Get Support
Recently active
We're looking into solutions for restricting users from download packages or software via Terminal. Just as an example, installing Homebrew via Terminal to install Python. Once users have access to Python, they are able to install and Python packages they please. It's been getting difficult to track who has Python installed and what sorts of packages installed as well. If a user installed Python via the Python website, we can see the installer listed in Jamf's app list for their device but found that if they installed it via Terminal, the only way to detect it is to run 'python3 --version' in Terminal to see if it returns a Python version. I'm exploring to see if we can restrict certain Terminal commands with an Admin password (such as restricting running the command that installs Homebrew). I'm open to seeing if Terminal can be completely locked down with an Admin password but would much like to explore other options first, if available. Has anyone else ran into something like this an
Hello We have started to enroll our macbooks for our employees without adminrights. Yes we have the privilege access configured in jamf connect, but don't want use it for everyone :) So i started to configure what is necessary for our employees that they can work without adminrights. So far so good. Now i am actually helpless with this one problem about creating a symlink via jamf pro policy after installation of Visual Studio code. What i need is: A symlink in the directory /usr/local/bin/code which points to /Applications/Visual Studio Code.app/Contents/Resources/app/bin/code So i am able to create it, but it isnt working. Checking it on a testmachine the symlink shows me in the "get info" as "Original" the path /usr/local/bin/code instead of /Applications/Visual Studio Code.app/Contents/Resources/app/bin/code So its not the first symlink i create but its the first in this location /usr/local/bin/code so maybe i am doing something wrong. I am using this sho
Copied and pasted from Mr. Macintosh site. Safari18.2SonomaAuto.pkg Safari18.2VenturaAuto.pkg
How would I go about blocking extensions on Arc? Since it's a Chrome wrapper will blocking extensions work the same way in Arc as they do in Chrome by using a config profile? If so, what are you using for the preference domain?
Hello everyone, I need assistance in configuring a policy that will apply only one time for each new computer following its enrollment, specifically for machines located at a certain site. The policy's aim is to modify the keyboard layout setting. As it stands, the factory setting for the laptop keyboards is Arabic, and I need to update this to Arabic—PC layout, owing to the fact that most new employees are familiar with the PC keyboard layout. This policy should only affect new installations and not disrupt existing setups. Additionally, I want to ensure that employees retain the option to switch back to the default MacOS keyboard layout if they choose to do so later. I've investigated the following plist file for keyboard configuration: /Library/Preferences/com.apple.HIToolbox.plist However, updating the keyboard layout through system settings does not seem to result in changes to this file. To modify the file, I've drafted a short bash script:  
Hello Jamf family, Is there a script that can uninstall apps like in Intune? Thanks, JM
I have set up Cache Server 1 in City A, where I added the subnets of this location in the "content cache for" section. For my local network, I used the "custom public IPs" option and added a TXT record to the local DNS. This configuration is working as expected. Now, I am setting up Cache Server 2 in City B. The configuration is the same as in City A, ensuring that the subnets in City B fetch cached content from Server 2. I have also configured them as peers, with no parent settings in place, and both City DNS servers are synchronized with each other. Q1: How is data served to clients in City B if Cache Server 1 already has the same files? Q2: What changes should be made so that, in the event one server goes down, devices at both locations can still retrieve data from the other server? Additionally, while both servers are available, how can we ensure that devices access their respective server to minimize latency? Q3: How do peers work in this setup? If Server 1 has a file, does
Is there an inventory setting or extension attribute to see the iPad Chip?
Is there a way to automatically have Safari 18.1.1 install on all end user MacBooks? I 'thought' if we pushed 14.7.1, Safari 18.1.1 would be included/installed at the same time. That does not seem to be the case as users still have to manually go into Settings -> software updates -> updates safari there.
Anyone using EntraID for IDP with JC have any best practice suggestions for what claims to include in the ID Token? We plan to use the Admin Elevation feature for particular groups.
Hello fellow Admins, My company has recently implemented Jamf Connect to do a "pre-provisioned" style setup for refreshes. We are stuck on our new hire setups as Okta is not setup yet for a new hire, but the login requires your Okta credentials. I have seen the option to list a help button that takes the new hire to the Okta portal to finish the setup:https://community.jamf.com/t5/jamf-connect/jamf-connect-okta/m-p/259033. We also have OICD and group access via Okta for our users. Has anyone else run into this situation at their company, and if so, what solutions have you implemented or considered? Feel free to PM me responses as well if you are not comfortable putting any information out in the open. Thank you in advance!
Hi all, I have a client whose company has very strict policy about data protection and privacy. We are developing an App for this client that will utilise the Apple Dictation function. Due to the data protection and cybersecurity requirements, we want to use the Apple Dictation function in offline manner, which is possible. However, Apple documentation did not provide option to exclude audio and text data using in audio transcription process to be uploaded to Apple servers. Hence we are looking to use JamF to block such traffic. In fact, we want to block most traffic to public internet, except those necessary for operating the devices, MDM and app. For example, we will allow list of servers used for certificate validation. My question to JamF community and JamF experts is if JamF can help us achieve our objectives, which including network traffic filtering at OS layer (blocking even iOS traffic to Apple servers)?
I have deployed BeyondTrust's remote support client to my test machine. However, if I set the configuration profile to Allow Standard Users to Allow Access for ScreenCapture, the app doesn't seem to realize it's been authorized. It continues to prompt to allow. Even if I check it with an administrator account. As you can see in the screenshots, even the Accessibility and Full Disk Access are also showing denied, even though they are set to allow in the configuration profile.The fun part is (on a fresh image) if I set the ScreenCapture to Deny, then use an administrator account to allow while on the computer, it actually does allow it.
I'm in the process of migrating our Iphone fleet from a different MDM to Jamf and for this reason we need to wipe our devices completely to enrol them on Jamf.I'd really like to not lose everything our colleagues have on their Iphone but in my tests I can see that the backup step is just before the enrolment step.If I proceed with the backup the last MDM is migrated to the device too but if I enrol the device on Jamf i lose the opportunity to have a backup at all.Is there any smart way to do this that's not just saving everything on a cloud?
Hello everyone, Once the workstation has been enrolled, some of my workstations doesn't have the folder "Remote Assist" in "/Library/Application Support/JAMF/", which is why Jamf Remote Assist does not work on these workstations. But I don't understand why it's doing this to me when it's working on other workstations. Could you help me please ?
Has anybody been able to configure the Apple Intelligence Report section in Privacy and Settings?
Hi all, We are looking to mass deploy a silent push where we can push random generated or making use builtin information for computer naming convention silently. We need to mass deploy this to our existing computers without user interaction. Does any know what the possibilities are with macos 14 and 15 and if something someone has?
I got to work this morning, logged into my Jamf console a few minutes, and noticed my entire dashboard is gone. I had a ton of items on my dashboard, and now they disappeared. Anybody else have this issue when they logged into their cloud-based Jamf console? How do I get all the items that were on there back on my dashboard?
Hi eveyrone, Rookie here. how can I upload a larger than 5GB pkg to jamfCloud? With Jumf Sync the max is 5GB. I checked the log and I get below. Failed to copy Adobe_AE to JCDS (Jamf Sync): dataRequestFailed(statusCode: 400, message: Optional("EntityTooLarge: Your proposed upload exceeds the maximum allowed size - max allowed size = 5368709120")). Adobe After Effects on its own package is 6.38 GB.
In case others need the Sonoma Safari 18.1.1 package: https://swdist.apple.com/content/downloads/07/27/072-35776-A_9GTPDVFEFP/vp2hopk2kfiw0at5uzlvvnfg6rp5z9iz8c/Safari18.1.1SonomaAuto.pkg This patches recent vulnerabilities: https://support.apple.com/en-us/121756
What methods are people using to get logs off of users systems? For example, a user will call in saying they have some issue with their system. We'll generally then take a look at system.log, install.log, jamf.log, etc. by remoting into their system, having them email us a copy, or looking at them directly. I'm thinking it would be much better if I could script a Self Service item that would upload those files to an available share, pull them with Casper Remote (without needing to Screen Share), or something similar. Has anyone done anything like this?
I am trying to renew the certificate on my IIS distribution point on a Windows server. The documentation has changed recently and the new documentation seems to have left out the part of making that request in the Certificates snapin in mmc. I can get part way through from memory but I know there were some other settings that I cannot recall. This is the documentation updated in October of 2024... https://learn.jamf.com/en-US/bundle/technical-articles/page/Using_IIS_to_Enable_HTTPS_Downloads_on_a_Windows_Server_2016_or_2019_File_Share_Distribution_Point.html Does anyone have a printed out copy of this page prior to the update? I recall that it was step 4 where they talked about making the request that I need to do. Thank you in advance for any help.
Hello Jamf Nation! We have just launched a Self Service+ 0.13.0 beta release which is the initial Public beta release version. We’re excited for your feedback and are looking forward to talking with you in the beta forum! Self Service+ 0.13.0 beta requires Jamf Pro 11.11.0 or newer, and is intended for testing and feedback purposes only. It must not be deployed to end users in a production capacity. To participate, log into Jamf Account, click "Feedback", and enroll into the Self Service+ Beta. The beta program is covered by the Jamf non-disclosure agreement; please do not share any information regarding your testing on any public forum, including the non-beta areas of Jamf Nation. Use the Jamf Nation Beta Forum or contact Jamf via beta@jamf.com with any questions. Please ensure under My Settings → Email in Jamf Account that “Don’t send me any community emails” is unchecked, or you will be unable to participate in providing feedback and interacting with
Looking into changing from DepNotify to Setup Manager. Our distribution point is not cloud based and needs authentication (this will not change) Is there a way to use Setup Manger once in the OS like DepNotify? I have done some testing adding the profile to the Prestage (but not the setup manager PKG) and setting a Setup Manager Policy with trigger on enrollment. But it does not seem to work all the time and when it did work and said it was installing packages (using jamf policy trigger) none of them installed. Any one use setup Manager in this way?
Hi all, My issue is based on jonw's script from here (big thanks for that), I used this for deploying AutoCAD LT 2025: https://community.jamf.com/t5/jamf-pro/packaging-maya-2025/m-p/320737/highlight/true#M277340 I use this line for registering the product: /Library/Application\\ Support/Autodesk/AdskLicensing/Current/helper/AdskLicensingInstHelper register --pk 827Q1 --pv 2025.0.0.F --lt USER --cf /Library/Application\\ Support/Autodesk/Adlm/.config/ProductInformation.pit The issue: When the script runs the applyLicense function, I get this error: Error (25) for adlmPITSetProductInformation_2: Error has occurred while parsing PIT file How can I write the license details into the file? Tried to change file permissions (chmod 644 and chown root:wheel) - no luck Tried to execute the command with sudo from Jamf - no luck Tried to execute the command from Terminal with sudo - no luck Tried to delete the file and create it again - no luck Tried to do a clean
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!