Get Support
Recently active
Hey folks,I have something odd on a few macOS devices after users change their AD/Entra password via Jamf Connect and sync it locally.Zscaler asking for auth again / certificate install Outlook asking to sign in again Self Service opens but is completely blank Company Portal acts like there’s no server connection Keychain won’t unlock or accept the correct new passwordThe only thing that consistently fixes it for us:Delete everything in ~/Library/Keychains Reboot Log back in Re‑enroll the Mac into Intune via Self ServiceAfter that, everything works normally again.
Hi, I have deployed a CIS benchmark under Compliance in JAMF Pro, I want to use this to justify how secure our Mac devices are and adjust the rules as needed. Is there a way to generate a report is a CSV or PDF format? having a detailed informations or executive summary options?
I have recently taken responsibility of jamf pro from a previous employee and have never really used it before so this is a learning experience. I have a Macbook Pro on Ventura OS in a computer group with a Staff Restrictions profile applied. This profile is somehow completely disabling Control Center and the ability to set a Screen Saver with the message "Control Center settings are not available. These settings are controlled by a profile." I can exclude the device from the profile and gain access to the Control Center and Screen Saver settings but not when it's applied. I figured these settings would be located under the Restrictions payload under Preferences but I see no such setting specifically targeting these. Does anyone know where / what is the setting that controls these? Is it another name or in another location? What am I missing? I see no specific setting to enable / disable. Thanks in advance
We are currently in the process of implementing Jamf Pro in our company environment. So far, we have successfully integrated several scripts, SMB shares, and other configurations, and everything was running smoothly.As the next step, we attempted to set up Jamf Connect in order to integrate a SAML authentication flow via our Entra environment. The goal was to allow users to log in with their Entra credentials during a fresh macOS installation.However, after configuring Jamf Connect, we started encountering a critical issue. The Microsoft 365 login window appears as expected, but after a few seconds, the entire Mac screen goes black and becomes completely unresponsive. The only way to recover from this state is by manually restarting the device.Additionally, since this issue started occurring, our previously working scripts and configurations are no longer functioning as expected.Has anyone experienced a similar issue or has any suggestions on how to troubleshoot or resolve this problem
Anyone want to share best practice for this? Blueutil doesn’t work as great/possibly at all in our environment after updating to macos 26.As a workaround I’ve been using the api to send the MDM command in a policy/script to those macs that turn it off. We have an outset login script that manages to lock out bluetooth changing in the control center and system settings, but there’s a short window of 5 seconds or so where students can turn it off before it is locked.
Hey Jamf Nation,We’ve just added our Jamf 100, 140 & 170 exam voucher codes to Jamf Nation Rewards. You could earn a free certification in the comfort of your home! The Jamf 140 course is our latest offering, launched in April this year 🎉.Check out your Jamf Account to see what’s new and start redeeming those hard-earned bytes.Not a member yet? Learn more and join here.Who’s going to be first to redeem their free exam code 👀
Hello Jamf Nation,Don't miss your chance to secure your 2026 JNUC tickets at the Early Bird rate of $1399 ($1199 for education and non-profit organizations). Starting April 1st, the Just in Time rate of $1,499 will apply ($1,299 for education and non-profit organizations).If you need help getting approval to attend, we've prepared a Convince Your Boss Letter to ensure you don't miss out.Have questions or need additional assistance? Visit our JNUC FAQ or email us at jnuchelp@jamf.com.Ready to secure your spot? Register for JNUC 2026!We look forward to seeing you in Kansas City this September! Best regards,Jeff
We got Defender working on our Macs about a year ago - deployed via JAMF Pro and with configuration profiles. We are not bound to the domain and do not use JAMF Connect.I am trying to follow along with Microsofts documentation (Onboard and offboard macOS devices into Microsoft Purview solutions using JAMF Pro | Microsoft Learn) which seems to be written for setting this up from scratch rather than adding it in to an existing setup. It seems to be doing something as we are getting better feedback under Device Onboarding, but still not making much progress. Here is an example of the details in Device Onboarding in Microsoft Purview with the error messages before and the more informative messages after I have created the configuration profiles in JAMF from the above guide:View under Device Onboarding: Before the configuration profiles were updated: After the configuration profile was updated: In the documentation that I linked to near the top, there is a "Before You Beg
Hey Jamf Nation! With JNUC getting closer you may have noticed that Level Up training options were recently added to the registration page. If you’re not familiar or you’ve never attended Level Up before, I wanted to share a little bit more about these training sessions and what you can expect this year. Level Up at JNUC returns as one day, exclusive, in-person training opportunities that take place the day before the conference kicks off. They will be held at the same location as JNUC, the Kansas City Convention Center, on Tuesday, September 22nd.These learning experiences are supplementary to the Jamf Training Courses like the Jamf 200, 300, and 400 Courses, but you don’t need to already have taken any of those as there are no prerequisites to participating in Level Up besides being registered for JNUC. If you have already taken some or all of these courses before, you may recognize some familiar faces at Level Up as they are taught by the same Jamf Trainers that design and teach our
Today, Jamf Training turns 20, and the milestone is worth pausing on.More than 40,000 people trained through instructor-led courses. Over 120,000 reached through the Online Training Catalog. 60,000+ certifications issued to IT professionals who've built careers on what they learned here.When we started this journey, the term "Mac Admin" didn't exist. There were no careers in Apple endpoint management. The path you're on today? It wasn't there yet. You, and people like you, built it.Now Jamf certifications are the industry standard for Apple device management and security. The admins who get trained deploy faster, run leaner operations and support their users better.But here's the thing: none of those numbers belong to us.They belong to you.To every admin who took a course before they felt ready. To everyone who earned a certification and finally had the credential to back up what they already knew. To the ones who stayed up late, asked questions on Jamf Nation, and showed up to JNUC re
We use Jamf Pro Cloud with Jamf Connect (for account creation + Entra ID password sync).After enabling “Use Self Service+ as the default end user app” in settings:Old Self Service was upgraded to Self Service+ on existing Macs Jamf Connect was removed, menu bar now has Self Service+ icon instead On new enrollments, we install Jamf Connect 2.45.1 → now it’s there alongside Self Service+I can’t find clear docs on this — so:Questions:Is Self Service+ intended to replace Jamf Connect completely? If yes, should we skip installing Jamf Connect post‑enrollment? Or should we move to Jamf Connect 3.x? Any official migration guide for 2.x → 3.x with Self Service+?Any experience or official Jamf resources appreciated.
Hello Jamf Nation!We’ve released Jamf Pro 11.28.0 beta. This release includes Mutual TLS Authentication for Webhooks, Jamf Pro API Changes and Enhancements and more! For full details, check out the release notes after enrollment.How to join the beta: Enroll in the Beta Program under Product Feedback at account.jamf.com. Click “Join Community” to join the beta forum once enrolled. If you encounter an error on Jamf Nation joining the beta forum, please log into Jamf Nation and then click “Join Community” again. Please also check out this recent blog on Configuring SSO in Jamf Account prior to testing Compliance Benchmarks, Blueprints, and App Switcher. Email beta@jamf.com with questions.The beta program is covered by the Jamf non-disclosure agreement; please do not share any information regarding your testing on any public forum, including the non-beta areas of Jamf Nation. Use the Jamf Nation Beta Forum or contact Jamf via beta@jamf.com with any questions. Thank you to all who participa
Hi everyone, I’m new here, so if this has already been asked before, please go easy on me 😅 Here’s the situation: I have a client who wants to prevent their developers from losing time every time they switch to a new machine (setting up their development environment, SSH keys, cloning repositories, etc.). Right now, their servicedesk team spends almost an entire morning preparing each device… but here’s the catch: instead of rebuilding the environment cleanly, they’re cloning everything from the user’s old machine. Personally, I don’t agree with this approach. I believe it’s better to go for a clean and automated process: regenerate SSH keys, clone repositories from Git, and configure the environment from scratch. So my question is:Is there any common approach or script within the community to handle this kind of scenario?For example, something that, using the user’s credentials, can generate SSH keys, clone repositories, and apply typical developer configurations. Any guidance, share
Trying to deploy device based certs to Non Domain MacOS devices, which will automatically connect to wifi. We have the following configured: AD (Ghost object created for the MacOS Device) ADCS (separate certificate template created for Mac) NPS NDES When we deploy the cert from Jamf, the cert deploys and installs on the device and I can see it’s issued with the correct template in ADCS. When we try connecting to wifi, we see ‘The specified user account does not exist. What am I missing? The domain controller is 2016, ghost object created, network policies created, we just can’t seem to bind the cert to the ghost object therefor it does not authenticate. Windows auth is obviously fine via the same NPS server. Any suggestions?
I was wondering if Jamf Hero’s is still open? Is there a application process?
Does anyone has a way to setup MS Outlook 365 as default mail app? If you want to setup it manually you have to do it in the Mac mail app, although you never used it. I have to send out something to the organization with an mailto: link and I do not want all people calling me to ask why Mail is opening instead of Outlook. Additionally it would be nice to set default programs via config profile in Jamf pro. Thank you for your help.
Any had this issue , devices where PSSO was already registered, users were prompted again to register. When they attempted to register, the process failed, and the devices entries are removed from Azure, resulting in loss of all organization access.we had to re-register the devices through System settings > User and Groups > Network account server > Edit, and then click repair.Note: We use Secure Enclave as authentication type, No changes where done at profiles
I’m well aware that there’s a big “old dog/new tricks” aspect to my reticence to move away from configuration profiles to blueprints, but my primary hangup with even exploring Blueprints too much is the limited scoping capabilities. In particular, I find it really useful with a configuration profile to just be able to exclude a single computer from the scope to remove it for testing or other reasons. But with Blueprints being entirely smart group dependent, the only way I know of to do that would be to modify the smart group to not include a computer name, or maybe link the smart group to a static group, but that feels janky. Help me think through this please.
Today we are releasing Jamf Pro 11.27; highlights include:AI Assistant in Jamf Pro General AvailabilityYou can use Jamf's AI-powered conversational assistant to support your organization's device management and security. AI Assistant consists of individual functionalities called "tools" that are organized in tool groups by product. When you enable AI Assistant, you enable AI Assistant Core, a foundational knowledge tool that can assist you with technical questions about Jamf's software and services. In addition, you can enable read-only tools for Jamf Pro. AI Assistant is disabled by default. Setup Assistant for Configuring OIDC-Based SSO with Jamf AccountA setup assistant for configuring OIDC-based single sign-on (SSO) with Jamf Account has been added to eligible Jamf Pro environments. This provides a convenient way to configure SSO through Jamf Account completely within the Jamf Pro interface, streamlining authentication and enabling platform capabilities in Jamf Pro. Enhancements to
For over 16 years, Apple admins have gathered at the Jamf Nation User Conference (JNUC) to learn, connect and discover better ways to manage and secure Apple devices. In its tenth year, the JNUC Diversity Sponsorship awards 10 individuals a full conference registration, a meet-and-greet with Jamf leaders, a networking happy hour and a $500 stipend to help cover expenses. We're looking for passionate people eager to learn and bring fresh perspectives to the tightest community in high tech.Applications close at 5 p.m. CST on May 1, 2026. Apply now!Read further to get all the details about Scooter and Alan's first-hand experience as scholarship recipients. SCOOTER’S STORYMy name is Scooter Kohler and I currently work at Alhambra ESD in Phoenix, Az. My journey with Apple hardware didn't start in a server room; it started in my daily life. I’ve been a MacBook user for the entirety of my adult life, drawn in by the clean hardware and stayed for the intuitive nature of the software. When the
I have searched AI and here but I can’t find anything that matches (or works) for our organization. I would like to have (as part of the pre-stage enrollment) the Mac device be renamed to a prefix + s/n. The configuration profiles logs all show MacBook Pro or Users’s MacBook Pro and not the naming scheme that is approved for the company. From what I understand, you can’t go b ack and rename machines in any log. and modify it.
Hi, First time poster here.We have a fleet of student iPads that we're managing through Jamf, and that have Microsoft Teams deployed on them for classwork.The students have learned that, if they tap "+ Add Account" within Teams, they can connect a personal Teams account within the app, and have been using this to send notes in class without oversight.We've been able to limit the Windows Desktop Teams App so that it'll only allow accounts on a specific Teams "tenant ID" to sign in - and we're hoping that a similar capability is possible in the iOS Teams app via Jamf, but have had trouble finding any information about it.Is this something that anyone has managed to accomplish, or has advice about? I'm relatively new to Jamf, so step-by-step guides are greatly appreciated.
Hey Jamf Nation! 👋 🚀 Free live LinkedIn workshop. April 22. Register now → https://jamf.it/JamfNationEvents Still here? Great. Here's the deal. 👇 Most of us in IT and security treat LinkedIn like a digital parking lot: set it up, forget it, and hope no one looks too closely. But LinkedIn is quietly one of the most powerful tools in your career arsenal. For finding your next role, building your network, and getting recognised as the expert you already are. We're bringing in Devin Reed, a content strategist who helps professionals and executives grow their LinkedIn profiles (and helped scale LinkedIn programs at Gong and Clari), for a live workshop built specifically for people like you. He'll break down exactly how to make LinkedIn work for you, without feeling like a self-promoter or spending hours every week on it. You'll walk away knowing: What a strong profile actually looks like (and how to fix yours fast) How the algorithm works and what actually gets you seen The sim
Can get some help with Packaging Xcode. We currently use Mac apps but it a hit and miss. I will like some help on the best practice to packaging and maintaining this app.
We’ve been using Jamf now for almost 10 years and are still struggling with users that don’t update their computers and mobile devices. So now we’re thinking of activating Software updates in Jamf. When we choose activate/enable it we get the message bellow. Is it just to continue or could it cause problems?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!