Get Support
Recently active
Pretty sure I know the answer, just doing due diligence at this point.We recently modified our local account password policy where we are actually are now enforcing one. For background, we’ve had a local account password policy for years, but never enforced it. Now we are.We’ve had a number of users who have been presented with the password change dialog, and rather than changing the password have clicked Cancel instead, then keep trying to login with their current password, which has resulted in them getting locked out.The field support team has asked if it's possible to modify the text in the PW change dialog in some way to help people understand that the pw change is not really optional.I didn't think there was, and I haven’t found anything to suggest otherwise, but thought I’d check in here to see if anyone has any suggestions.
We purchased some M5 MacBook Airs with Tahoe with 26.2 installed and when we deploy them to a new staff person, they are required run a macOS update despite the fact we have the minimum required macOS version in the prestage set to “no enforcement”. I don’t think this was happening in previous macOS’es.This just prolongs the onboarding process.
I was struggling with targeting a Web Clip in Single App mode for some iPads. I found several articles saying you couldn’t do it until I found a Jamf article saying that it was possible but, only by targeting the specifc bundle ID of the Web Clip.https://support.jamf.com/en/articles/13274571-configuring-single-app-mode-for-web-clips-in-jamf-proThis sounded great and I thought my search was over. However, this didn’t work. It made sense though, targeting the specific payload identifier should work. So, after much testing I discovered the following with regard to targeting a web clip in single app mode:1. There can only be a SINGLE web clip profile with a single web clip payload deployed to the iPad. I chose full screen but, it might not matter.2. The Single App profile MUST use the standard "com.apple.webapp" bundle ID.That's it. If you do those two things, the single web clip will present in Single App mode.Good Luck!
Introducing the MacAdmins Definitive Resource DirectoryOne of the greatest difficulties I found when I began my career as a Mac Systems Administrator was not learning the technology or the tools, but rather finding out where I should be looking. The MacAdmins community holds a vast amount of information and resources, however, due to the sheer volume and the fact that there is so much spread around the web, it can become quite intimidating, especially for newbies.This is why I decided to create the MacAdmins Definitive Resource Directory: https://github.com/maccy10/definitivemacadmins Reasons for Building This ProjectOf course, there are already other very good, curated collections of links, and it would be unfair not to mention the projects that inspired this one:* Community is Valuable: A List of My Favourite Community Resources: https://community.jamf.com/tech-thoughts-180/community-is-valuable-a-list-of-my-favorite-community-resources-53430* https://github.com/JordyThery/bookmarksJ
Hi,We're starting to see a number of cases being raised internally about some of our Macs (all on macOS 15.1.1) having intermittent login issues. Our devices are bound to AD and our users have been logging on fine for some time but now we're starting to get issues. Sometimes the logins are fine. Sometimes they take ~10 mins and sometimes they appear to stall completely (waited over 2.5 hours in testing) even on the same device. The login screen appears to freeze (the time doesn't change) and you eventually get the spinning beachball. SSH is still working and you can run a "jamf policy" successfully. "Screen Sharing" reports that the user who has attempted to log into the device is the active user when you connect.Can anyone share some tips as to how we would start to investigate this sort of issue let alone resolve it???ThanksStuart
Hi everyone! Looks like Microsoft may have finally released a compatible version of Company Portal for simplified platform SSO to work with JamfPro and Intune :). I’m sure I’m not the only one who’s been keeping an eye out for Microsoft to release a compatible version of Company Portal for Platform SSO during registration, so wanted to share the info with everyone. I noticed late yesterday that Microsoft updated their “What’s new in Intune” page with this little tidbit:What's new in Microsoft Intune - Microsoft Intune | Microsoft Learn They released this blog post in the last couple hours:New Platform SSO with registration during Automated Device Enrollment on macOS | Microsoft Community Hub And here is the direct link to the Microsoft learn article on setup for it:Add Platform SSO policy to ADE Profile on macOS devices - Microsoft Intune | Microsoft Learn Anyone gotten a chance to play with it yet? If so, what are your thoughts? It’ll likely be tomorrow before I get a chance, sad
Hi there,I try to use Jamf Setup Manager to made zero touch installation on my Macs.First question, i don’t have found how to launch JSM after enrollement wouthout let a welcome pane open. If the Mac return back to login screen nothing happens. Is it possible to automatically launch JSM without a pane opened?I also try to change Mac name and sync his identify on Jamf inventory, which are the command i could use in JSM to do this?Thanks for your help
I had a support ticket recently where a user reported that they couldn’t update any packages they had installed in the TeX Live Utility, and I wanted to post here in case anyone was searching around for a solution. The large majority of our users don’t have local administrator rights on their Macs, so I wanted to find a solution where they could update their packages within the program without being prompted for administrator credentials.The solution is to create a Jamf policy to install MacTeX (of which TeX Live Utility is included) via Installomator and make this installable via Self Service.General > Display Name: MacTeX LatestCategory: UtilityTrigger: <Leave Blank>Execution Frequency: OngoingScripts: installomator.sh and Tex Live Utility Script (see below)Scope: As desired, but I elected to make this available to ‘All Computers’Self Service: Choose a Display Name and short Description. I then checked the Utility category.User Interaction > Complete Message: MacTeX has b
I’m struggling, we’ve got a policy that disables uninstalling apps and system apps, and we have a policy that enables uninstalling apps and system apps.I’ve confirmed the Disable policy was removed from the device and the Enable policy was installed. I’ve confirmed no other applied policies are affecting those toggles (“remove apps” and “remove system apps”)For some reason, the device still won’t let us uninstall apps. What am I missing? We’ve restarted the devices and still no luck.
Hi all!We have been having a very strange problem for a while, the iphones without touching the buttons or starting the recovery mode are formatted from the factory. It does not happen to us in all the iphones devices that we have in Jamf but we have reported more than 15 cases with this problem, we reviewed the configuration and we did not find anything strange. We have configured the installation of updates if the user has not applied the update after 90 days, but these cases occur with all the updates made.Do you know what could be due?Thanks!
Hey Jamf Nation,Happy WWDC week 🎉!The festivities kicked off yesterday with Apple’s Keynote and Platform State of the Union.So let’s dive in…What are you most excited about so far? Either professionally or personally!
Anyone running into an issue with the Shared Device SSOe profile failing to install on shared iOS devices? I set up the Intune integration with Jamf Pro for both shared devices and standard iOS devices. Standard iOS devices register with Microsoft just fine, but don’t actually perform SSO with the Microsoft apps but they do show as compliant in Entra. I had the Shared Devices registering for about two days and now after wipe, The “Install Device Compliance Shared Device Profile” command fails every time even with a different device. Previous Entra records have been removed. Any ideas of what I could try to fix it or where I can find more detailed logs? History of failed commands had nothing.
Jamf Icon Uploader is a utility that streamlines the bulk upload of icons to Jamf Pro, eliminating the tedious process of uploading them one at a time. This app was built to solve a common pain point: hosting app icons on Jamf Pro for use with Setup Manager. Instead of manually uploading each icon through the Jamf Pro interface, you can now upload an entire collection in a single operation. • Link: https://hcsonline.com/support/resources/apps/jamf-icon-uploader?ref=macadmins.news
I understand that it’s expected behavior, but when using the “Preserved Apps” option with the Return To Service feature, OS updates can’t be installed.Has anyone found a way to work around this limitation?
Taking a swing at the regex. How is this?iOS/iPadOS 27 (Regex Devices Can't upgrade)^(iPhone(12|13|14|15|16|17|18|19),\d|iPad(8,(9|10|11|12)|12,\d|13,(1|2|1[6789])|14,(1|2|[89]|1[01])|15,\d|16,\d|17,\d))$
What’s new in managing Apple devicesDiscover the latest updates to declarative device management, Apple Business, and Apple School Manager. Explore how these advancements help you streamline deployment, strengthen security, and improve the experience for people using your managed devices. Whether you're building device management solutions or managing enterprise fleets, you'll learn practical ways to take advantage of these new capabilities. https://developer.apple.com/videos/play/wwdc2026/206/
I have trouble under this device ID 116, because It’s failed to delete or looking details in Jamf Pro
How to bulk lost mode a smart group of ipads in Jamf Pro?I have a smart group but lost mode is not one of the available remote commands?Suggestions?
I am trying to configure Baseline. I can’t seem to get the Global Status Icons to work. For example: Global Status Icon - Fail:SF=xmark.circle.fillGlobal Status Icon - Success:SF=arrow.down.circle.fillGlobal Status Icon - Wait:SF=progress.indicator They don’t show up at all when deploying packages.
Standalone rostering tools sync class lists and stop there. They don't connect to your identity system, SSO, or governance policies, which means gaps, lingering access, and manual cleanup for IT. RapidIdentity handles rostering natively within your IAM platform. When a student enrolls, their identity, access, and rostered apps are all provisioned in one workflow. When they leave, it all unwinds automatically. No reconciliation. No disconnected tools.Identity and rostering working as one system means students get access on day one, and IT stays in control throughout the lifecycle. Want to go deeper?We have new RapidIdentity Studio Academy courses that cover IAM-integrated rostering in detail. A great next step if you want to see how this works in practice. Drop your questions in the comments or share how your district is handling rostering today.
Hello,Currently, the date of the day is displayed at the top of the message, but the subsequent messages do not have a specific timestamp. For better organization and a clearer follow-up of discussions, I suggest adding a precise timestamp (time) to each message. This would help us keep track of conversations more effectively, especially for instructions or immediate feedback.Thank you!
We recently laid off 14 people and were going to gift them their M1 Laptops after they were off-boarded. I issued Lock Computer commands from JAMF Pro to each machine and, to my surprise, found that only 3 of the 14 had actually locked out the user. Luckily, these folks were all friends of the company (sad) and they did not do anything malicious, but I was able to use my TeamViewer link to the machine to go in and ‘removeFramework’ and re-enroll. After that, I was able to wipe the machines normally. Is there a way to get the rest of my machines back into compliance without removing the framework and re-enrolling them, one by one? Will a ‘renewDeviceCert’ work? Thanks.
Last year, I had the extraordinary privilege of travelling to Zimbabwe to meet and teach some of the most driven, curious students I've ever encountered — the cohort at the MATTER Career Readiness Institute (MCRI). If you're not familiar with MCRI, let me explain why it matters. You may already know the Matter Innovation Hubs (MIH): tech-forward, student-centred environments designed to foster active learning and creativity for children who often lack access to critical educational resources. MCRI takes that mission further. It's a post-secondary workforce training program with a bold goal — equip young Zimbabwean students with the skills needed to become software engineers and secure remote employment with Western companies. In an environment where opportunity can be rare, MCRI is opening doors that were once closed, helping students turn potential into power. How the program worksStudents apply from local secondary schools, go through a rigorous selection process, and dive into a cu
I’m just wondering if anyone has got this to work via Jamf Pro on-prem?I’ve created a package deployment of the latest Company Portal, configured the SSO extension profile as explained in the Jamf guide for Entra, and setup the pre-stage enrolment but when I go through the setup on my test MacBook Neo it doesn’t work.It takes over 15 minutes to try and install the Company Portal and then just moves on to the ‘create user’ step. If I restart the MacBook Neo it may eventually pick up the Company Portal and SSO extensions but then after signing in via Entra it shows a “Sign in to your organisation” screen with a box for username and a box for password, which will not accept any kind of credential.I can access the package URL and download the pkg file in seconds via a browser. I’ve reloaded Tahoe on the MacBook Neo and deleted and recreated the SSO extensions, still nothing.Thanks
Does anyone have any insight to when (or if) Jamf Security Cloud will be available on MacOS and Windows?I see the options as not yet supported, but wondering if there is a timeline on that.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!