Get Support
Recently active
Hey Jamf Nation! We're kicking off regular Product Office Hours: your chance to hear directly from our Product and Leadership teams - live - every week. Each session runs 45 minutes and centers on a theme. Think behind-the-scenes looks at Jamf, product how-tos or big-picture thinking. Speakers will walk through the topic and provide live examples, where applicable. When? Every Thursday, starting Aug 13th — 9am CDT / 3pm BST / 4pm CESTWhere? Register for the upcoming sessions here: https://jamf.it/ProductOfficeHoursYou can pop in for just 10 minutes or stay the full session each week! How your questions get answered:We run this one community-style. Got a question? Drop it in the comments on each week’s post ahead of time if you want it on our radar, though you don't have to. We'll be taking questions live on the call too. Anything we don't get to, we'll follow up right here within 24 hours. Why stop by?Hear straight from the people building what you use Get real answers to the question
Hello,I manage a fleet of iPads used for exams with my on-premises Jamf Pro instance. I push a configuration profile to restrict all of the iPad’s features and only allow students to access Safari and a whitelist of approved websites.I was informed that students might be able to use ChatGPT on the iPads by exploiting a vulnerability.I haven’t been able to verify this yet, but is there a way to block access to ChatGPT through a configuration profile?Thank you in advance for your help.
We have a Jamf Pro license and according to what I can see Composer is part of this. But I can not find this software anywhere when I log into the backend ? - Where can I download this ?
We have one of our users who is trying to take their macbook off the domain. When they take their macbook and establish it on a network that is not our own, they cannot get signed into their computer. The machine will error stating incorrect username or password while off the networkWe attempted to setup active directory through the general settings area of Jamf Pro, we established “Directory Bindings”, entered our domain information. The computer OU format of OU=OU1,OU=OU2,OU=OU3,DC=DC1,DC=DC2 and went into “User Experience” and ensured “Create Mobile Account at Login” was checked. Now I am not sure what else I missed in setting up the domain or which settings we need to enable so our user can take their device offsite. I do not want to remove the configuration/enrollment from the device or create a local account. Does anyone have any suggestions?
Nobody knew what anyone else had builtThe first real AI problem on our team had nothing to do with model quality. It was that dozens of people had each built something genuinely useful, and none of them knew about the others. That’s where CSAssistNOW came in. All applications I have developed with AI end in the word “NOW” because it is directionally accurate to the time it takes to build, it is catchy, and almost a little bit annoying. It’s just a shared place to publish and find the prompts and skills people build.There are four reasons we wanted this. Visibility - Once a department gets past a certain size, AI use can very quickly become fragmented. Someone automates a renewal summary, someone else builds an account brief, then another builds a risk status dashboard. A library helps make the work visible and legible. You can see how AI is actually being used vs. how it’s supposed to be used, or what you see folks using it for on social media. Basic social features were added to try
I have a problem where some users are unable to enroll new devices in Jamf School. I use enrollment via Entra. After entering their email address and password, it just spins for a while and then returns to the Entra window saying, “You can’t sign in right now. Please try again.”When I check the sign-in logs in Entra, they show “successful” several times, but no failed attempts. However, this does not affect all users—some are able to sign in and enroll devices, which is what confuses me.Has anyone run into the same issue?
Hi,Pretty new to Jamf and Mac MDM but seem to have the handle on the majority of stuff. I’m having a single issue with the users enrolling the devices into PSSO during the simplified set-up. I am pretty certain it’s a Conditional access policy we have set within our tenant that blocks access to any cloud resources from Uncompliant devices. The guidelines suggest - “The User Registration app for Device Compliance created when you connected Jamf Pro to Intune must be added as an exclusion in any policy that may prevent users from registering their devices.”And from the logs I can see this is the exact application that is getting blocked on the policy.The problem, even if I add the exception for this application into this conditional access policy it will still get blocked.If I add the user to an Exception group, the device enrols perfectly fine. Not sure if anyone else has had a similar issue?
Can someone help me how to block copilot app record option for corporate ios devices, i tried adding xml dictation on device apps> app configuration to block but did not worked
Hi Nation,Product Office Hours #4 - Jamf's Engineering AI: Nighthawk - A peek behind the curtainNext session: Thursday, 3rd Sep - 9am CDT / 3pm BST / 4pm CESTSpeakers: Akash Kamath, Chief Technology Officer, Martin Barnard, Senior Product Manager & Justin Wilke, Principal Enterprise ArchitectRegister here: https://jamf.it/ProductOfficeHours 🧵 Got a question? Drop it in the comments below ahead of time if you want it on our radar, though you don't have to. We'll be taking questions live on the call! Anything we don't get to, we'll follow up right here within 24 hours.See you Thursday 3rd!
Over the summer some of our computers has lost our Wi-Fi profile. I wonder what’s the best solution to get it back. For the moment they are using our guest Wi-Fi. But it’s very limited for the users so we need to get the profile back.I’ve created a smart computer group that show all the computers that don’t have the profile. Should I put the group in the scope? Won’t the loose the profile again when they’re not in the smart group anymore?
Hello all,First-time poster on Jamf Nation, so please criticize formatting, grammar, etc.We use Bomgar Remote Support on our Macs, but when deploying to a test machine running Sequoia, I get the message "Allow Remote Support Customer Client to find devices on local networks?" It looks like a PPPC popup with options to "Don't Allow" or "Allow", but I can't find a corresponding PPPC setting. We already have Accessibility, SystemPolicyAllFiles, and ScreenCapture set up according to this deployment guide, and I don't see another PPPC option that looks related to this error message. I'm not even sure why this is a permission that needs to be allowed. It feels like the Windows message to "allow this device to be discoverable on local networks," but it's going the opposite way. Why would I need permission to go out on the network and connect to the Bomgar server from my endpoint? Has anyone else seen this popup before or something similar?
Has anyone been getting unsuccessful GSX warranty lookups this week? I have been getting them since yesterday.
Hello Team,We are currently using Jamf pro + Jamf Connect for privilege elevation on our macOS devices. From an audit and compliance perspective, we are looking for a solution that can monitor and track user activity after elevated privileges are granted and can Alert .Specifically, we are interested in capturing and reporting on:Commands executed using elevated privileges (sudo/admin actions) Applications launched while elevated System configuration changes Software installations/removals Security-related modifications Detailed audit logs for compliance and forensic investigationsWe would like to understand how other organizations are addressing this requirement in their macOS environments.Are there native Jamf Pro, Jamf Connect, capabilities that provide this level of auditing? If not, what third-party solutions are commonly integrated with Jamf pro for monitoring privileged user activity? Has anyone implemented this using CrowdStrike, SIEM/EDR platform? What has been your experience
Hi.We’re using Jamf School as MDM (so please do not tell me all the wonderful things available in Pro 😅 ).Setting up MacBook Neo’s as new student devices. We want to block applications as: FaceTime, iMessage, Phone, iPhone mirroring during enrollment. As of today the only “half ass” solution is the “Safelist and Blocklist” payload, but this is deprecated : Are there any other good solutions for getting this to work?
My company has been using Jamf Pro to manage iPads for several years. I’m trying to get our Jamf Pro account configured with SSO using JumpCloud SAML and I have a few questions.First of all, I’m new to jamf and not too familiar with the nomenclature. I have an account in our Jamf Pro subscription but not in Jamf Account (apparently). I created a Jamf Account but it doesn’t seem to be connected to our Jamf Pro subscription in any way. I’m assuming that the Jamf Account is some umbrella account that manages all the other Jamf subscriptions (education, pro, etc.) Is a Jamf Account necessary if we only have a Jamf Pro subscription?If I’m reading the docs correctly, SAML is the deprecated way of managing user logins for Jamf Pro and we’re supposed to use OIDC from our Jamf Account account. Is that correct? We are not looking to do anything fancy through SSO, I just want to manage my employee’s Jamf Pro accounts. We’re not building apps or anything else that need OIDC.Can I just use
Hello fellow Jamf Admins,I would be extremely grateful if anyone has come across this App before (Hospital setting) called, “CBORD Mobile Inventory”. I am trying to add the App Config settings like I’ve done for plenty of our other Apps, but this particular App won’t give me a break. Below is a screen shot of what fields need to be filled out and the App Config I came up with and verified via AI. I am at a loss right now. The last thing we want is for our end-users to have to enter the data manually as that would be a nightmare. Any assistance would be very much appreciated. App Config I’ve tried (certain fields have been changed for obvious reasons). <dict> <key>serverURL</key> (<===== I have also tried “APIURL”) <string>https://netmenu4.cbord.com/NetMenuAPI</string> <key>appClientId</key> <string>xxxxxddddfffcxxxxxxxx</string> <key>region</key> <string>us-east-1</string> <key>
New Fortinet customer here. We are testing always-on IPSec VPN (split tunnel) on macOS 26 Tahoe.I have all the Fortinet recommended MDM profile payloads deployed to my test Macs (SEXTs, TCC/PPPC, Notifications, Content Filters, Login Items, etc). But Im still seeing a couple issue, including these 2:1 How do I suppress this user-facing pop-up: "FortiTray" Would Like to Add VPN Configurations All network activity on this Mac may be filtered or monitored when using VPN.2 Once approved (which is required for some reason), a virtual ‘VPN’ interface is INSTANTLY created in macOS Network Settings. Yet this interface is literally unusable, and never becomes active. And users are able to remove it manually if they so desire (i.e. it’s not locked). If a user does NOT allow this VPN, this pop-up will appear persistently until action is taken.How can I remove this pop-up and related interface? I dont want end-users to see this in the UI since it isnt ‘real’ and will just lead to confusion and fr
Hi all,I hope I'm posting this in the right place, but I am experiencing an issue with my jamf school shared iPad deployment regarding display names.From the list of selectable users, most users have their first name listed, but for a very select few users, their accounts are listed with their last name instead of their first name. This has become confusing for the younger students here at the school I manage. Hope that makes sense.I don't know why this is, their first names only range between four to six characters, and there aren't any users who share the same first or last name as the affected users in the system. If I could list their entire name that would be ideal, but I'm willing to take any advice or solutions to this problem.My users are provisioned through SFTP sync and uploaded to ASM. I have checked their users through Jamf and it looks like the first and last name are being populated correctly.Thanks!- sammy
Hello everyone We are trying to deploy FortiClient VPN only from this link https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/76cde386-1f8c-11ef-8c42-fa163e15d75b/FortiClient_7.4_Jamf_Deployment_Guide.pdfthe Application installed perfectly but we have issue with configuration of the app1- To grant FortiTray permissions to load and grant network access.2- To grant full disk access to load the following FortiClient processesI have made the same as what they mentioned in the pdf but the user get popup to allow them.what I want is:1- These configuration only install if they install FortiClient.2- Not popup any thing to the user when install FortiClient to allow for permission3- If someone can please shared with me the configuration.
Hi all !How can I enable/disable admin rights to change wifi setup, by script or config profile ?It’s located graphically in the advance pane on the wifi preference pane. Thank for all of your suggestions :-)
Hi all,I'm running into an issue with device naming in Jamf School (not Jamf Pro) and could use some clarification.Setup:Device: Mac mini (2024), macOS 26.6.2Enrollment: Automated Device Enrollment (User Approved Enrollment)Device Details > Name field shows "Set by policy"Issue:The Mac's local computer name was changed after enrollment (directly on the device), but this change is not reflected in the Jamf School console — the inventory still shows the old name. I tried the "refresh" button next to Details on the device page, but it does not pull in the updated name.Questions:What exactly does the "Enable Renaming Devices" checkbox under Organization > Settings > Enrollment do — does it affect already-enrolled devices, or only new enrollments/Setup Assistant?Since this device's name is "Set by policy" (likely from the ADE naming scheme/template), is there a way to sync the device's current local name into Jamf School's inventory, or does Jamf School always treat the naming poli
Through guided simulations, discussion, and some time with Jamf subject matter experts, you will get direct practice building and deploying blueprints in this workshop. It’s free, it’s two hours, and it’s hands-on: you’re not watching a demo, you’re doing the work.Register now and pick a date and time once you’re logged in with your Jamf ID. Can’t make this one or want to explore more first? Watch the Jamf Short video for Jamf Pro, Jamf School, or Elevate customers. Read the blueprints documentation for Jamf Pro, Jamf School, or Elevate customers. Check out the Jamf Nation Live demo session on the shift to the DDM only life. Learn how to configure identity and access management, a prerequisite for blueprints, with this training series. Quick Reminders Blueprints will also be covered during the Level Up full-day, hands-on learning experience prior to JNUC in a few weeks. Come join us in person! Stay up to date with all the latest training videos, release notes, Jamf Shorts, and
Hello everyone,This year we’ve got aboout 300 Macbook Neo’s. About up to 5% on the get an error. We enroll them just like we always have. The users log in with their Entra credentials during onboarding. After a while when the login is processed an error message pops up as shown bellow:The only thing for us to do is to format the drive and reinstall the computer. Then the users does the same without any problems. We had never had this error message before until Macbook Neo.Does anyone know we we get and/or what we can do to prevent it in the future?
If you are using SSO configuration and receive the following notification in Jamf PRO or your Jamf Account:“ SSO configuration will be read-only from Thursday, Sept. 10, 5 p.m. CDT to Friday, Sept. 11, 10 a.m. CDT due to maintenance. Creating or editing connections will be unavailable. Login won't be affected. “ Please prepare a standard user account (not an SSO account) in Jamf Pro under:Setings → System → User Accounts and GroupsThis account can be used as a backup to ensure that you can still create or edit configurations in Jamf Pro if there are any issues with your SSO login.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!