Get Support
Recently active
Good morning!I did a search and couldn't find my exact question, so feel free to point me in the right direction if you know of anything...But I'm having an issue updating Jamf Connect in my environment. Because of the Launch Agent I'm running with it, it can't properly close and update and results in a very annoying, persistent pop-up asking to close the program that when followed, relaunches and pop-ups again until you restart the machine a few times.I'm reaching out because there has to be a better way. What's the easiest solution to ensure Jamf Connect is updated and not being disruptive to our users?Thanks!Joel
Hi Team, Apologies if this was ask before but I cannot find the proper process to unmanaged devices that are no longer on the network. A lot of conversation around using API and CURL command but as a none mac user, I cannot figure out how to use. I know it's not great to other people who work hard to post and reply to those query but i'm struggling to know what to use and how to use the API We use windows base system and servers and Jamf Pro cloud Can someone please help me? Thank you in advance Regards G_Man
Hey all,We have about 150 student iPads 9th gen that haven't updated to 18 because we used the schedule install command which requires at least 17 to be installed. What is the best course to get these iPads updated? Do I resend a plan in jamf to download and install and target just these iPads?Or does it make more sense to have out staff have the students update on device?
Is the calculator app new to ios 18? I never noticed it until I started updating ipads to ios18. Is there a way to remove/hide the calculator app with a configuration profile? Thanks
Hi, Anyone using Jamf Protect to audit all file access (new/read/update/delete) on an attached storage device? If so, how are you setting that up? Thanks
Hello, We were trying to install iMovie to some laptops. We add the laptop to the scope of the imovie app catalog in jamf pro but nothing appears to happen. The app would not show up on the laptop after a few restarts and manual inventory updates. In jamf, the app shows in the scope of the computer but in the history tab there was no pending, failed or completed command that shows regarding the iMovie app. I went into this section in the image provided and in username box i typed in admin which is the local admin account we create on all managed laptops. After that the iMovie app downloaded on the laptop. Not sure if typing the admin account in the username was the solution but will I have to do this to every laptop I assign the iMovie app? How can I avoid this and just make sure the app installs on all laptops in scope? Thanks
Co-Authored By Simone Martorelli and Jonathan Krauer At the Jamf Nation User Conference this year, the Mac@IBM team presented a new solution that’s set to transform Mac device migrations in the enterprise: IBM Data Shift. Developed in response to the unique challenges of managing large-scale Mac deployments, it provides a user-friendly, secure, and efficient method to migrate data on managed devices—bridging gaps left by traditional migration tools. Why Traditional Migration Solutions Don’t Fit Enterprise Needs When it comes to Mac migrations, enterprises encounter complexities that personal device users typically don’t face. Managed Device Environments, for instance, have high security standards and stringent configuration needs that general migration tools aren’t designed to meet. While Apple’s Migration Assistant is well-suited for a personal environment, it may lead to headaches in a managed setting. Some of the main challenges include: Post-Setup Migratio
Hi, I have quite a few macs with admin accounts on 10.13.6 that dont have a secure token (viewed by running sysadminctl command).I want to add the secure token silently without involving the user via ssh or someother tool, as i have seen the users of the machines have this secure token.I have tried sysadminctl -secureTokenOn "admin account" -password "password" but get Operation is not permitted without secure token unlock.i know that sysadminctl -adminUser user -adminPassword “password” -secureTokenOn "admin account" -password “password” Will probably do it but i cant go asking for the user password Does anyone know of another way?
looking for mac admins in the area to get together once in a while....let me know if you are and we can set something up Dan
Hello, Are there any alternatives to Apples Screen Time, more specifically the App & Website Activity section where we want to track data on how much time students are spending on apps. Not sure if Jamf Pro has any way to configure and collect the data or will we have to go through each students device and set it up and go to each device to collect the data?
Update 19 December 2024: Standard cloud upgrades are scheduled for the weekend of 20–21 December (details below). We appreciate your patience. Today we are releasing Jamf Pro 11.12; highlights include: New Restrictions for Computers and Mobile DevicesNew restrictions include support for bypass screen capture alert and the ability to restrict Apple Intelligence features. Computer Extension Attributes Page RedesignThe redesign features improvements to search, filtering, and display of computer extension attributes. For additional information on what's included in this release, review the release notes via the Jamf Learning Hub. See the latest release notes video for a brief overview of new features and enhancements. To access new versions of Jamf Pro, log into Jamf Account with your Jamf ID. The latest version is located in the Products section under Jamf Pro. Cloud Upgrade Schedule Your Jamf Pro server, including any free sandbox environments, will be
We're looking into solutions for restricting users from download packages or software via Terminal. Just as an example, installing Homebrew via Terminal to install Python. Once users have access to Python, they are able to install and Python packages they please. It's been getting difficult to track who has Python installed and what sorts of packages installed as well. If a user installed Python via the Python website, we can see the installer listed in Jamf's app list for their device but found that if they installed it via Terminal, the only way to detect it is to run 'python3 --version' in Terminal to see if it returns a Python version. I'm exploring to see if we can restrict certain Terminal commands with an Admin password (such as restricting running the command that installs Homebrew). I'm open to seeing if Terminal can be completely locked down with an Admin password but would much like to explore other options first, if available. Has anyone else ran into something like this an
Hello We have started to enroll our macbooks for our employees without adminrights. Yes we have the privilege access configured in jamf connect, but don't want use it for everyone :) So i started to configure what is necessary for our employees that they can work without adminrights. So far so good. Now i am actually helpless with this one problem about creating a symlink via jamf pro policy after installation of Visual Studio code. What i need is: A symlink in the directory /usr/local/bin/code which points to /Applications/Visual Studio Code.app/Contents/Resources/app/bin/code So i am able to create it, but it isnt working. Checking it on a testmachine the symlink shows me in the "get info" as "Original" the path /usr/local/bin/code instead of /Applications/Visual Studio Code.app/Contents/Resources/app/bin/code So its not the first symlink i create but its the first in this location /usr/local/bin/code so maybe i am doing something wrong. I am using this sho
Copied and pasted from Mr. Macintosh site. Safari18.2SonomaAuto.pkg Safari18.2VenturaAuto.pkg
How would I go about blocking extensions on Arc? Since it's a Chrome wrapper will blocking extensions work the same way in Arc as they do in Chrome by using a config profile? If so, what are you using for the preference domain?
Hello everyone, I need assistance in configuring a policy that will apply only one time for each new computer following its enrollment, specifically for machines located at a certain site. The policy's aim is to modify the keyboard layout setting. As it stands, the factory setting for the laptop keyboards is Arabic, and I need to update this to Arabic—PC layout, owing to the fact that most new employees are familiar with the PC keyboard layout. This policy should only affect new installations and not disrupt existing setups. Additionally, I want to ensure that employees retain the option to switch back to the default MacOS keyboard layout if they choose to do so later. I've investigated the following plist file for keyboard configuration: /Library/Preferences/com.apple.HIToolbox.plist However, updating the keyboard layout through system settings does not seem to result in changes to this file. To modify the file, I've drafted a short bash script:  
Hello Jamf family, Is there a script that can uninstall apps like in Intune? Thanks, JM
I have set up Cache Server 1 in City A, where I added the subnets of this location in the "content cache for" section. For my local network, I used the "custom public IPs" option and added a TXT record to the local DNS. This configuration is working as expected. Now, I am setting up Cache Server 2 in City B. The configuration is the same as in City A, ensuring that the subnets in City B fetch cached content from Server 2. I have also configured them as peers, with no parent settings in place, and both City DNS servers are synchronized with each other. Q1: How is data served to clients in City B if Cache Server 1 already has the same files? Q2: What changes should be made so that, in the event one server goes down, devices at both locations can still retrieve data from the other server? Additionally, while both servers are available, how can we ensure that devices access their respective server to minimize latency? Q3: How do peers work in this setup? If Server 1 has a file, does
Is there an inventory setting or extension attribute to see the iPad Chip?
Is there a way to automatically have Safari 18.1.1 install on all end user MacBooks? I 'thought' if we pushed 14.7.1, Safari 18.1.1 would be included/installed at the same time. That does not seem to be the case as users still have to manually go into Settings -> software updates -> updates safari there.
Anyone using EntraID for IDP with JC have any best practice suggestions for what claims to include in the ID Token? We plan to use the Admin Elevation feature for particular groups.
Hello fellow Admins, My company has recently implemented Jamf Connect to do a "pre-provisioned" style setup for refreshes. We are stuck on our new hire setups as Okta is not setup yet for a new hire, but the login requires your Okta credentials. I have seen the option to list a help button that takes the new hire to the Okta portal to finish the setup:https://community.jamf.com/t5/jamf-connect/jamf-connect-okta/m-p/259033. We also have OICD and group access via Okta for our users. Has anyone else run into this situation at their company, and if so, what solutions have you implemented or considered? Feel free to PM me responses as well if you are not comfortable putting any information out in the open. Thank you in advance!
Hi all, I have a client whose company has very strict policy about data protection and privacy. We are developing an App for this client that will utilise the Apple Dictation function. Due to the data protection and cybersecurity requirements, we want to use the Apple Dictation function in offline manner, which is possible. However, Apple documentation did not provide option to exclude audio and text data using in audio transcription process to be uploaded to Apple servers. Hence we are looking to use JamF to block such traffic. In fact, we want to block most traffic to public internet, except those necessary for operating the devices, MDM and app. For example, we will allow list of servers used for certificate validation. My question to JamF community and JamF experts is if JamF can help us achieve our objectives, which including network traffic filtering at OS layer (blocking even iOS traffic to Apple servers)?
I have deployed BeyondTrust's remote support client to my test machine. However, if I set the configuration profile to Allow Standard Users to Allow Access for ScreenCapture, the app doesn't seem to realize it's been authorized. It continues to prompt to allow. Even if I check it with an administrator account. As you can see in the screenshots, even the Accessibility and Full Disk Access are also showing denied, even though they are set to allow in the configuration profile.The fun part is (on a fresh image) if I set the ScreenCapture to Deny, then use an administrator account to allow while on the computer, it actually does allow it.
I'm in the process of migrating our Iphone fleet from a different MDM to Jamf and for this reason we need to wipe our devices completely to enrol them on Jamf.I'd really like to not lose everything our colleagues have on their Iphone but in my tests I can see that the backup step is just before the enrolment step.If I proceed with the backup the last MDM is migrated to the device too but if I enrol the device on Jamf i lose the opportunity to have a backup at all.Is there any smart way to do this that's not just saving everything on a cloud?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!