Get Support
Recently active
Hi all,I’m looking for guidance on how to fully automate macOS updates across our company-managed Mac devices.We currently manage our Mac fleet using Jamf Pro version 11.24.1-t1769438062288. At present, macOS updates are being deployed manually through Self Service using packaged installers, but we would like to move to a more reliable and scalable automated process.So far, I have tried the following methods, but I have not been successful with either approach:Mass Action Command Managed Software UpdatesFor context, all company devices are:Enrolled via PreStage Enrollment Supervised Configured with Bootstrap Token allowed and escrowedIf anyone has successfully implemented a fully automated macOS update workflow in a similar Jamf environment, I would greatly appreciate your advice on the recommended process, prerequisites, or any known limitations.
Inherited a Jamf Pro deployment and looking to upgrade a piece of software that is being pushed out. This is what the policy looks like:GeneralEnabledTrigger: Recurring Check-InExecution Frequency: One per computerPackagePKG file, action InstallMaintenanceUpdate Inventory If I want to upgrade this with a new package, do I need a new policy with the same scope and disable this one? Or can I put a new PKG file in there?Thanks for any nudges in the right direction!
AI is changing how we work and it’s a huge area we’re all focused onOne of our engineers recently shared in an AMA some prompts customers are using with Ask Jamf right now:Help me identify OS versions in my fleet, highlight devices that can't be updated and need to be replaced. Can you explain how this policy and its script work? Survey our policies, profiles and groups and help write documentation. How do webhooks work in Jamf Pro? How do I get started with them? Do I have any configuration profiles that will conflict with this Blueprint?Now it's your turn, what prompts are actually working for you?Drop your best Ask Jamf prompts in the comments. I'll collect them and turn this into a community resource we can all learn from.Go 🚀 !
I am interested in how we can automate some reports or feed data into a SIEM like Splunk of Jamf Connect activity. The most important data point is when a user uses the privilege elevation feature. Does anyone have any experience or advise on this? Thanks in advance, -Pat
Shifting compliance checks left—giving control directly to end users via Self ServiceAs part of improving endpoint security and reducing operational overhead, I built a macOS compliance dashboard using SwiftDialog and Jamf, available to users via Self Service.This solution focuses on managing third-party vendor applications that are not updated through Jamf VPP/App Catalog or Installomator. These apps are maintained using internal PKG deployments, with the script enforcing organization-defined required versions.From an admin perspective, the key objective is to eliminate dependency on service desk tickets for compliance. Users can proactively check their device status and remediate issues themselves, without needing to raise a ticket.The script performs real-time validation of critical security controls such as FileVault, Firewall, SIP, and MDM enrollment, along with verifying that required security applications are installed and up to date.If any application is missing or outdated, re
Apologies if this is covered elsewhere and I’ve missed it!I’ve noticed that with the latest version (15.1.1) of Keynote, Numbers and Pages, the new version installs, and the old version remains. Using my Mac as an example, I currently have Numbers 15.1.1 and 14.6.2 installed. Trying to sort out a way to remove old versions from our Macs using Jamf Pro? I’ve tried a few scripts that claim to work even on Apple apps, but haven’t had any luck.
HiWe use Mac and Windows with Outlook in our schoolIn the group policy I can configure default fonts for Windows How can I configure Default Fonts for Mac for all the users in the organization Kind regards,
Am working on a project to migrate to Blueprints in Jamf Pro as much as I can and something I’m finding exceptionally frustrating is how to plan for future management of Apple Intelligence. We disable it by default for a host of privacy/protection reasons, but everywhere I look I see that the current tools will be deprecated (or were with 26.4) and there’s zero guidance on how to manage this going forward.Currently resorting to some Custom Settings payloads but am under the impression this will soon also not work after 27.0’s release. Couldn’t find anything searching the boards, but would love if I could get clarification from the community on if I’m correct or not in my concern or where to look for future-proofing.
Hey Jamf Heroes! I need some of that superhero good will.Going wide on my PSSO Pilot today. Testing went very smoothly, but we all know that sometimes the difference between dev and prod can be expansive.(Yes, I copied and pasted this from Slack. ;-)
I’m looking for a good printer for home use and would like some advice. I mainly need it for printing documents, school work, and occasional color pages. My old printer has been slow and expensive to maintain, so I’m thinking of upgrading.What printer would you recommend for reliable and cost-effective home use?
We set our users to be Standard users on their Macs, and which prevents them from being able to delete Wi-Fi SSIDs. Sometimes, we've needed to allow them to do so, so we have a script in Self Service that will delete a known SSID when run.#!/bin/sh ## Get the wireless port ID WirelessPort=$(networksetup -listallhardwareports | awk '/Wi-Fi|AirPort/{getline; print $NF}') ## Run a SSID removal if its present networksetup -removepreferredwirelessnetwork $WirelessPort "NAMEOFTHESSID" 2>/dev/nullBut we've run into a situation where a work-from-home user wants to delete an SSID from their home network, etc. I was wondering if there's a way to a have a script that would allow the user to choose from existing "preferred wireless networks" SSIDs and choose which one to delete? That way, we could just have one "Remove Wi-Fi Networks" item in Self Service, and users could remove whichever one they want.
So as we approach the inevitable coming of Self Service + we have noticed something that would be great to remove if possible to bypass some potential issues.In the Mac menu bar the Self Service + icon does not go away no matter what at the moment, and it also has a “Get software” option in the menu that does not apply to us. So I have the following questions:1: Is there a way to automatically hide or disable the icon from showing up?or2: Is there a way to customize what menu options the icon has so that it is more applicable to different use cases where optional software deployed through self service is not a thing?
We would like to restrict our admin user from installing any applications via installer files (pkg or dmg) on their Mac. There is a functionality in the configuration profile under Restrictions that allows us to check "Restrict the App Store," but this only prevents users from opening the App Store. They can still download package files from the web and install them. Is there any way to restrict admin users through a script or configuration profile?
Today we released Jamf Connect 3.8.0; this release addresses the following product issues:[PI-995] Fixed: The Jamf Connect login window presents the following error after a failed ROPG password verification: ERROR: Unknown error. Message: The credentials provided were invalid., STATUS: 400. [PI155825] Fixed: Jamf Connect configurations with Okta Identity Engine as the identity provider fail to use the preferred_username attribute during user creation, causing the user to have the incorrect login information assigned to them. To access new versions of Jamf Connect, log in to Jamf Account with your Jamf ID. The latest version is located in the Solutions section under Jamf Connect.Product DocumentationFor additional information on what's included in this release, review the release notes via the Jamf Learning Hub.
Using Escrow Buddy. Its rotating keys as expected, but the keys are not working to unlock the disk. I have run sudo fdesetup validaterecovery and it returns with false. I re-run the Escrow Buddy policy and get a new PRK, still says the new PRK is false. Anyone experience this? It seems like no matter what, even though Jamf is saying the PRK is Valid, its not escrowing properly.
We launched Phase 1 of our new Jamf Learning Hub today. In addition to a cleaner layout and crisper learning experience, we now have a better performing and more extensible platform that gives us the foundation to deliver the new features you have been asking for.A few things to know as you explore the new Jamf Learning Hub:📌 BookmarksIf you had pages bookmarked using the Jamf Learning Hub bookmark functionality, you'll need to re-save them: Sign in to the Jamf Learning Hub. Go to the page you want to bookmark. Click the button shown below. Change the name for the bookmark if you like. Click the Save button. If you had bookmarked pages using your web browser bookmark functionality, you will not need to re-save those as we have redirects in place.📄 Creating PDFsThe PDF process has a new flow: Click the button shown below. Select Print this topic. Choose the topics you want to include from the publication and click Print. Set your Destination to PDF and click Save
Hello all, Today and last week Friday, we’ve been seen users get the Jamf Connect Keychain pop up. Computer will show JC 3.5 is installed and it’s getting the latest Self Service + and the popup reoccurs on restart. I’ve opened a ticket but wanted to reach out here and see if something clear and apparent is happening.
Hello All,We’ve just started to implement Jamf Pro in our company. Nearly all configurations are completed except sending compliant information to Microsoft Intune. We have to do this because we’re using Azure (Entra) Conditional Access rules in our company. If a macOS device is not compliant it cannot reach internal company resources. Just a simple rule. Steps CompletedJamf <> Intune compliance partner connector connected successfully. Microsoft Device Compliance configuration policy prepared in Jamf Policies -https://learn.microsoft.com/en-us/intune/intune-service/protect/jamf-managed-device-compliance-with-entra-idProblem SummaryAfter enrolling to jamf, we are trying to sign in to Company portal and jamf compliance popup appears. Then we are entering our user account details again but somehow Microsoft login page shows that “get app”. It behaves like Company Portal is not installed. Briefly some of our computers are being Compliant without any problem, but some of others canno
Hi everyone,I'm working on upgrading our Mac fleet from Jamf Connect 2.39 to 3.7.1 and running into some cleanup issues I'd love some guidance on.Environment:Jamf Pro 11.26.1 macOS 15 Sequoia Apple Silicon and Intel endpoints Devices enrolled via Apple Business Manager (ABM) using Automated Device Enrollment (ADE) Identity Provider: Azure AD / Entra IDCurrent situation: All of our managed Macs have Jamf Connect 2.39 installed. I have already built and validated a Jamf Connect 3.7.1 configuration profile in Jamf Pro and scoped it to a handful of test machines successfully.The problem: When pushing JamfConnectLogin.pkg (3.7.1) via policy, it does not remove or replace the existing 2.39 installation. After the policy runs I can confirm:Jamf Connect.app (2.39) remains in /Applications The 2.39 menu bar app is still present and running JamfConnectLogin.bundle does get updated to 3.7.1 via the pkgI also want to note that sudo is restricted on our endpoints via BeyondTrust Privilege Managemen
Hello,I have multi-user workstations on which I do not have FileVault activated so as not to have a problem when connecting a new user with Jamf Connect. Unfortunately, the TAHOE update automatically activates FileVault and suddenly at the start of the station an account is requested that can activate FileVault before having the Jamf Connect window. How can we get around the problem or how can TAHOE not activate FileVault?
As a Jamf trainer, there are two questions I’m asked time and time again:How much scripting is involved in the Jamf certification courses? How can I prepare before attending a remote instructor-led course?If you’re planning to take a Jamf certification course and want a clearer idea of what to expect, and how to set yourself up for success, this guide is for you.The Jamf Pro Training PathThere are three core Jamf Pro instructor-led courses, each designed to build on the previous one as your skills develop:Jamf 200 – Core understanding of Jamf Pro, as well as an enterprise-focused examination of the macOS and iOS platforms Jamf 300 – Deeper understanding of the macOS and iOS management capabilities within Jamf Pro Jamf 400 – Automation and APIsLet’s take a look at what scripting knowledge is expected at each level, and how you can prepare. Jamf 200The Jamf 200 course provides a solid introduction to Jamf Pro, along with an enterprise-focused overview of macOS and iOS device management.
I have had success with scripts to insert the auth code for SPSS in past but SPSS 30 will not apply code through script. Popup still comes up. Script that used to work was this one. I have tried few option using the SPSS instruction manual but no success. What's working for you all?
Reading over the Jamf documentation it’s not clear how to schedule MySQL backups using the Jamf pro server tool cli on windows when the DB is on its own server. I have Jamf server tools copied over to the DB server and I see you can set a schedule in the config file but that will not actually do anything since jamf-pro is not running on this server. It says you can use Schtasks to schedule this but what command do you put in the schedule task? jamf-pro database backup ?If i do it this way should I have no schedule task in the config? Also what account does this need to run as?
Like many of you, part of my job involves erasing and reimaging test machines over and over. This morning I attempted to do something I've done hundreds of times before - erase the drive on my M4 Tahoe test machine and reinstall Sequoia. This time, Sequoia is not available, only Tahoe.It's possible Apple may have restricted the Sequoia installer from Tahoe machines, much like they did with the iOS 18.x installers on iOS 26.x devices.I wanted to get word out there as a word of caution.
BLUF: ASM shows 314 devices assigned to our Jamf Pro (cloud) server, but Jamf Pro is stuck at a 255-device count, preventing macOS Tahoe's native migration lockout from triggering for 50+ migration targets.Hi everyone,I’m running into a sync issue between Apple School Manager (ASM) and a new Jamf Pro instance. For backstory, we are migrating from several independent Jamf Cloud installs to a centralized version. While many of the devices will need to be manually touched, I have more than 50 that can be migrated between Jamf instances. Those devices are on Tahoe, have a T2 chip on Intel hardware or are Apple Silicon, and are DEP enrolled with a valid MDM Profile (not expired) on the legacy Jamf instance. I successfully migrated a separate Jamf Cloud instance into our new, centralized Jamf instance using ASM just a week ago, so the process has proven valid.Currently, ASM shows 314 devices (all endpoint Macs save for 5 iPads) assigned to our MDM server via Device Management Services. Howev
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!