-of-office network.Thank you.
JNUC 2026 is coming to Kansas City, September 23–25*.Jamf CEO Beth Tschida sits down with Jen Kaplan to unpack this year's theme, *Power Up, and what's ahead for Apple device management.In this fireside chat, Beth explains why Kansas City's Power & Light District is the right metaphor for where Jamf is headed, how shadow AI is reshaping the work of Mac admins and CISOs, and gives a preview of one keynote moment: a workflow where the device tells you something is wrong before a frustrated user files a ticket.What's inside?What the JNUC 2026 theme "Power Up" means and why Jamf chose it for this yearHow Jamf is connecting Apple device management and endpoint security, and layering AI on topWhy shadow AI has become a day-to-day problem for IT and security teamsA preview of a JNUC 2026 keynote workflow: proactive device health before the support ticketHow to govern AI on an Apple fleetWhat the Jamf Nation Global Foundation is doing at JNUC 2026,CHAPTERS:0:00 Introduction: Jamf CEO Beth
Jamf Pro 11.30.2 (Jamf Cloud),SYMPTOMAn App Installer deployment stays IN_PROGRESS forever after the install hasalready completed successfully on the Mac. Once stuck, Jamf never issues anotherInstallEnterpriseApplication for that (Mac, title) pair. retryable is false, andper the docs "Retry all failed" does not cover in-progress deployments, so thereis no way back other than toggling the deployment off/on (a PUT to the deploymentre-dispatches it within minutes).WHAT MAKES THIS DIFFERENT FROM THE USUAL "STUCK IN PROGRESS" THREADSWe can point at a trigger. From /var/log/install.log on an affected Mac: until 2026-07-12: Will start wait for 1 apps to close with timeout: -1.0 from 2026-07-13: Will start wait for 1 apps to close with timeout: 172799July 13 is the day we set a global update deadline of 48h (previously: nodeadline, so timeout -1 = wait forever). Every stuck deployment we have datesfrom after that change. With no deadline, the install only ever happened whenthe user closed
Today we released Jamf Connect 3.12.0; highlights include: Changes and ImprovementsThe Jamf Connect login window now displays the time remaining before you can attempt to log in after an authentication lockout. To access new versions of Jamf Connect, log in to Jamf Account with your Jamf ID. The latest version is located in the Solutions section under Jamf Connect.Product DocumentationFor additional information on what's included in this release, review the release notes via the Jamf Learning Hub.
We’re seeing an issue on multiple (more than 10 Macs, multiple hardware specs) Sonoma (14.8.8) devices which have attempted the 14.8.9 update in the last week. The OS update seems to fail, and the machine reboots, but afterwards no users are able to login (login window shakes as if incorrect password was entered, for all accounts).Booting to recovery we can use the existing user accounts to unlock the disk without any issue, so doesn’t seem to be a SecureToken issue. Using the resetpassword option from Recovery doesn’t fix the issue either, the users are all still unable to login after rebooting to the normal drive. Safe mode doesn’t help either. We can thankfully backup the users’ files (via the terminal in recovery) to an external drive, but the system itself seems to be completely hosed, and has to be erased and have a fresh OS installed.Any ideas what might be causing this sort of issue? I’ve never come across something like this before.
So as we approach the inevitable coming of Self Service + we have noticed something that would be great to remove if possible to bypass some potential issues.In the Mac menu bar the Self Service + icon does not go away no matter what at the moment, and it also has a “Get software” option in the menu that does not apply to us. So I have the following questions:1: Is there a way to automatically hide or disable the icon from showing up?or2: Is there a way to customize what menu options the icon has so that it is more applicable to different use cases where optional software deployed through self service is not a thing?
Hey Jamf Nation!We're excited to announce SCIM-based provisioning and lifecycle management of administrator profiles in Jamf Account, now available in Beta.Inbound SCIM lets your identity provider push administrator profiles directly into Jamf Account without requiring those users to sign in first. Once configured, your IdP becomes the source of truth for administrator lifecycle events in Jamf. This beta supports Microsoft Entra ID and Okta as identity providers.Today, SCIM-provisioned profiles appear in Jamf Account, names stay current when updated in your IdP, and you can assign roles and privileges before an administrator's first login. This is the foundation for platform-wide administrator provisioning across Jamf Pro, Jamf Security Cloud, and other Jamf applications. When that work ships, your SCIM configuration carries forward with no changes required.When configuring your SCIM connection, you can also select the groups scope. Groups sync now but do not yet drive role assignments
Long ago we distinguished between our Staff and Student Macs by “installing” a DMG that just created a folder. We used the search term of “Packages Installed by Jamf Pro” with that DMG name. This has worked fine for us for the past 10+ years. We installed this package on Student Macs and didn’t install it on Staff Macs. If we needed to convert a MAc from Student to Staff, we just used the Jamf Pro capability to “Uninstall” that package. That removed it from the list of “Packages Installed by Jamf Pro”. It seems that with the (no longer recent) removal of Jamf Admin and the ability to index packages, the ability to “Uninstall” packages and DMGs has gone away as well. So we can still install that DMG to tag the Mac as a Student Mac. However, we can no longer “Uninstall” that DMG. Which brings me to my question: How do I remove an item from the “Packages Installed by Jamf Pro” list? This isn’t the same as the package receipt list that you get from running pkgutil --pkgs. I am hoping tha
Thanks again, @boberito! https://github.com/boberito/sc_menu
We are in the middle of a refresh for school secretaries from iMac to MacMini and are noticing an issue where some MacMini’s are not checking in with Jamf, so we are not able to push anything out to them. We used Data Migration, with Time Machine data and restored from that. We did not move over previous JAMF hidden admin account, only the account need for the user. Any thoughts on what may be happening?
https://community.jamf.com/p/jamf-heroes
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!