Get Support
Recently active
Today we are releasing a maintenance version of Jamf Pro; highlights include:Resolved IssuesJamf Pro Server: Security IssuesJamf provides the CVE-ID for security issues with high or critical severity when possible.[PI144208] Fixed: A cross-site scripting (XSS) issue.Jamf Pro Server[PI-1394] [PI-1471] Fixed: The Jamf Pro API returns IDs instead of human-readable display names when the following criteria are used: Computer Group, Mobile Device Group, User Group, Assigned User Group, Assigned User. [PI-1404] Fixed: Jamf Pro fails to create a Jamf Pro Summary when backend activation code services are nonoperational. [PI-1429] Fixed: Directory services sync may fail when the directory service is very large. [PI-1430] Fixed: When Jamf Pro attempts to sync with directory services and the database goes offline, Jamf Pro fails to complete the sync or restart the sync when the database becomes available again. [PI-1441] Fixed: Directory service groups fail to sync when the database contains dupl
Hey Jamf Nation 👋🏼, Welcome back to our Jamf Nation Development Series! 🚀 Next up - we have a free learning workshop on Human - Centered AI Implementation. Register now → https://jamf.it/JamfNationEvents Here’s what this session is about: Most AI talks aimed at technical folks skip the part that actually matters. They obsess over the tools and forget the humans running them. This session does the opposite.You're likely already using AI in your environment, so this session won't cover the basics. What's worth talking about is the harder-to-Google stuff: how to use this technology responsibly, what it's quietly costing us, and how to get real value instead of just more to manage. It'll stay practical and honest, with room for your questions and your war stories.Here's what we'll dig into together:Keeping humans at the center, even in a highly technical shop, and why the people side of AI is always harder than the technology The environmental footprint of AI, the part almost nobody's
• Apple link: https://support.apple.com/en-us/125615In macOS 28 and later, the Mac OS Extended file system format will be supported only for volumes (disks and other storage devices) that aren't encrypted. For future macOS compatibility, either decrypt or reformat any encrypted Mac OS Extended volumes.
Does anybody have a solution for teachers with managed iPads to mirror a Netflix Video from their iPad to the Classroom ATV ? Netflix account is a personal account, as the school does not have any.Thanks for your helpger
Hello everyone,we are experiencing an issue with our Apple School Manager / Jamf School environment and hope someone can point us in the right direction.EnvironmentApple School Manager Jamf School Privately owned student iPads Automated Device Enrollment (ADE) Current iPadOS versionConfigurationOur student iPads are managed using Apple School Manager.Each student has a Managed Apple Account. The devices are assigned in Apple School Manager and synchronized with Jamf School. Devices are enrolled using Automated Device Enrollment (ADE). In Jamf School, each device is assigned to the corresponding student as the Owner. The devices only receive: one general profile ("All iPads") without any restrictions configured two Wi-Fi profiles As far as we know, there are no additional restrictions or App Store policies configured.The issueAs soon as a student signs in with their Managed Apple Account under Settings, the same account is automatically used for the App Store.There is no option in the
On Saturday, August 8, 2026, Jamf Cloud Infrastructure will be patched. During this time, you will be logged out of your Jamf Pro instance. The purpose of patching is to ensure that Jamf Cloud infrastructure and the database service are up-to-date, stable, and safe from security threats. Please see the times for our regions below. Hosted Data Region Date Start Time End Time us-gov-west-1 August 8, 2026 0800 AM CT 1200 PM CT
Hey everyone! Quick question. We are deploying MacBook Air’s in a school setting. The devices will be connected to school WIFI with a configuration profile. Do you think it is necessary to manually set WiFi at the top of the network service order?
Hi, we use a pretty basic blueprint to keep our devices up to date to the latest MacOS , we force it to install within 30 days. Without having to edit this Blueprint and redeploy, will the regular “Block” for the New MacOS Golden Gate work and only keep the updates coming for Tahoe until we unblock Golden Gate (usually for us is 90 days after it comes out.).
Is there any good way to do this? I have some icons that were replaced with higher quality ones and I would like to remove the older ones, but there is no interface I know of in the JSS. I realize I can go into the icons table if needed but would prefer not to.
Our company has one app that we must defer updates for, and it absolutely cannot be allowed to update during normal hours. We keep automatic updates off and have a script for pushing updates for this app overnight. Recently I had to rewrite this script due to endpoints being deprecated, and it ended up being a bit of a pain. So, I decided now might be a good time to provide some insight here in hope that someone experiencing the same situation might stumble upon this. The workflow that works with the new endpoints is: wait until scheduled time (and wait between most of these steps) > get necessary device info > send restart command to devices > change app setting to force updates > send INSTALLED_APPLICATION_LIST command to devices > send blank push to devices > revert app setting However, there is a catch. You may want to use the “/api/v2/mobile-device-groups/static-group-membership/” endpoint to get the Management IDs for devices. Currently, this endpoint has a
We are currently using Jamf Setup & Reset on our student devices. Setup is used to select a teacher classroom and set the appropriate role. We then have the students use a soft reset in Jamf Reset before the next student gets on the device.When the next student gets the device it has the Jamf Setup app on the screen. But it comes back with the All Set page even though the EA was successfully cleared. Is there a way to force Jamf Setup to open to the first selection screen other than forcing a reinstall of the entire app?
I read somewhere that with iPadOS 26 we will have an option to manage Safari like set Bookmarks and other staff. Unfortunately when i want elaborate this more further i am not able to find any offical documentation from Apple or from Jamf on this topic. Has anybody experience with this? Does Jamf already implemented into console tools to manage Safari via DDM?
Is it possible to Install Matlab R2020a silently? I have a registration key and a license.dat File.
Districts buy a lot of apps. Some get used every day. Others quietly gather dust after the first semester. The problem is that most IT teams don't find out which is which until renewal season, by which point it's too late to make a good decision. That's the gap RapidIdentity Insights is built to close.What Insights actually shows youInsights is the analytics engine built into RapidIdentity. It doesn't just tell you an app is licensed. It shows you how students and teachers are actually using it, down to the individual login. That includes:A full inventory of your SSO applications, including their status, security controls, and who has access to what Usage stats by user type, school, grade level, or location, so you can see exactly which apps are catching on and where Trend analysis and forecasting, so growth or decline in adoption shows up before it becomes a budget surprise Individual application launch events, if you need to drill down that far Engagement tracking, including which us
We have Jamf-enrolled macOS devices integrated with Microsoft Entra and Microsoft Intune for office and conditional access. Currently, a single compliance group in Jamf sends the device compliance status to Entra, where it's used for Conditional Access policies.Our client now wants to expand the compliance requirements by adding several new criteria. I'm wondering what the best approach is:Should we add the new compliance criteria to the existing compliance groupOr would it be better to create a new compliance group, validate it, and then switch Entra reporting to the new group once it's readyI'd appreciate any recommendations or tips.Thx
I have 3 devices in my org that when they hit the JAMF Connect Login screen to MFA into the device it auto-reboots. I do not have a chance to choose local login since it is instant. I'm not sure if it's a pending policy or JAMF connect causing the issue since it has not checked in since the reboot has started. I do not see any pending policies in the logs. I can't apply any current policies or check-ins since it reboots too quickly to check in to JAMF and or post a boot up trigger. 2021 M1 Macbook ProJamf Connect 2.45.0
I know this has been asked before, but has anyone been successful using Jamf Pro to accomplish either of the following on managed iPads?Prevent students from deleting their Chrome browsing history. Prevent students from signing into Chrome with personal Google accounts (either allowing only our managed Google Workspace accounts or disabling personal sign-in altogether).If you've gotten this working, would you mind sharing how you configured it? Was it done through a Chrome managed app configuration, Google Workspace policies, Jamf restrictions, or a combination of the three?
Written by Diane Meza The demand for skilled Apple IT professionals isn't slowing down. As more schools and businesses build their operations around macOS and iOS, they need people who know how to manage, secure, and support those devices at scale — and the talent pipeline hasn't kept pace.Mesa Community College is helping close that gap. Through the Maricopa Information Technology Institute (MITI), in partnership with Jamf, the college offers the Enterprise IT Professional Apple Technology course series: a hands-on iniative built to turn students into job-ready Apple IT professionals.Learning by doingUnder instructor Carl Cortez, students get more than lecture time. The initiative combines classroom instruction with real device management experience, covering how to work with macOS and iOS and how to manage them in both business and education environments. Along the way, students earn Jamf 100, Jamf 170, and Jamf 200 certifications, credentials that carry weight with employers already
Launching the inaugural Mac Admins User Group Paris meetup during Apple annual developer conference week was quite a challenge… but a good one, and I must really thank all the Jamf team for helping us to make it happen in such a short time! As a long time Mac user, I loved the energy from Apple Expo in the old days. Since its termination, Paris has long needed a localized hub for Apple IT professionals to connect face-to-face. I worked on different Mac admins events in the past (Command IT, Gete.Net Connect), but I felt that choosing WWDC 2026 as our kickoff theme for this new Paris User Group provided the perfect catalyst, uniting the community around massive technical shifts. WWDC 2026 Highlights for Mac Admins Apple made it absolutely clear this year that Declarative Device Management, aka DDM, is no longer just the future, but the present standard. Hopefully, the message was well sent, and as our favorite management tools have been updated to use DDM properly, and this transition s
I have gotten as far as the OneDrive icon prompts and says “Your IT department wants you to backup your folders” and if they click the botton it does work, but I’d like to have this just forced with no choice. This is what I have setup as far as a policy { "title": "Microsoft OneDrive Folder Backup", "description": "Silently enable OneDrive Folder Backup for Desktop and Documents and prevent users from turning it off.", "type": "object", "properties": { "KFMSilentOptIn": { "title": "Tenant ID", "description": "Microsoft 365 tenant ID used to silently enable OneDrive Folder Backup.", "type": "string", "property_order": 10 }, "KFMSilentOptInDesktop": { "title": "Back up Desktop", "description": "Silently move the user's Desktop folder to OneDrive.", "type": "boolean", "default": true, "property_order": 20 }, "KFMSilentOptInDocuments": { "title": "Back up Documents", "description": "Silently move the user's Document
Hi, We deployed self service + with jamf connect globally to our environment and computers that use local accounts are now showing a self service + login prompt. The prompt will not go away and will display over all other windows. We can log in, yes but these are shared use local accounts and we don’t want users to log in with their credentials to self service +. That would be a security concern. We’ve tried setting up restrictions for self service + and its processes but that has either not worked or the window still pops up momentarily every few seconds.
Greetings,Is there a way to determine the last time a policy was triggered? I’m doing some clean-up in my cloud environment, and have several policies created by other people that I’m reasonably certain haven’t been used in a long while; like months or years. Ultimately its my decision on whether to remove the policy or not, but having evidence to support that decision (and the knowledge of how to get that evidence anytime) is useful to me.
I have a fleet of ipads that run conference room meeting equipment. I’m trying to figure out a way to schedule them to reboot overnight, a couple of times a week. I know this can be done with a policy for macos. I’m hoping i can accomplish something similar on iOS. All the answers i’m getting seem to be related to the computer side of things. Any help would be greatly appreciated.
We have a number of machines that restart when left for awhile. These machines did not do when old MDM, but after am getting a number of complaints. Mine also does this. It is reminiscent of the M5 issue that was fixed in 26.5.1; however, none of the machines that are having this issue are M5-based including my own, which is an M3 Air.Is there a fix for this? Could it be Digital Guardian or SentinelOne.
Hi everyone,I recently built a small native macOS utility called App Signing Inspector to make it easier to inspect applications and create application-execution declarations for the new macOS 27 Declarative Device Management controls.I started working on it while testing the macOS 27 beta because gathering the correct signing information and manually building declaration JSON was becoming repetitive and easy to get wrong.What it doesThe Inspector lets you select a macOS .app bundle and displays information such as:Bundle identifier Application version and build Executable path Signing ID Team ID Signing authorities Complete designated requirement Hardened runtime status Gatekeeper assessment Locally reported notarization status Apple Silicon, Intel, or Universal architecture classificationThe separate Policy Builder lets you combine multiple applications and rules into a complete com.apple.configuration.app.settings declaration.It currently supports:Allow and deny rules Signing ID and
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!