Get Support
Recently active
My Jamf Connect environment is interfaced with Entra ID. In our testing and pilot phases the deployment went well. However, now that I’m deploying to production we’ve had a sporadic issue where the Jamf Connect login window will claim that the network password doesn’t match the local password and also temporarily locks the account. The user might have to reboot and try again to get it. Anybody else deal with this?
Hi All,AD bound Mac’s with macOS Tahoe 26.4. When a new user login I got “Sign in to Your Apple Account” and “Age Range” message , any idea how do disable these?thanks
Today we are releasing a maintenance version of Jamf Pro; highlights include:AI Assistant in Jamf Pro General AvailabilityYou can use Jamf's AI-powered conversational assistant to support your organization's device management and security. AI Assistant consists of individual functionalities called "tools" that are organized in tool groups by product. When you enable AI Assistant, you enable AI Assistant Core, a foundational knowledge tool that can assist you with technical questions about Jamf's software and services. In addition, you can enable read-only tools for Jamf Pro. AI Assistant is disabled by default.To enable AI Assistant for Jamf Pro, log in to Jamf Account and navigate to Organization > AI Assistant.Note: This feature was made available on 31 March 2026 for Jamf Pro environments that support the AI Assistant, regardless of version. For more information, see AI Assistant in the Jamf Account Documentation.Enhancements to OIDC-Based Single Sign-On (SSO) with Jamf AccountYo
Hi,I work at a small creative arts UK University and our IT department has recently contracted a service provider to manage all our Mac devices via JAMF. I am being told that as a new security policy any new OS must be deployed via JAMF within 7 days and any Mac devices not updated will lose web browser functionality.As a Faculty that uses a wide range of audio, video and graphics software on our Macs - often simultaneously on the same device- we have never previously adopted the latest OS for at least a couple of months until any major bug/conflict fixes from Apple and software providers have been implemented. We have also refrained from updating Mac devices whilst in use for art installations in exhibition or live events in rehearsal/performance - so as to ensure continuity of service over a period of weeks.I am wondering how this is handled in other University or education institutions? Do other institutions reasonably manage security concerns through a policy of delaying the new OS
How is everyone handling cleaning up stale devices in Entra? I have the Jamf Compliance Connector setup to register macs with Entra. The compliance reporting is working fine, but the computers show in Entra as registered and last activity as the same date, no activity after registration completed. I normally have cleanup scripts running to disable computers with no activity in the last 90 days but my Jamf macs are not showing activity and I don’t want to disabled them if they still active. My mac used daily shows no activity for over 60 days (since it was registered) in Entra (Company Portal shows connected today):
Your Mac is Ready for FileVaultFileVault keeps your Mac safe by encrypting your data andprotecting it with the password you use to log in. If youforget your password, you can use your Recovery Key toreset it.
Hi Jamf Nation!We are excited to announce Beacon by Jamf Threat Labs.What is Beacon by Jamf Threat Labs? It is a Mac-only threat hunting service delivered by Jamf Threat Labs. It’s designed to help you detect, analyze and respond to threats impacting your macOS environment. Whether you’re building your Mac security program from the ground up or looking to elevate an existing one, Beacon delivers the expertise, visibility and operational support to make it happen.Beacon by Jamf Threat Labs is currently available to limited customers in Private Beta. If you want to learn more, read our blog here or contact your Jamf representative.
On Saturday, April 11, 2026, Jamf Cloud Infrastructure will be patched. During this time, you will be logged out of your Jamf Pro instance. The purpose of patching is to ensure that Jamf Cloud infrastructure and the database service are up-to-date, stable, and safe from security threats. Please see the times for our regions below. Hosted Data Region Date Start Time End Time us-gov-west-1 April 11, 2026 0800 AM CT 1200 PM CT
Hi,our macOS Sequoia clients get the macOS Tahoe Upgrade offered by Notifications since 25th of March.Despite a distributed Configuration Profile which includes the 90 days delay (and worked fine passing those 90 days), Clients get the Upgrade Notification.Did anyone experience the same issue?Is there another way to turn off those notifications?Thanks!
Teachers have been using Apple Classroom to lock iPads if students are misbehaving on them. However, the students have found that if they restart their iPad, the lock clears and they can access it again. Wondering if anyone knows of any other ways for teachers to be able to lock their student’s iPads that doesn’t just clear if a student restarts it. After some testing, I found that if I put it in Lost Mode, that works, but the problem with that is the teachers would need to tell me to do it. I also considered putting a passcode on the device, but the teacher would need to unlock the device for these students each time they use it, and if a student gets locked out, I could see them trying to guess the password too many times and getting locked out for a long period of time. I am looking for tools other than Apple Classroom that teachers could have access to, or any other ideas for how to lock a student out of an iPad and keep them locked until the teacher clears the lock.
why do some Dock items path have /localhost and some other don’tfile://localhost/Applications/*****.appfile:///Applications/GarageBand.app/the main ones i see that have /localhost are applications that don’t come preinstalled on a mac.
Not sure if this is possible; having trouble thinking out the logic. We have systems that are setup with macOS Tahoe, but we also have systems that are being upgraded from macOS 14 and 15 to Tahoe. I am wondering if it is possible to come up with a smart group to differentiate systems that came with vs upgraded to?One thought is to “mark” systems during setup with a flag file during enrollment and use an extension attribute. Maybe a plist that has an array of discovered operating system builds. This way it can be used in the future, not just for macOS Tahoe.Curious if anyone has a better way.
Our goal is to distribute (wifi)certs to about a couple of thousands of iPads, and we have Microsoft and NDES as our infrastructure. Seems to be impossible to find information about how to assign SCEP in JAMF School, especially how to configure Challenge. Does anybody here know how to use the SCEP section? Have done some trials and, all, errors...
Hello, I succeded to deploy SCEP with Jamf School for our iPhones and iPads device. They received certificates and they are able to connect to our WiFi. But the problem is they don’t renew their certificate when they’re about to expire. It seem JamfSchool SCEP don’t send a new request for renew certificate before expiration. Others MDM have an option to set renew before X days of expiration but JamfSchool don’t have that option. How to do it? I did’nt find any documentation.Thank yoU!
Hello Jamf Nation!We’ve released Jamf Pro 11.27.0 beta. This release includes A setup assistant for configuring OIDC-based single sign-on (SSO) with Jamf Account, Active User Display, and more! For full details, check out the release notes after enrollment.How to join the beta: Enroll in the Beta Program under Product Feedback at account.jamf.com. Click “Join Community” to join the beta forum once enrolled. If you encounter an error on Jamf Nation joining the beta forum, please log into Jamf Nation and then click “Join Community” again. Please also check out this recent blog on Configuring SSO in Jamf Account prior to testing Compliance Benchmarks, Blueprints, and App Switcher. Email beta@jamf.com with questions.The beta program is covered by the Jamf non-disclosure agreement; please do not share any information regarding your testing on any public forum, including the non-beta areas of Jamf Nation. Use the Jamf Nation Beta Forum or contact Jamf via beta@jamf.com with any questions. Th
Due to changes being made by our network team we’re required to deploy a new Trusted Root Certificate within our Wifi Configuration Profile. DigiCert are changing Root Certificates.What I’m encountering is even though I can successfully deploy the Certificate and Trust it within the Configuration Profile if I deploy more than one Root Certificate the Mac will not connect.I’m hoping that I can deploy the new certificate without impacting the existing wifi connection before Networks make the backend change.
To install Creative Cloud at my company, end users are directed to the Adobe Creative Cloud website (https://www.adobe.com/creativecloud/desktop-app.html). Every two weeks I get a report from our Security team listing device vulnerabilities. There's frequently a fair number of devices that need one or more Creative Cloud apps updated. I started emailing users individually, reminding them to update their Creative Cloud apps. Wondering if there's a better way, because emailing users and following up when they don't respond is too manual and too time-consuming. Curious how other admins approach this.
Is there a better way to update Users chrome app via JAMF? I’ve been using Mac Apps and it’s working for the purpose, however the issue is with the force quit. Sometimes while users are in an online meeting, chrome just force quit to update. I want to force update but not while they are using chrome.
I have been having this issue where some of our Mac computers are being force to change their password approximately every 90 days. First thing comes in mind is if we have a Jamf policy for password expiration. As per checking we don’t have any policy enforced for a password expiration. I’ve been researching if what may be the cause, most says that it’s due to an MDM.Anyone having this kind of issue? how did you resolved it. We don’t want to set an expiration date for our Mac passwords.
Subsequent to extensive logging, analysis, and corresponding packet captures I have correlated results from two managed endpoints under the following conditions:With Netskope active/tunnelingWith both Netskope/GlobalProtect active/tunnelingWithout eitherLog streams captures were correlated against corresponding pcaps; results are presented as pasted herein. Sanitized logs and reports available upon request. TIME ───────────────────────────────────────────────────────────▶STEP 1: DNS RESOLUTION (Resolver Layer)────────────────────────────────────────Client → DNS Query ← Response: hostname → IPs (TTL = 60) [TTL countdown begins immediately] Example: cityofphoenix.jamfcloud.com → 184.32.98.75, 54.218.86.150, 34.215.108.82 TTL = 60sSTEP 2: TTL DECAY (Cache Reality)────────────────────────────────────────Time passes (milliseconds → seconds)Observed TTLs:- 60 → 57 → 32 → 7 → 2(Netskope system shows fragmented snapshots: multiple partial TTL views si
Hoping someone can help me out.I have a script in JAMF that is very simple and runs the KLIST command only. #!/bin/bashklistexit 0When run on a machine with valid kerberos ticket I get a klist: Cache not found: error. Wehn I run this script in a terminal window with sudo I get valid results. Not sure ehy running it thru JAMF is returning an error. Thank you in advance.
Mac Admins Europe is a new conference built by and for the European Apple Admin community, bringing together admins from education, enterprise, and beyond to share knowledge, swap war stories, and find their people closer to home. Organizers @mischavdbent , @rob_potvin, @Armin and me reflect on what's driving the growth of the community, why now felt like the right moment and what success looks like.When you look at the European Mac admin community today versus a few years ago, how has it changed, and what made you feel the time was right for a dedicated European event?A few years ago, the European Mac admin community felt more fragmented. There were great people doing great work, but a lot of it happened in smaller pockets — local meetups, Slack channels, or at events outside Europe.What’s changed is confidence and scale. macOS and Apple platforms are now firmly embedded in education and enterprise across Europe. That’s created more Mac admins, more diverse roles, and more shared c
Hey folks! I know it’s a stupid question but.. quick sanity check before I flip a switch in Jamf ProI'm working on a custom enrollment flow using Okta SSO, which requires enabling the “Use SAML authentication for end users” option.Right now, admins are logging into Jamf via Jamf Account and everything works fine there.Just want to confirm that turning this on won't impact admin access, correct? Admins should still be able to log in the same way as before?Anything I should be careful about before enabling it?Thanks in advance!
I have some MacBooks that are pre-stage enrolled that have stopped checking in and stopped inventorying. I have others that are User initiated enrolled that stopped checking in but I just had them remove the profiles and redo the enrollment and they are working again. These are all remote users so I cannot be hands on. I had a few of the pre-stage enrolled devices attempt to run sudo jamf recon and sudo jamf policy from terminal but they are receiving "Device Signature Error - A valid device signature is required to perform the action" Other postings I've seen that are quite a bit older mention unenrolling devices and reenrolling them. Not really an option if they are pre-stage enrolled from what I understand. Does anyone know what I can do get these devices reporting properly?
With Jamf Pro 11.26, session options configured in Jamf Account are enforced, computers with macOS 26 or later are automatically registered with the Jamf device compliance integration with Microsoft Entra ID during enrollment, and administrators can programmatically manage Jamf Pro user accounts with the Jamf Pro API! Be sure to check out the Jamf Pro release notes for all of the exciting new features and enhancements.Thank you for your continued support and feedback!
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!