Get Support
Recently active
I joined Jamf as a training instructor in March of 2022. It was a strange move for me. Prior to that, I was a mostly lone-wolf Jamf Pro admin, enjoying my days in relative solitude with a CodeRunner window and my ticket queue open, communicating mostly by typing words into a document or a chat window. When I did have to hook my laptop into a projector or share a screen during an online meeting, the majority of the time I was meeting with colleagues that I knew well already. For an introvert, not really too big of a lift, I think. So jumping into a job role where I would not only be speaking, but managing a class full of a dozen different people, mostly not-colleagues, but customers, nearly every week for four days straight, was as you can maybe imagine, a bit of a shock to the system. There were a lot of lessons I had to learn very quickly, and some new problems to try and solve, though most of them are rather specific to this job I know few readers share. But there are a few I think a
Haven't posted in a while... glad to be back, at least to ask this question:When do normal Jamf Pro customers get this?https://datajar.co.uk/products/jamf-auto-update/This seems like something that Jamf App Catalog was meant to be. This company is now owned by Jamf. Hoping this product expands from being just for MSP's to Jamf Pro customers soon. Having automatically updating Mac packaged app catalog for over 800+ apps seems like something all Jamf customers deserve. The App Catalog in Jamf Pro has not expanded as quickly as hoped, and also continues to be unreliable at times with it using the Apple Enterprise Application install API's.Thoughts?
Hi,We’ve migrated our on-prem Intranet site to SharepointOnline and I’ve been tasked to deploy the new site to our Mac fleet of about 180 Macbooks. Microsoft Edge is our Organisational standard and the way it’s going to work is that whenever Edge is launched the landing page will be the new Sharepoint Online Intranet site. The issue is, upon launching Edge it keeps prompting to authenticate via login.microsoftonline.com before the site loads. On Google Chrome it works as expected without requiring authentication. Is there anything i must configure in the configuration profile? Our Macs are not domain joined.
Hello Jamf Nation,We are excited to announce that AI Governance for Mac launches today.Organizations are adopting AI tools on Mac fast, and until now there has been no way to see which tools are sanctioned, how they are configured, or prove it to leadership. AI Governance changes that. It gives IT and security teams a dedicated control plane to define policy for AI tools like Claude Desktop, Claude Code and Codex, push it tamper-proof through blueprints, and get a real view of AI posture across the fleet.To make sure you are ready for AI Governance, you will need to meet a few criteria. AI Governance is available as part of Jamf for Mac, Jamf for Mac Hi-Ed, Business Plan and Enterprise Plan.Here is what you need to have in place: Enable SSO with Jamf Account. OIDC authentication must be enabled in Jamf Pro, connecting your environment to Jamf Account via single sign-on. This ties your identity layer to AI Governance controls so the right people can see and act on AI activity across you
In Jamf Pro, We have policies to install the 2024 Microsoft Office suite LTSC during our Provision policy which is a script that calls each policy to install individual pieces of software we want to install on a Mac.Here is the order for the Microsoft install we have 2 policies:1. Install 2024 Microsoft Office 16.106.26020821.pkg(This is the older version from February. Testing. I tried the lastest version too)2. Install Microsoft_Office_LTSC_2024_VL_Serializer.pkg(I have also tried swapping the order)Ever since I can remember this has worked exactly as intended. The Office suite is installed then the volume serializer is installed to activate the license. At first launch it opens to the templates/recent documents page.However, over the last couple weeks of testing, the activation is no longer applying. I’ve tried everything I can to try and deactivate the license/reactivate it, but the only fix appears to be completely removing all office components, and reinstalling them - only then
We use a post install script to install Zscaler by combining the script in the package using Composer to populate UserDomain and several other settings and this works fine. However, we are considering moving away from that process and leveraging Profiles as documented herehttps://help.zscaler.com/zscaler-client-connector/deploying-zscaler-client-connector-jamf-pro-macosStep 3 outlines the requirements for a Custom configuration which is responsible for providing the cloudName.The profile in System Settings shows that the cloudName is present, however when Zscaler launches it requires the user to enter their email address and then click Login at which point it presents two options; zscalerbetazscalertwo.The profile reflects that the setup should be zscalertwo without presenting the two options above.Has anyone come across this issue?The script method injects the cloudName and works fine but would be good to get the Profiles to work.
HI!I have a problem with our Jamf Pro System.The following problem only occours since about 3 weeks and only in prestage, not in userinitiated enrollements.We are using our admin-accounts to log into jamf for the prestage enrollment. This will create a local admin-support account for the IT. So far so good.Now, after completing the enrollment, jamf forces us to type in the password of the IT-User-Account used to log in while doing the prestage enrollment. It will create a user account on this device with this account. There is no way around it. I cant change to local login.And even after the creation of the unwanted account: if i delete it it forces me to tell jamf the password of the account and creates it again.Anyone has ideas or the same problem?We didnt change anything.P.s. yes, skip account creation is checked.
Hello! I hope someone can help me with this. I've look into several other links and it does not seem to work.We generally have the Sharing preferences disabled in our Jamf using the Config Profile. We have a certain group of people who needs Screen Sharing. While we can exempt them from Sharing preferences which allows Screen Sharing, this will open up the ability for them to enable File Sharing, Media Sharing, Content Caching, and so on. 1. Is there a way to keep Sharing preferences disabled and allow only Screen Sharing? 2. Is there a way to enable Sharing preferences, allow Screen Sharing but disable the rest inside the Sharing preferences (File, media, Content cache, Bluetooth, internet sharing, printer sharing...etc)I've tried the below but it doesnt seem to work. My test machine is on Sonoma.!/bin/bash /usr/libexec/PlistBuddy -c ‘Set :com.apple.screensharing:Disabled No’ /private/var/db/launchd.db/com.apple.launchd/overrides.plist launchctl load /System/L
Hello Jamf Nation!We’ve released Jamf Pro 11.30.0 beta. This release includes Inventory and API enhancements, logging improvements and more! For full details, check out the release notes after enrollment.How to join the beta: Enroll in the Beta Program under Product Feedback at account.jamf.com. Click “Join Community” to join the beta forum once enrolled. If you encounter an error on Jamf Nation joining the beta forum, please log into Jamf Nation and then click “Join Community” again. Please also check out this recent blog on Configuring SSO in Jamf Account prior to testing Compliance Benchmarks, Blueprints, and App Switcher. Email beta@jamf.com with questions.The beta program is covered by the Jamf non-disclosure agreement; please do not share any information regarding your testing on any public forum, including the non-beta areas of Jamf Nation. Use the Jamf Nation Beta Forum or contact Jamf via beta@jamf.com with any questions. Thank you to all who participate in this program!
Overview · Setup decisions for admins Managing who has access to what and keeping it current as students move between classes is one of the more tedious parts of running a school's tech environment. RapidIdentity's rostering capability takes that off your plate by pulling class data from your external sources and automatically translating it into SSO app access and student group memberships.This post walks through how the pieces fit together and the key decisions you'll face when setting it up. For step-by-step configuration, head to the Help Center.How the sync worksRapidIdentity connects to your class data source, typically a student information system (SIS) like Clever, ClassLink, or a direct CSV feed, and syncs on a schedule you control. When a student is added to a class, they're added to the corresponding group. When they're removed, access goes away. No manual intervention required.That group membership drives everything downstream: which SSO-connected apps the student can see,
Today we are releasing Jamf Pro 11.29; highlights include:Simplified Setup for Platform Single Sign-on EnhancementThis feature previously supported only a single workflow configuration where the Single Sign-on Extensions (SSOe) profile installs after the computer is enrolled with Jamf Pro. This enhancement expands the functionality of Simplified Setup for Platform SSO by including an additional workflow configuration where the SSOe profile installs at the beginning of the enrollment process, forcing users to authenticate with your identity provider (IdP) before enrollment completes.Directory Service Group CriteriaNew directory service group criteria are available for smart groups and advanced searches. Smart groups and advanced searches with these criteria use a local cache to store user information obtained from an LDAP server or cloud identity provider (IdP). For additional information on what's included in this release, review the release notes via the Jamf Learning Hub.To access ne
Hi everyone,I’m trying to set a default font in Microsoft Outlook (macOS) using Jamf Pro, and I’m running into some trouble.By default, Outlook uses Aptos, but I’d like to change it to Book Antique, which is already available on the device.What I’ve tried: I attempted to use the 3rd-party tool OutlookFontPoke by Paul Bowden @ Microsoft. Here’s what I did:• Deployed the OutlookFontPoke script and TemplateRegDB.reg via a package (both located in /private/tmp/OutlookFontPoke-master).• Created a policy in Jamf that:• Extracts the current logged-in user• Fixes permissions• Run the command as that user: sudo -u "$loggedInUser" /private/tmp/OutlookFontPoke-master/OutlookFontPoke 'Book Antique' '11.0pt' 'black' Issue: Despite several variations of the above, I keep getting this error in the script logs:WARNING: Registry DOES NOT exist at path /Library/Group Containers/UBF8T346G9.Office/MicrosoftRegistrationDB.reg. Attempting to create...mkdir: USER/Library/Group Containers: No such file or dir
I have 2 questions with my Mac management with my on premise Jamf Pro instance.Before news MacOS is launch we would like to block the update while we made a couple of tests with our applications used in my university.What is the best way to block MacOS upgrade and for how long can we block the update? Second questions, After the pre stage enrollement i execute Jamf Setup Manager to install few applications and apply some configurations, i try to execute a script to reboot the computer but after reboot JSM runs again, how could i execute a reboot action after JSM properly?Thank you very much.
Hello, Just checking to see if anyone has found a way to update Libcurl on macOS without using Homebrew? There are several CVEs out for security issues related to the version of Libcurl in macOS. I’m not sure why macOS uses a version that is over two years old when there are updated versions available.
I'm @TyBorrell the product manager for Jamf AI Assistant. My second week at Jamf, I was at JNUC in Denver, talking with admins about AI. I haven't stopped since: what they're trying, what's working, what they're quietly unsure about. Here's what I keep hearing, and then I'd like to ask you something.At Jamf Nation Live London this year, 221 admins were asked what they need help with most, and AI integration topped the list at 84%. It came up across every career stage, from first-timers to people running teams. What I keep hearingMost of it comes back to a few questions:How do I use AI to manage my fleet more intelligently? How does it make me a more impactful contributor at my org? How do I free up time for the parts of the job I actually want to do?People are approaching AI every which way. Some have built plenty, some are just starting, and none of that is the point. If you'd like to work through it alongside other admins, there should be a place for that. An invitationI created a g
Enrolling new laptops and Self Service+ is installing. However at login we are seeing a pop up for intel based apps with the old Self Service logo stating this version of “Jamf” will not work with at future release of MacOS
Hello,Every year we roll out the current version of Logic to our student walk-up Macs. We have started working on next academic year's configuration, which we expect to include Logic 12.To our surprise, the way they handle the Extra Content has changed utterly. Instead of 1000+ PKG files, which we had a reasonably well-established mechanism for deploying, pulling down all the content now results in a single huge "bundle" file here:~/Music/Logic Pro Library.bundleThis is the worst-case scenario for us, because instead of having a single set of extra content installed to Logic proper, it wants each user to have their own copy of the vast extra content.We therefore want to move the content to a shared location, and they have a mechanism for doing that. My problem is that the location of the extra content is itself stored per-user. I obviously need to deploy the setting telling each user to look for the extra content in the shared location, rather than defaulting to the per-user location.I
Today we are releasing a maintenance version of Jamf Pro; highlights include:Improvements to Enhanced Log CollectionThe following improvements have been made to TriggerEnhancedLogCollection and related functionality:*Details for the TriggerEnhancedLogCollection command are now included in the Jamf Pro API. A CancelEnhancedLogCollection command has been added to the Jamf Pro API. When triggered, active log collection processes are stopped on the target device and logs are not sent to Apple. See the following developer documentation from Apple for more information: https://developer.apple.com/documentation/devicemanagement/cancel-enhanced-log-collection-command. Two new dedicated privileges, "Trigger Enhanced Log Collection" and "Cancel Enhanced Log Collection", have been added to Jamf Pro for their respective functionalities.*Feature support is based on testing with the latest Apple beta releases. Resolved IssuesJamf Pro Server[PI-33] Fixed: Jamf Pro incorrectly attempts to reinstall a
We are excited to share that we’ve updated our Privacy Notices to enhance transparency, improve readability, and reflect evolving privacy and AI requirements.Our Privacy Policy has been revised to provide greater transparency regarding our use of AI-assisted tools within our Services, including technologies that may help record, transcribe, summarize, and analyze customer and sales interactions. We have also added information about our commitment to responsible AI practices, including compliance with applicable AI regulations and safeguards around automated decision-making.Additionally, we have expanded our disclosures regarding advertising and marketing activities, including how we use certain technologies to measure the effectiveness of our campaigns. We have also enhanced our children's privacy disclosures, and introduced information about our process for submitting and resolving privacy-related complaints.We have also updated our Employee Privacy Notice to provide greater transpare
Hi all!We run Jamf Trust with enforced Secure DNS (DoH, ProhibitDisablement = true). The activation profile includes an OnDemandRules-SSIDMatch list with Action = Disconnect for typical captive portal networks (airlines, hotels), so that the DNS connection disconnects there and the login page loads.Problem: A colleague can’t access the captive portal on the Eurowings onboard Wi-Fi (SSID “Wings Connect”), neither on an iPhone nor on a Mac. The SSID is simply missing from the list. The same issue occurs with Lufthansa (“Telekom_FlyNet”), even though “FlyNet” and “Telekom_FlyNet” are included in the list; I suspect the actual SSID being broadcast differs (e.g., with “®”). My questions for you:1. Is this captive portal SSID list editable within the Jamf Security Cloud console itself? In our setup, under Settings > Service Controls, I only see “Privacy”—no “Dynamic Routing” or “SSID Bypass.” Am I missing something, or is this managed on the tenant side by Jamf and can only be changed thr
Im testing Jamf/Entra Device Compliance. Everything is working as expected (Smart Groups, compliant/non-compliant criteria, Entra/Intune connector, etc). Now its time to focus on the actual registration workflow and policy logic to make it as painless as possible for my users.Does anyone have a customize workflow that improves the registration user experience? Popping up the Company Portal auth UI is not an elegant way to register our employees.🙏🏻
I need to lock down some iPads to only display a single web page. These devices are supervised, and will be handed out to study participants in a lab. They’ll then interact with that single web page during the course of their participation in the study. We don’t want the participants to be able to launch any other app, configure any iOS settings, or visit any other website.This article, “Configuring Single App Mode for Web Clips in Jamf Pro,” which was just published four months ago, seems to be exactly the sort of thing I’m looking for. However, when I attempt to implement it on my test device, all I get is a blank white screen with the iOS status bar on top of it.I have tried using both com.apple.webapp and com.apple.webapp.managed as Bundle ID values in my Single App Mode payload. Both have the same result. The Jamf article seems to possibly imply I need to find a Bundle ID value that is specific to the web clip I’ve defined, as it references another article titled Determining the B
Jamf School is there a way of restricting a managed device to only use a managed apple ID. We are looking to go to managed apple Id’s with our Ipads and our New NEO’s. So we are interested if we can do this.
The need for skilled IT workers continues to grow. Many companies and schools rely on professionals who can manage Apple devices and systems. In partnership with Jamf, Maricopa Information Technology Institute (MITI) supports Mesa Community College to offer the Enterprise IT Professional Apple Technology course series to help meet this need and prepare students for today’s workforce.Under the leadership of instructor Carl Cortez, the program provides both knowledge and hands-on experience. Students learn how to work with macOS and iOS and how to manage devices in both business and education settings. Participants also earn Jamf 100, Jamf 170, and Jamf 200 certifications. Jamf is a widely used tool that helps organizations manage Apple devices. Through this training, students build practical skills in setting up, securing, and supporting devices at scale.A key strength of the program is its focus on real world learning. Students do more than attend classes. They complete a capstone proj
I am working on setting up SSO to use Teams on managed devices for Imprivata MAM. I followed this guide to set up the SSO plug in and it was working but now seems to have stopped. Configure iOS/iPadOS Enterprise SSO app extension with MDMs - Microsoft Intune | Microsoft LearnAfter setup, the authenticator app no longer shows Shared Device Mode, but just the normal add account screen. I’ve tried recreating the SSO configuration and changing to a personal network to confirm the issue isn’t network related. I reviewed this troubleshooting page by Microsoft, but that didn’t seem to help either. Troubleshooting the Microsoft Enterprise SSO Extension plugin on Apple devices - Microsoft Entra ID | Microsoft LearnAny other ideas?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!