Get Support
Recently active
We want these to NOT be able to be toggled off, even by an admin - ideas?
Is there a way to get a report or list of all failed commands for our mobile devices in Jamf Pro. Whenever I go to a device for any reason I often find failed commands from several months ago and manually clear those. But it would be nice to be able to know all the devices with failed commands so I can look at what failed without having to go to each device individually.
Hello, Is it possible to block the passwords app within Mac OS Sequioa I tried to block it through a config profile and also a policy but I’ve had no luck is this an app that can be blocked or no?
Does anyone know if there is a configuration profile I can use to turn off Settings -> Home Screen & Dock -> Show App Library in Dock? I see iPadOS 15 decided to add this "super helpful feature" for us and defaulted it to on, of course. It ignores my Home Screen Layout profile and puts it in the dock anyway.
Today we released Jamf Connect 2.40.0. This release includes the following changes and improvements: The Verify User Promotion via FIDO2 (VerifyUserPromotionFIDO2) setting allows administrators to have users authenticate through Safari prior to a privilege elevation session. Authenticating within a browser adds support for WebAuthn authenticators including passkeys and FIDO2 keys. This setting is currently supported with the following identity providers: Microsoft Entra ID Okta Identity Engine Okta OpenID Connect (OIDC) PingFederate Note: Requiring WebAuthn authentication for privilege elevation may require changes to your identity provider's authentication policies. After enabling the setting, the Jamf Connect OIDC application located in your identity provider configuration must use the following Redirect URI to prevent any errors: jamfconnect://loggedin The Jamf Connect menu bar app now displays the temporary privilege elevation duration in the format "MM:SS" to improve
Hey folks,Since updating our inventory of MacBooks to MacOS 14 Sonoma, users have noticed weird behaviour with Airdrop that was working correctly on MacOS 13.x. From the jamf-managed MacOS 14 MacBook, users can:Airdrop TO Jamf-managed iPad (iPadOS 17.0.3)Airdrop TO non-managed personal iPhone (iOS 16.7.1) However, airdrop is not working in the other direction. If the other devices are not signed into the same iCloud account, the MacOS device is not even visible as an available device to airdrop to (visible to everyone settings are enabled). If the devices are signed into the same icloud account, the MacOS device will be visible as an Airdrop target, but actually sharing a file will timeout and fail. All of these devices (including jamf-managed MacOS) are able to Airdrop TO a personal non-managed MacOS 13.4 device We have no Configuration Profiles restricting use/access to Airdrop. Airdrop settings are set to 'visible to everyone' on all devices. The issue only
This is going to sound lame, but how do I turn off this new feature using a Jamf Pro config file? We are Jamf Cloud hosted so we currently have the newest shipping version of Pro. Given that we are in a school setting, our teachers don't want a student using the new functionality on an iPad to get things done for them on say a math test. I'm told that Jamf Teacher might offer this capability, but I want to know all the ways to possibly control this including from the centrally-set side.
I've tried moving all of the apps that use Policies to install to use Jamf App Catalog instead (if they are present). What I noticed is that the apps take a long time to install when re-provisioning a Macbook. Sometimes it would take 3 days before the apps would show up as installed on the Macbook. Is this delay normal? Is there a setting to force it to install immediately after enrolment just like it did with Policies?
I add all email accounts to our end user iPhones during setup using Configuration Profiles (Exchange ActiveSync & Google Account). I am a one-person tech department for an organization of ~40 end users (including myself), so I typically employ 2-3 of our most trustworthy and tech-literate managed end users as "testers" for new major OS upgrades before deploying them organization-wide.Since updating two managed end users to iOS 18, they have both lost access to the "Auto Reply" option underneath each of their managed/Jamf-deployed Mail Accounts (whether Google or Exchange). I have always limited their ability to turn on Notes, Reminders, and Contacts in these accounts, and before iOS 18, they always retained access to "Auto Reply" and "Account Settings" despite the aforementioned restrictions. This seems like a massive step backward if it's intentional. Any ideas? Am I missing a new feature/setting I need to turn on or off?
I have created a configuration profile using "Application and Custom Setting" Payload with Application domain as "com.microsoft.wdav" where I am enabling "Real-Time Protection" (attached screenshot). When I push this config profile, it enables the "Real-Time Protection" on device and make it restricted (attached screenshot) stating "This setting is managed by the organisation"When I upgrade the macOS to 14.7, suddenly the real time protection setting becomes unrestricted. As far as I know, any application setting managed by JAMF is restrcted by default. Hence, I need you help to understand why the setting is reverted post OS upgrade? And, how can I ensure that real time protection is restricted for user to make the changes?
These unwanted logoffs happen in most cases when I click on the "Refresh" button after uploading PKGs to our Jamf Cloud server (hosted by Jamf).I always use Safari (with a 2-factor auth.) for Jamf tasks, should I change the browser or is it a browser settings thing?
Hello! We are unable to log into any computer that is bound to Active Directory with the mobile account that is created. We've noticed that:- On Jamf, impacted computers will stop checking in.- Computers will flap on the network, that is, they will intermittently lose connection and gain connection.- When we log into a local administrator account, use sudo jamf policy and other commands and log out, the mobile account will be accessible for only a temporary period of time.- AD connection is valid, and all iMacs are in the proper OU. There are no duplicate entries.- All computers are on Sonoma.- We use Crowdstrike, and no alerts have been triggered. Any ideas as to why this may be happening?
Hello! Trying to polish up our Jamf Connect configuration, but I notice upon reboot the Jamf Connect screen doesn't pop up, I have Filevault disabled, and I made it so the authchanger script runs every time the computer logs in. This is the plist file:<?xml version="1.0" encoding="UTF-8"?><!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"><plist version="1.0"><dict><key>CreateJamfConnectPassword</key><true/><key>CreateNewUserHide</key><true/><key>DemobilizeUsers</key><true/><key>DenyLocal</key><true/><key>DenyLocalExcluded</key><array><string>orgadministrator</string></array><key>EnableFDE</key><false/><key>EnableFDERecoveryKey</key><false/><key>LocalFallback</key><false/><key>LoginWindowMessage</key><string>Welcome to xyz! Please log
Hello,Does anyone know a way to pass through the password from a presage enrollment SSO login to the Exchange ActiveSync settings so the user doesn't need to "Edit Settings"?This would be great, especially with the rollout of iPad OS 18 and them hiding Mail another layer deep in settings. Thanks!
Hi all, I'm a JAMF newbie (and to any kind of Mac administration). I recently completed an engagement with JAMF to assist in setting up JAMF Pro, but JAMF connect was out of scope for the statement of work. The professional services engineer did a great job of explaining what next steps I should need to take to get JAMF connect setup. To get to the point: I created a configuration policy for both JAMF connect and JAMF connect login, targeted to our test Mac - then deployed the JAMF connect app to the Mac but it does not seem to be taking the settings needed to work. The JAMF connect app is also not auto-launching when the system restarts. To get into more detail: I used the JAMF connect configurator to finish setting up the Entra login details. Everything tested successfully. Per the engineer's suggestion, rather than saving the mobile config file, he suggested it's better to save the XML data from the configurator, ten create a configuration policy per each XML. I
I am receiving the "Unhandled exception" error when I attempt to install Apple Classroom on ANY MacBook. This is via VPP. I cannot find anywhere that someone else has had this error for apps. I have already shuffled around licenses to VPP accounts to see if it was a licensing issue.Has anyone else experienced this in their environment and how did you resolve it?
We've been pushing certain iOS apps to our Macs such as Google Authenticator and VCastSender with Jamf. After updating my M1 Mac to macOS 15, I've been unable to open them. I've been getting the "The application xxx.app can't be opened" pop-ups instead. On macOS 14, on occasion you would get these same errors but it was usually rectified by deleting and reinstalling the app through Self Service. This method does not work in Sequoia.
So in a lab setting where students share computers is there a way to automatically allow Wacom tablets in 2023?Not sure why this is so difficult. Is allowing it and getting the user to approve the only way? Really annoying that when the user signs in the Wacom utility pops up and wants interaction. We are new to JAMF and this is one of the main reasons we got it so that we don't have to manually install it on hundreds of Macs.Any insight is appreciated. Did a search here but those threads are not much help.
Please create a Self Service app/web clip that allows user to update inventory from their device.
Hello,When our students graduate we offer the option for them to keep the devices. We wipe and delete them from JAMF when they sign them out during the final days of school. Once we do this if they restore from an iCloud Backup, all of our configuration profiles are added back via the backup without the iPad enrolling back into our MDM server. One profile we have is to deny the ability to factory reset the iPad via Settings. This means the graduated students are unable to reset their device that has pulled its old management controls. The only way to wipe them is to put them in DFU mode and use Apple Configurator 2.Is there a better way to release these devices through smart groups or anyone else noticing this.Thanks!
Hey All!Just a small question, and more like IM wondering if anyone has been able to do this.In our computer lab, we one of the machines connected to two monitors; the monitors are one standard monitor and one projector. Sometimes when we log into the machine as admin and set it so that the left monitor (standard) is the primary one and the projector is the extended, the projector will sometimes take over.In short this then requires either to login while looking at the projector screen, but if it's off, we just yoink the cable out and plug it back in. Honestly, the solution to just unplug the cable is fine, but our lab tech/admin is inquiring if there's a way we can make it easier on folks and keep that monitor as the primary. Is this something that can be set via script or config profile?
We have some users who have long since received a new Mac but for what ever reason they won't return the old Mac. I see in Jamf Pro that they are still using these old Macs and the new ones. We could send a remote lock command to the old Macs but I think that would complicate matters with our remote users. Instead, I want to use Swift Dialog to launch a full screen alert to the users that they need to return the old Mac. The only option that will be provided will be to shut the Mac down. I will include a 60 second timer. When it runs out, the Mac will shut down. I want to use a launch daemon to launch a script that I will install locally on these old Macs. I'm having trouble getting the script to launch using the launch daemon. The script does launch immediately after the launch daemon gets installed and loaded, but it does not launch when the computer is restarted/shut down and then started up again. I see in the error log an entry that says "id: : no such user". It appears that the s
In our Mac fleet are Clients who have Microsft Teams 1.x and 2.x installed. It turned out that "Microsoft Teams (work or school)" in Version 24231.x changed its Name back to "Microsott Teams". Does this mean that it will remove a installed "Microsoft Teams" in Version 1.x ? How does this effect Jamfs Patch Management for Microsoft Teams?
When I create document in Microsoft word document in mac and try to save it, it gives me options to save data to local storage, OneDrive and additionally it shows 'Manage Storage accounts'Manage Storage accounts >> shows OneDrive, Dropbox, Box, Egnyte, ShareFile, iManage online storage account options.Can we disable all these options via PPPC file/script/Config policy? anybody faced this issue?
We're currently working on bringing macOS users that are on version 13 to macOS 14. We want to restrict users from upgrading on their own to macOS 15 until it is fully vetted out. The question here is, if we were to enable this would it also impact our users that are trying to get to version 14 from lower versions?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!