Get Support
Recently active
We are a K-12 independent school preparing to implement Jamf Protect. Our immediate, high-priority goal is reigning in the highly creative gaming habits of our middle schoolers and not so much of malware protection. We recently migrated away from Santa and are hoping Protect will be our new line of defense. If you are using Protect as a method similar to this, what are some things you wish you knew when you first implemented it, or what challenges or succeses have you had with it?
So I was looking at deploying the updated Adobe apps using the Mac Apps feature rather than packaging up from the admin console and making a policy. However; Apparently you can only target one group. O.N.E. group for deployment. Since I want to stage the deployment to different labs rather than all at once (by making yet another smart group), I would have to add multiple instances of the app.Blueprints can be deployed to multiple targets, So can software updates. Why can’t Mac Apps do the same? Am I missing something?
With Jamf Pro 11.30, administrators have increased visibility with a new Last Contact field in device inventory and can configure activation conditions for blueprints. Be sure to check out the Jamf Pro release notes for all of the exciting new features and enhancements.Thank you for your continued support and feedback!
Today we are releasing Jamf Pro 11.30; highlights include:Inventory Reporting EnhancementA Last Contact field has been added to computer and mobile device inventory records. This attribute displays the date and time a computer last made contact with Jamf Pro using the Jamf binary, MDM, or declarative device management, or the date and time a mobile device last made contact with Jamf Pro using MDM or declarative device management. This attribute can also be used as criteria for smart groups and advanced searches. For additional information on what's included in this release, review the release notes via the Jamf Learning Hub. Subscribe to Jamf Learning Hub contentWhen logged in to the Learning Hub, click the Subscribe button (bell icon) on the release notes page to receive email when that content is updated (i.e., a new version of Jamf Pro is available). For more information about the Subscribe feature, see Jamf Learning Hub Watchlist. To access new versions of Jamf Pro, log into Jamf A
We are excited to announce the return of the Learning Hub watchlist. To get started, log in to the Learning Hub and click the Subscribe button on any page you would like to watch. You will receive email notifications when that content is updated. By subscribing to "Release Notes" and "Release History" pages, you will be notified when a new version of a Jamf application, portal, or capability is available.Notes: You will receive a separate email from "learn@jamf.com" for each page you have subscribed to. The subject line of each email message will include "search summary". Email notifications will be sent once per day at 11 PM Central Time (UTC-5). To manage your subscriptions, navigate to My Library > saved searches.
Are you familiar with or have you used MacPAR deLuxe?For a long time, it was a go-to tool for creating and using PAR2 files, which can repair corrupted files using parity data. PAR2 files are primarily used on Usenet servers (newsgroups).The problem is that the application was developed solely for Intel-based Macs and appears to have been abandoned since 2018. Furthermore, the announced removal of Rosetta 2 in a future version of macOS effectively rules out its use on Apple Silicon Macs.PAR2Manager can help you solve this problem. Developed natively for Apple Silicon Macs (while remaining compatible with Intel Macs), this open-source application allows you to create, verify, and repair PAR2 file sets.GitHub : https://github.com/chrisbasse/PAR2Manager
This thread is a decent reference to the "feature" on Big Sur, as it's not brought up that much from what I can tell: Solved: Hide "Your screen is being observed" - Jamf Nation Community - 236104Unfortunately the solution was "you can't" and I would not be surprised if that's the same solution here, just want to confirm before I have to break the bad news to the teams that'll be affected by it. Now when you remotely screenshare with ARD/VNC, it makes a very obvious popup from the menu bar with icon stating that "Your screen is being controlled" with the IP that it's coming from:And then on top of that, it says when it stops being observed: I get that it's for security and can help a little bit, with the off chance that someone sees a connection that's not with an expected IP address (for example we'll be asking folks to watch for any non 172.etc addresses), but most end users won't know or retain that information and generate unnecessary noise and change a lot of behavio
Is the API call for the "Overview of Automated Device Enrollment devices" working for anyone? I use Jamf School, and while many endpoints work perfectly, this one doesn't. I am getting a "404 Not Found" error.GEThttps://{yourDomain}.jamfcloud.com/api/dep
I am attempting to roll out Jamf trust for ZTNA. I currently have Crowdstrike falcon installed on all of my fleet. My understanding is a limit of Mac is only one network filter can be active at a time. It seems like Crowdstrike doesn’t play nice with Jamf Trust. Even with the filter disabled I am unable to edit the DNS settings to have default to Jamf. Has anybody successfully deployed both products?
Districts buy a lot of apps. Some get used every day. Others quietly gather dust after the first semester. The problem is that most IT teams don't find out which is which until renewal season, by which point it's too late to make a good decision. That's the gap RapidIdentity Insights is built to close.What Insights actually shows youInsights is the analytics engine built into RapidIdentity. It doesn't just tell you an app is licensed. It shows you how students and teachers are actually using it, down to the individual login. That includes:A full inventory of your SSO applications, including their status, security controls, and who has access to what Usage stats by user type, school, grade level, or location, so you can see exactly which apps are catching on and where Trend analysis and forecasting, so growth or decline in adoption shows up before it becomes a budget surprise Individual application launch events, if you need to drill down that far Engagement tracking, including which us
We have all our Users Synced from ASM. Pupils will bring their own iPads from August. These will not be Supervised but we would like them all to enrol in JAMF.Is there anything that could be done during Enrollment that would automatically associate the device with the correct User so that we can use JAMF Student?
Another year, another Jamf Nation Live London and Berlin in the bag! And this might be bold to say, but I think it was the best one yet. This year, the Community team wanted to approach things differently. Rather than assuming we know what you need from us, we wanted to hear it directly from you, the community members, so we could understand our gaps and figure out how to close them. My "vision" was simple: create an interactive space that got attendees to stop and think about where they are in their Apple admin career, and see other people right there alongside them. We built a wall showcasing the different stages an Apple admin might find themselves in, from just starting out in management and security, all the way through to leading teams and strategy, with plenty of stops in between. Attendees filled in cards with a mix of light-hearted preference questions (light mode vs. dark mode... guess what won? 🌚) and the areas where they'd like more help, like AI integration, career growth
https://ideas.jamf.com/ideas/JPRO-I-2178i think this would be invaluable, please vote on if you agree
Newbie MDM user here. Signed up for Jamf Now and have 6 iPhone 14's being managed for work. The iPhones are not signed into an iCloud account. What is the best/easiest way to push a managed list of contacts to the phones?
What are the best practices for legal name changes for staff when utilizing Google Workspace and JAMF Connect? If you change the Google Workspace account name, JAMF Connect creates a new user on the users Macbook when they log in with that new account. How would I effeciently sync the new google account to the previous user account. I have read the Unmigrating a local Account post, but not sure how that helps with linking the new google account to that unmigrated account now.
Configuring single sign-on through Jamf Account for administrator authentication to the Jamf platform now supports Microsoft's admin consent flow for Entra ID connections.From Organization > SSO > New Connection, choose Entra, then select "Use Microsoft's admin consent flow for multi tenant applications." Click Connect with Microsoft and approve the screen. If you're not the Entra Global Admin, copy the link and send it to them instead. Once they approve, Jamf configures the connection. Manual configuration is still available as an option.New Entra connections request GroupMember.Read.All and User.Read instead of Directory.Read.All. Existing connections on the old scope can switch to the new scope using the "Entra Scopes" selector, which preserves existing group mappings.If your organization's domain is already verified in Microsoft Entra ID, Jamf inherits that verification automatically. Domain verification in Jamf Account is skipped for that connection.Full setup steps: Setting
I’m not sure if anyone else was struggling with some of these apps as much as I was for the past few weeks but we’ve got quite a few that we use in our environment: Linear, Notion, Claude Desktop, Google Antigravity (just to name a few).If so, I was able to create a few configuration profiles that will stop them from auto updating and stop all those annoying prompts users keep getting.I’ll leave a comment with each config profile\policy and the setup and hopefully it’ll save someone out there some time and headaches.
Hey Everyone, I have been battling this issue for quite some time and have done rigorous testing but have sincerely hit a wall with this issue. My organization is prepping to remove Administrator access from all users on our macOS systems, this requires them all to be converted to a Standard user. (We have a "MakeMeAnAdmin" script in place in JSS we plan to utilize) MacOS: 14.3.1Jamf Connect: 2.32.0 We use Jamf Connect with Azure/EntraID so users can authenticate on login, we have the app roles setup for the app registration in Azure with two groups, MacUserAdmin-Entra & MacUserStandard-Entra with the correct roles tied to each (Administrator & Standard) The Problem:Whenever a user is moved into the group tied to the STANDARD role in Azure and attempts to login to Jamf Connect on one of our Macs they can enter the O365 email, PW, verify 2FA, but then hit a "Yellow Exclamation Point" box with simply an "Okay" button. Once you click "Okay" you are kicked back
Is anyone experiencing issue with the lock desktop wallpaper configuration with macbook neos in Tahoe 26? I can get the configuration profile to block the “change the wallpaper” section in System Settings; however, users can still download a picture and right click to “Set Desktop Picture.” I have a policy to downloads and sets the wallpaper, which works, but users can now download any image and set the wallpaper. I am uncertain if this is a OS bug with Tahoe
Hey Community,From now until Sep 26th, you’ll earn 20 BYTES in Jamf Nation Rewards just for subscribing to our Jamf Nation General Discussions!How? Easy:Head to the page linked above! Click the big blue Subscribe button. Stay in the loop on all things Jamf + Apple - and get rewarded for it!⭐️ BONUS TIME ⭐️For a limited time, get 50% off the bytes needed to redeem some of our newest swag. Imagine rocking that gear at JNUC!Not part of Jamf Nation Rewards yet? If you’re a Jamf customer, sign up through your Jamf Account (details here).Your swag is waiting…⏰Please note: You may not see your new points reflected in your Jamf Nation Rewards Account right away. We are currently in the process of reconnecting our updated Jamf Nation with Jamf Account. We appreciate your patience while we reconnect these programs.
Hi. Im working with the new platform API, but i cannot access the Integrations tab on our company Jamf Account, and every time need to ask my colleague. My colleague has exactly same permissions as meand yet he can access Integrations tabs just fine, creating and modifying integrations, while all am seeing is two errors:Has anyone had a similar problem and managed to resolve it? Our accounts are provisioned from Duo IdP
Hello, Looking for a way to configure the Global HTTP proxy via Jamf Pro for macOS. The "Global HTTP Proxy" payload is only available for 'Devices' in JamfPro. We previously pushed a proxy pac URL setting that restricts browsing if not signed in to VPN via a script from macmule that uses the networksetup command. We found that this method doesn't restrict Safari and only restricts Chrome. After a chat with Apple Support, it appears that we need to use the Global HTTP proxy method for it to apply to Safari. Has anyone deployed a "global HTTP proxy" configuration to macOS devices via Jamf Pro? Thank you! Thank you
Anyone able to update to Google Chrome to version 150+? I’m stuck at 149. It won’t flip for me. And I tried creating a new title too.
Has anyone else noticed that custom Self Service branding no longer applies to App Installer / Notification Center notifications?Environment:Jamf Pro (current version) Self Service 11.28.1 macOS Tahoe 26.5.1What I’m seeing:Self Service branding is configured correctly in Jamf Pro. The custom icon appears correctly in the Self Service UI and as the application icon. However, macOS Notification Center notifications (e.g. App Installer update notifications) show the generic Jamf icon instead of our branded icon.Some investigation:Notifications appear under Management Action in System Settings > Notifications. CFBundleIconFile for Self Service points to AppIcon. AppIcon.icns appears to contain the generic Jamf icon. Running selfservice branding brand --icon <path> changes the Dock/Finder icon but does not affect notification icons. The behavior appears to be specific to notifications delivered via Management Action, which is how they appear in System Settings > Notifications.I
Many organizations recommend or prescribe a specific web browser for their users. The user can change the setting in the user interface, even though it is not really obvious where to look. Many MacAdmins would like to pre-set this browser and the default during enrollment. However, there are several challenges associated with this in macOS. It would be really nice if Apple provided some means to manage this with a configuration profile. If you agree, please file feedback with your AppleSeed for IT account. While we wait for that, what can we do? Use the browsers Most third party browsers have a built-in command option to set themselves as the default browser. Most Chromium based browsers (Google Chrome, MS Edge, etc.) can be launched with the --make-default-browser option: open -a "Google Chrome" --new --args --make-default-browser open -a "Microsoft Edge" --new --args --make-default-browser For Firefox, the options are different: open -a "Firefox" --new --args -silent -nosplas
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!