Get Support
Recently active
“Tanoe," the script that blocks macOS updates, is primarily intended for Macs not officially supported by Apple (often used with OpenCore Legacy Patcher/OCLP), as well as macOS virtual machines.It also allows users to bypass the 90-day update window authorized by Apple via a configuration profile.I sent it to many contacts, and several were shocked to discover it was a terminal script.So, I created a Swift application with a graphical user interface (GUI), named "TanoeGUI," to simplify its use, especially for those unfamiliar with the command line. https://github.com/DrDonk/Tanoehttps://github.com/chrisbasse/TanoeGUI
Edited 4SEPT2024: Updated information with the release of Jamf Pro 11.9 for PSSO and Device Compliance. Also added link to Jamf Pro documentation. Jamf Learning Hub Instructions: https://learn.jamf.com/en-US/bundle/technical-articles/page/Platform_SSO_for_Microsoft_Entra_ID.html Current Public Preview Limitations What is Public Preview As of 15 JUL 2024, Microsoft Entra ID support for Platform Single Sign-On extension (PSSOe) is currently in Public Preview. As such, supported features and deployment information is subject to change without notice. For more information, visit https://learn.microsoft.com/en-us/entra/fundamentals/licensing-preview-info. Jamf Pro and Microsoft Entra Conditional Access Jamf Pro 11.9 and greater now includes logic to detects changes to PSSO registration. When a new device ID is created in Entra ID as part of the registration, the gatherAADInfo command will report device compliance state to the new object. For
We are building a Python application using the JAMF Pro REST API (OAuth2 client credentials) to send MDM restart commands to iPads. We are calling POST /api/v2/mdm/commands with a Bearer token and the following body: {"clientData": [{"managementId": "<device-management-uuid>"}], "commandData": {"commandType": "RESTART_DEVICE"}}. The API client has the following privileges assigned: Read Mobile Devices, Update Mobile Devices, Send Mobile Device Restart Device Command, Send MDM command information in Jamf Pro API, Send Blank Pushes to Mobile Devices, Update Mobile Device Inventory Collection, Update Sites, and Update Change Management. Despite all of these permissions being assigned, we are consistently receiving a 403 INVALID_PRIVILEGE: Forbidden response. The managementIdUUID is retrieved from the device detail endpoint /api/v2/mobile-devices/{id}/detail and confirmed correct. We have tried two separate API clients, both returning the same 403. Reading devices works perfectly wit
Hi all, we use Automated Device Enrollment with Apple Business Manager.Suddenly, device registration in Jamf stalls. After user login and MFA confirmation (Entra ID), a small notification window appears asking, “Do you want to allow downloads on ‘login.microsoftonline.com’?”No matter what we select here, the process then stalls at “Retrieving enrollment profile.”We have already checked ABM, Intune/Entra ID, and Jamf settings (token), and all syncs are running.Does anyone else have any idea what the cause might be here?
Hi,with MacOS 26 Tahoe Apple introduced the new Simplified Setup for Platform Single Sign-On. Both Jamf Pro and Jamf School support this new feature in theory, but I was not able to get it working with Jamf School using Microsoft Entra.Jamf School support says that it should just simply work, but both Jamf and Microsoft say that it is not yet supported (see Jamf and Microsoft).Has anybody been successful?
Hello Jamf Nation!We’ve released Jamf Pro 11.29.0 beta. This release includes Simplified Setup for Platform Single Sign-on (SSO) enhancements, new directory service group criteria for smart groups and more! For full details, check out the release notes after enrollment.How to join the beta: Enroll in the Beta Program under Product Feedback at account.jamf.com. Click “Join Community” to join the beta forum once enrolled. If you encounter an error on Jamf Nation joining the beta forum, please log into Jamf Nation and then click “Join Community” again. Please also check out this recent blog on Configuring SSO in Jamf Account prior to testing Compliance Benchmarks, Blueprints, and App Switcher. Email beta@jamf.com with questions.The beta program is covered by the Jamf non-disclosure agreement; please do not share any information regarding your testing on any public forum, including the non-beta areas of Jamf Nation. Use the Jamf Nation Beta Forum or contact Jamf via beta@jamf.com with any
I am currently getting to know more about the new Blueprint feature in Jamf Pro. Currently I can see that a blueprint has been deployed to 60 devices, 19 devices are pending and 1 device currently has got an error. How can I check which devices have already received the Blueprints components and which devices still need them?Thanks in advance!
On Saturday, June 6, 2026, Jamf Cloud Infrastructure will be patched. During this time, you will be logged out of your Jamf Pro instance. The purpose of patching is to ensure that Jamf Cloud infrastructure and the database service are up-to-date, stable, and safe from security threats. Please see the times for our regions below. Hosted Data Region Date Start Time End Time us-gov-west-1 June 6, 2026 0800 AM CT 1200 PM CT
Hello,We have two sites using Shared iPads. For no apparent reason, all the iPads switched to English and the saved documents disappeared. The students then changed the language settings, and the documents reappeared.Have you ever received feedback about this type of behavior?Kind regards,
Hello all,I wanted to ask for your thoughts on how Jamf Connect stores the Google Web Application credentials on end-user devices. I’ve always been of the mindset that credentials are secrets and should be stored safely. When I go onto any end-user device, I see that any user can view the plain-text credentials by opening the config profile. The credentials in question are the OIDCClientSecret and OIDCClientID. This was the result of just following the Jamf Connect Deployment Guide, and support tells me that this is normal behaviour, but I wanted to ask what others think. I’d appreciate any feedback or guidance you could offer. Thanks,
Hey Jamf Nation 👋🏼,Big news: we just dropped a new reward in Jamf Nation Rewards!Redeem your bytes for a complimentary full-access ticket to Jamf Nation User Conference 2026, the premier event for Apple and Jamf admins to connect, learn and level up. Only 5 tickets are available on a first come, first served basis.Here's what you need to know:📅 When: September 23–25, 2026📍 Where: Kansas City Convention Center, Kansas City, MO🎟️ What's included: One (1) full-access JNUC conference ticketHead to Jamf Nation Rewards, find the JNUC 2026 ticket reward and redeem your bytes before someone else snags your spot. Once you've redeemed, a member of our Community Team will be in touch with next steps.A few important notes before you redeem:This reward is non-transferrable and may only be used by the redeemer. Bytes are non-refundable once redeemed. Travel, accommodation, meals and other expenses are not included - this covers your conference ticket only. Please verify with your organization t
In April, I had the opportunity to attend MacAD.UK in Brighton for the first time. It was the conference’s ninth year and the tenth anniversary of the very first gathering, which made it feel like a special moment to be part of. Even more importantly, it was my first professional conference presentation, made possible by the Charles S. Edge New Speaker Grant from the Mac Admins Foundation. The MacAD.UK team also played an important part in making it possible for me to speak at the conference, and I’m incredibly grateful for that support. I had applied earlier in the year and, to be honest, almost forgot that I had done it. So, when I received the email from Chris Dawe saying I had been selected, I could hardly believe it. The excitement was quickly followed by nerves, because I knew I would soon be meeting with Chris and Diego Laconelli and later with @rebecca_latimer. Speaking English does not always come naturally to me, so I spent a lot of time getting ready for those conversations
We migrated from on-premise Jamf Pro to Jamf Cloud, and recently some users cannot see the apps deployed from Mac Apps, while others can. We are using a single Smart Group, but we are puzzled as to why it does not appear on other machines, even on Zero Touch built devices.Do you have any idea why this is happening? And can you advise me on where I can troubleshoot this? Thank you so much.
At my current environment, we have an admin account and LAPS turned on. As we know, LAPS doesn’t work for unlocking FileVault. We need an admin account to unlock file vault and log into so we can troubleshoot issues. I love the idea of LAPS but it doesn’t seem to be practical in our environment. Is the best thing to do is have a local admin account with a very complicated password. Also, we have it setup to only allow one ad account to log into the computer so using an ad account isn’t going to work either.
I have a script that I wish to use to remove old user accounts on Macs that have no activity after a specific date. I have ran this script manually on various Macs that we have with no issues, however when I try running it via Jamf, it gets stuck on "Installed" for the status and never executes. Even when I run a simple "echo "test"" script, this results in the same issue, so it seems that I am unable to run any scripts at all. If I go to "Result of script execution" it says "Could not load any current execution, we will try again soon...". This has been going on for maybe several months now, if anyone has any ideas on how to resolve this, it would be much appreciated.
2026 Jamf Nation Live (JNL) Commercial Roadshows are right around the corner, and we’re bringing a series of free, half‑day events to cities across the U.S. These sessions are designed for Apple admins, IT leaders, and anyone looking to learn, connect, and get hands‑on with Jamf. Each JNL event includes: Practical, real‑world workflows Live demos and technical deep dives Direct access to Jamf experts Opportunities to connect with peers in your region Upcoming 2026 JNL Dates: New York City – April 14 Atlanta – April 16 Seattle – April 21 San Jose – April 23 Chicago/Naperville – April 28 Minneapolis – May 6 REGISTER HERE If you have any questions about the events or registration, reach out anytime to jnlhelp@jamf.com.We hope to see you at one to see you at one of the stops!
Hello everyone!On every mac using JC3 / SS+, the “Local Account Password Expires” counter never shows a correct days number, no matter what I try.-Kerberos is valid.-Signed out and back into SS+.-Changing the PW using the integrated workflow WILL change the password, but the counter never changes. The new PW will be accepted with SS+ and JC.-New-to-that-computer users who login will show a seemingly “random” date that does not match the idP Thanks for any help y’all have!PS: Sorry if this is a common fix, I searched all sorts of threads but didn’t find anything that helped.
Just a heads up of this issue for my fellow macadmins. This will be fixed in a future Teams update but in the meantime the there’s a fix in the article. We’ve confirmed it works.Article here:https://www.bleepingcomputer.com/news/microsoft/microsoft-blames-undismissible-teams-location-prompts-on-macos-update/amp/
Finished Jamf 100 and 200 courses. Should I continue on to 300 and 400? Is it that much more valuable for a school environment? Thanks.
Hi all,I've been dealing with a persistent performance issue with Jamf Trust and I'm curious whether others are in the same boat.We have around 50 Mac users in Milan using Jamf Trust (WireGuard, split tunnel) to access an internal Synology NAS via SFTP. Remote transfers consistently top out at 8–12 MB/s, which feels low given that the same setup without the tunnel reaches 20+ MB/s on the same connections and hardware.I've spent quite a bit of time investigating — the firewall, the NAS, the cipher negotiation, the tunnel overhead — and nothing on our side explains the gap. The infrastructure handles the load fine, and removing the tunnel immediately doubles the transfer speed.Support has not been helpful and hasn't been able to pinpoint a fix so far. I've also tested Network Relay, which unfortunately performed worse than WireGuard in our case.Is 10–12 MB/s a common ceiling others are seeing with Jamf Trust, or should we realistically expect more? Has anyone found a way to improve throu
The Dinner Table Tech DeskLet’s be honest, we’ve all been there - so let me paint the picture. It’s the holidays, everyone is gathered around the table, you’ve managed to dodge most of the argument inducing conversations and you’re about to take that first mouthwatering bite out of <insert your favorite festive food here>. Suddenly someone pulls out their iPhone and says one of these (or many other) nightmare inducing phrases; ”Hey can I ask you a question about iCloud real quick?” or “Hey, how many Apple IDs should I have?” These questions are par for the course when you are the designated tech person both at work and at home. I’m having a little fun here and I know that we all do our best to help out that relative to the best of our ability and get them not only back up and running ASAP but hopefully also feeling good about their tech. It’s likely the reason we keep getting asked for help, because we are good at it (and be honest, you enjoy it at least a little)! This article i
Hey,I am looking for way to disable the newDisable Google Chromes KI-Modell Gemini Nanohttps://www.heise.de/en/news/Commotion-about-unsolicited-AI-file-downloads-in-Chrome-11285401.htmlDoes anyone have an Json ready that can manage this setting?Is there any other way, to disable this unwanted “feature” ?Thanks in advance.
Hey,I am looking for a way to pre configure the server address for the Nextcloud Client.Even in Version 33.0.4 does a Configuration Profile not work.This is the JSON that I use, but it does not work for domainscom.nextcloud.desktopclientorcom.nextcloud.desktopclient.mac <?xml version="1.0" encoding="UTF-8"?><!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"><plist version="1.0"> <dict> <key>serverurl</key> <string>https://your.domain</string> <key>username</key> <string>$USERNAME</string> </dict></plist>Has anyone found out, how to get this to work?Thanks in advance.
Today we are releasing Jamf Pro 11.28; highlights include:Mutual TLS Authentication for WebhooksJamf Pro webhooks now support mutual TLS (mTLS) as an authentication type. With mTLS, both parties authenticate each other during the TLS handshake: Jamf Pro presents a client certificate to the webhook endpoint, and Jamf Pro validates the server certificate presented by the endpoint. This ensures that webhook traffic is both sent by a verified Jamf Pro instance and received only by a trusted destination, enabling secure workflows that require strong authentication at the transport layer, such as certain SCEP configurations. Title Editor Authentication ChangeJamf Pro now uses Machine-to-Machine (M2M) authentication to communicate with Title Editor instead of the Cloud Services connection. M2M authentication is available only for Jamf Pro cloud-hosted instances. Note: Upgrades to Jamf Pro 11.28 may take 2 hours longer than usual. For additional information on what's included in this release,
Hey all. Rather than having to install and update Jamf Connect manually through policies after the black screen scare on Sonoma, i've been trying to have it deploy and update automatically through Mac Apps. However i find it is stuck on 'in progress' and never gets past that stage. Has anyone experienced this? It seems scoped to the correct group, i have attached my configuration settings in case anything seems odd there. Many thanks.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!