Get Support
Recently active
Today we are releasing a maintenance version of Jamf Pro; this release addresses the following product issues:Jamf Pro Server: Security IssuesJamf provides the CVE-ID for security issues with high or critical severity when possible.[PI207065] Fixed: A vulnerability within the Jamf Pro XPC validation. Jamf Pro Server[PI-1418] Fixed: The enrollment process for computers with macOS 26.6 or later may fail during Automated Device Enrollment or user-initiated enrollment with error code 71 (JBEnrollErrorKeyRecon). Subscribe to Jamf Learning Hub contentWhen logged in to the Learning Hub, click the Subscribe button (bell icon) on the release notes page to receive email when that content is updated (i.e., a new version of Jamf Pro is available). For more information about the Subscribe feature, see Jamf Learning Hub Watchlist. For additional information on what's included in this release, review the release notes via the Jamf Learning Hub.To access new versions of Jamf Pro, log into Jamf Account
Hello everyone 🙂!I was wondering if any of you managed to make SSO work for SMB share with Platform SSO and Entra? (no jamf connect)I found this documentation on Microsoft learning hub, but as i’m still a newbie i’m not sure how to implement it yet.The idea is that i want to connect automatically to the share at the user login with SSO, for now it is manual and with the password which is not ideal if we want a passwordless environment.Any tip is welcome, thank you for your help!!Joséphine
Can we clear Activation Lock via an API Call?
I recently traveled to the Matter Career Readiness Institute (MCRI) in Victoria Falls, Zimbabwe to teach a macOS fundamentals and essential skills workshop alongside my teammate, Tyler Davis. MCRI's mission is to train students for jobs in the tech industry and create opportunities for those who might not otherwise have a clear path forward.We knew the students had potential before we arrived. Our MCRI intern, Anita, had just joined us full-time as a Client Platform Associate,* and hiring her was undoubtedly one of the best decisions our team has made. While I didn't expect the whole class to be like Anita, I had a feeling I'd catch glimpses of her intellect and drive in them.When we walked into the room, everyone was focused and ready to begin. As a woman in tech who spent the earlier years of her career struggling to be taken seriously and have her voice heard, seeing them all genuinely eager to listen was a full circle moment. Part of why I cofounded the Women in Tech Apple Admins g
If we want to use Jamf’s built-in Patch Management notifications to let clients know about new patches as they become available in Self Service, they will receive a notification for each patch title as their Macs come into scope for each patch policy. That’s not really a big deal if we only push out one or two patches at a time, but say after Patch Tuesday… yikes! That can easily result in a string of notifications which can get pretty annoying. Additionally, there may be situations where notifications do not behave as we would expect, such as with PI104511, which can result in Self Service notifications not consistently appearing in the Notification Center when they are scheduled to do so, resulting in unpatched apps quitting unexpectedly when they reach their install deadline. This is where we found ourselves and why we built our own patch notification workflow. It leverages jamfHelper and a Smart Computer Group to send our clients one notification each day while patches are availabl
Hi, Our company WiFi uses user network creds to join, but the window that pops up for this has a certificate dropdown box (with several items available). The users get confused and start trying these. Is there a way to remove this box for at least this one SSID? Thanks in advance, -Pat
Hi all,I'm running 2 macOS VMs on a bare-metal Mac (host is also macOS). I'm seeing inconsistent iMessage sign-in behavior depending on the Apple ID type and whether it's bare metal or virtualized:Managed Apple ID (ABM-issued): signs into iMessage fine on the bare-metal host.Same Managed Apple ID: fails to sign into iMessage inside the VM on the same physical machine.Personal/basic Apple ID: signs in fine in the VM without issue.Has anyone run into this specific combination — MAID working on bare metal but not inside a VM, while a personal ID works fine in both?
I was reminded about DDM being the method used to supply iPhones with updates going forward.This article (Managed Software Updates End User Experience for Mobile Devices • Jamf Pro Documentation 11.30.0 • Jamf Learning Hub) talks about DDM being used for the Download and schedule the install feature and this article (General Requirements • Jamf Pro Documentation 11.30.0 • Jamf Learning Hub) routes towards Blueprints for setting up DDM. Will we still be able to use the managed software updates in any capacity or will we need to set up Jamf SSO and use Blueprints once this update rolls out?
Mac Apps, App Installers, Jamf Apps, Jamf App Catalog… whatever name you know it by, the feature found in your Jamf Pro server at Computers – Mac apps – Jamf App Catalog is a great tool for deploying and patching many commonly used Apps which aren’t available through Apple’s App Store. For the sake of clarity, I will refer to them as App Installers for the remainder of this post. App Installers do have some caveats which are documented here. Being aware of those is well and good, but even the most experienced admins can make mistakes. Jamf Pro will not alert you if you have done something like overlapped scopes for different deployments of the same App Installer title.If this occurs, that App Installer will likely cease to recalculate its deployment as more Macs are added to the Computer Group it is scoped to. If you toggle the “stuck” app’s deployment off and back on again, it’ll force it to recalculate and the Macs it was missing will begin to receive it.This overlapping scope behavi
Hello:I’m looking at this document about setting up Federated IDs in ASM:https://support.apple.com/guide/apple-school-manager/intro-to-federated-authentication-axmb19317543/webWe have about 300 students in Apple School Manager with their school email addresses and Managed Apple IDs. They look like this:email: slynch30@students.mpslakers.commanaged: slynch30@appleid.mpslakers.comWe’re trying to set up our new students using Entra so they can use SSO. Students are currently in Entra using their email address as their UPNs.Is this possible? How, if at all, will this affect our other 300 students in ASM?
Is there a statuspage for cloud based JamfPro?
Connect 3.4.0Self Service+ 2.12.0OS 26.1 Tahoe (Many other machines on 26.0.1)I can not get this prompt to close no matter what I do. Everything in the back end seems fine with my machine and my connection to Jamf, self service, connect, everything, it all seems fine. Anyone have any ideas? I did not see this issue prior to updating OS from 26.0.1 to 26.1 and that is the only thing I can think of that may be triggering it. I have tried deleting associated keys and allowing them to regen, I have tried flushing and re-pulling Config Profiles and Policies. P&S settings are all good. I have fond that if I leave the window there for 30min or more, it will finally close after entering PW and selecting Always Allow, but then comes back up after Reboot.
• iOS 26.6 and iPadOS 26.6 address almost 90 security vulnerabilities • macOS Tahoe 26.6 has more than 130 vulnerability fixeshttps://support.apple.com/en-us/100100
I am attempting to run policies on one device and receive an error "The index 999107 is invalid". I am able to run jamf recon and jamf manage. I renewed the Jamf framework. I also ran it with -verbose and nothing stands out.
Hello everyone 🙂,I recently set up PSSO with Microsoft Entra ID, using Jamf Setup Manager with Simplified setup and Secure Enclave enabled. Everything is working fine except for the user profile picture synchronization. The profile picture exists in Entra. I can’t figure out how to get it to work. Is there a specific permission I should add in Entra, through Microsoft Graph for example?Thanks for your help,JoséphineMac os version Tahoe 26.5.2, Company Portal v. 5.26206.0
Has anyone tried to disable iCloud Private Relay? I'm using the Plist below, but it only hides the iCloud Private Relay option in the iCloud settings and doesn't actually disable it. I still found it to be ON. Has anyone else experienced this or found another way to disable iCloud Private Relay? <?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"> <plist version="1.0"> <dict> <key>allowCloudPrivateRelay</key> <false/> </dict> </plist>
Tahoe now wants to put three default widgets on the desktop in the upper left corner (Calendar, Weather, Photos) I don’t mind the weather and calendar widgets but the Photos widget will confuse people who are using this machine in a Lab setting. How can I control, remove or disallow them during or after setup?I looked through all the Configuration Profile settings but there doesn’t seem to be any way in the Jamf GUI to address this. Will it require a custom Configuration profile?Thanks!
When I first learned about Jamf Setup Checklist, I didn't view it as merely an optional companion to Setup Manager. In my mind, this was the rare movie sequel that genuinely had a clear, critical purpose.Setup Checklist was something our users needed. Something our technicians needed. And frankly, something I needed.🤔 Imagine this scenario…💻 Your user receives a brand-new MacBook Pro.The user opens the lid, glides through the beautiful Setup Manager workflow, and waits patiently as Jamf Pro onboards the Mac.⏰ 30 minutes pass. The Mac reaches the Desktop. The user is excited and ready to be productive on day one.So, they try to open Outlook. Error: No Internet connection.Okay… so they try to open Safari. Error: No Internet connection.😰 Minnesota, we have a problem. Panic sets in. What’s the Help Desk number again?Because this user is tech-savvy, instead of immediately calling support, they double-check the Wi-Fi connection and try the classic fix: toggling Wi-Fi off and on. Safari st
We’re using Return to Service to wipe a group of iPads with the Return to Service option enabled under ‘PreStage enrollments’. Now seeing iPads that have Software Update blocked with this message. Unable to Check for Update These settings are not available while this device is configured for Return to ServiceThis message shows on iPads even after an erase using Apple Configurator.Two questions. This now the default for all devices that support Return to Service even if not used on all iPads? How do we install any Software Updates if blocked? Jamf’s AI answers are telling me the fix is to unmanage these devices.
heres what i wrote up https://ideas.jamf.com/ideas/JPRO-I-2200 please vote if you agree, or are like me and are just simply terrified that you're going to accidentally hit the delete key….
Morning, I’ve recently upgraded our Logic Pro from version 11.2.2 to 12.3I’m concerned about our students downloading additional sounds/loops via the sound library (and filling up the hard drive) as it seems they can now download sounds without an admin password Has anyone got anything setup that will prevent users from either being able to open the sound library or prevent users from downloading sounds? Thanks
In Acrobat Pro and Adobe reader the Generative AI upload is enabled by default and you have to opt-out if you don't want to do that. Here for more: https://helpx.adobe.com/acrobat/using/generative-ai.htmlFollowing script can be deployed with a policy and creates two plists which disables Generative AI in Adobe Reader and Acrobat Pro. #!/bin/sh # Adobe Reader /usr/libexec/PlistBuddy -c "Add :DC dict" /Library/Preferences/com.adobe.Reader.plist /usr/libexec/PlistBuddy -c "Add :DC:FeatureLockdown dict" /Library/Preferences/com.adobe.Reader.plist /usr/libexec/PlistBuddy -c "Add :DC:FeatureLockdown:bEnableGentech bool false" /Library/Preferences/com.adobe.Reader.plist # Adobe Acrobat Pro /usr/libexec/PlistBuddy -c "Add :DC dict" /Library/Preferences/com.adobe.Acrobat.Pro.plist /usr/libexec/PlistBuddy -c "Add :DC:FeatureLockdown dict" /Library/Preferences/com.adobe.Acrobat.Pro.plist /usr/libexec/PlistBuddy -c "Add :DC:FeatureLockdown:bEnableGentech bool false" /Library/Preferences/
Microsoft has announced plans to move storage of the Workplace Join Key out of the user’s Login Keychain and into Apple’s Secure Enclave: Microsoft Enterprise SSO plug-in for Apple devices - Microsoft identity platform Announced in March 2024, Microsoft Entra ID will be moving away from Apple’s Keychain for storing device identity keys. Starting in Q3 2025, all new device registrations will use Apple’s Secure Enclave. There will be no opt-out of this storage location. Applications and MDM integrations that have a dependency on accessing Workplace Join keys via Keychain will need to start using MSAL and the Enterprise SSO plug-in to ensure compatibility with the Microsoft identity platform. In the same document, Microsoft provides guidance on how to test the Secure Enclave today to ensure the change will be compatible with your environment when the change goes live: If you would like to enable Secure Enclave based storage of
It would be extremely beneficial if there was a “automatic log-out” feature with JAMF Setup/Reset for iOS.We routinely have staff that do not logout with JAMF Reset and the iPhone is locked to their unique passcode. Can JAMF create the ability to initiate JAMF Reset automatically after 20 or so hours? This will be a huge quality of life improvement if JAMF could implement this.
Hello Everyone while i am trying to registry any mac device with company portal it is saying get the app popup even device already have the latest company portal app installed, If anyone can help me to fix it Note - it was working as expected two days back
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!