Get Support
Recently active
Hello For those running MacOS 26 how are you deploying background security improvements?Blueprints doesnt seem to understand the format. https://support.apple.com/en-gb/111333I could find anything in Jamf blueprint documentation either. thanks
Hi Team,I’m evaluating a potential integration between Jamf Pro and a third-party Threat Intelligence Platform (TIP), and wanted to validate feasibility from a technical/partner perspective.The TIP APIs provide: Stream of malicious IOCs (IP, domain, file hash, URL) (Usually need to run on schedule) On-demand IOC reputation lookup (malicious/suspicious/benign) File and URL scanning capabilities Planned approach: Integration will rely only on Jamf Pro APIs (no agent/kernel-level extensions) Key questions: Can Jamf Pro workflows leverage external IOC data to trigger actions on managed devices? Using Jamf APIs, is it feasible to: Enforce blocking of malicious domains/URLs via configuration profiles or policies? Act on files (e.g., remediation based on file hash via scripts)? Trigger automated responses (policies, scripts, device lock/wipe) based on external intelligence? Are there any recommended patterns or limitations when integrating external threat intelligence fe
I am using Jamf Pro with Google IdP, Enrollment Customization, PreStage Enrollment, and Single Sign-On. However, no matter what I try, when I enroll a device the fields populate as:Full name: Firstname LastnameUsername: firstname.lastname@emailaddressWhat I want instead is for the username to be first.last.I created a custom SAML attribute that maps to firstname.lastname, but I have not been able to get it to work. I’m not sure what else to try.Is it possible to have the home directory set to first.last instead of using the full email address?When I use $FULLNAME and $REALNAME in Enrollment Customization and PreStage Enrollment, the auto-populated information during device enrollment becomes:Full Name: Firstname LastnameAccount name (home directory): Firstname Lastname Not using Jamf Connect
Hello all you Apple Rockstars!I just noticed that there’s a whole reward system you can redeem points (“bytes”) for stuff. Very cool. Ivanti used to have something like this called Insiders, but the reward system was abruptly discontinued while I had lots of unspent points.I’m not sure I fully understand what actions get points, but it looks like you get 5 points for the first posting/replying each day, and then a single point for each subsequent post/reply.Doing some quick math: If you want to get to 500 points, that would take you 100 days. Assuming you only did 1 post/reply a day, on normal workdays, thats 20 weeks.Does that seem like an unreasonable amount of effort to get a tech mat or whatever?I know they are doing this to stimulate customer engagement, but I think they would need to get more generous with the points for people to participate more.What do you think?Anyone had experience with redeeming points? I’m not sure how long this has been a thing.
Today we are releasing a maintenance version of Jamf Connect which includes minor bug fixes and improvements. To access new versions of Jamf Connect, log in to Jamf Account with your Jamf ID. The latest version is located in the Solutions section under Jamf Connect.Product DocumentationFor additional information on what's included in this release, review the release notes via the Jamf Learning Hub.
For some reason there is an Item Failed notification in the Self Service+ App (with+ I mean the new version.So the old fix “sudo rm -R ~/Library/Application\ Support/com.jamfsoftware.selfservice.mac/”dont work any more. Its account related because if I login with a different account this issue is gone:Also its only there when you start SS.app (the 1 in the Dock appear if you close SS the ! disappear)Any idea? thanks
We have an iPad that switched on after 2 months now it has an expired certificate I cannot renew. (See the attached images)This iPad is connected to the wifi but it doesn't communicate with the JAMF server all the commands are in pending status.When I check the " JSS Built-in Certificate Authority " in the server it's expires in 2033Can anyone help regarding this issue what should I do? When I open the iPad from the JAMF server This is what I can see on the device When I got to the PKI certificate and checked the certificate expired in 2033 Most importantly self-service is not working
Hi everyone,We have a WPA2/WPA3-Enterprise network, and I am wondering if it is possible to use Jamf’s built-in CA to push certificates to end devices, so that users can be authenticated for Wi-Fi using those certificates.Additionally, what is the typical approach for this setup? I see docs recommend using AD CS, but our organization uses Azure rather than on-premises Active Directory.I would appreciate any guidance from someone with experience in this area. Thank you.
Hi, I am running a vendor bash script from self service as part of a remediation effort. As part of the script there is a device shutdown. This happens before the device feeds back policy logs so if it fails I cant see why. Would anyone know if sh scripts and their results get logged automatically somewhere or if there is a simple command to get them to do so? Alternatively presumably I could remove the reboot from the script and have the JAMF policy do that?
How to do we stop these notifications from popping up? Staff are receiving these throughout the day and it’s very annoying and disruptive. MB Air M2 and OS is 15.5.0 or later. Is there a config profile or settings to adjust in Jamf?
I inherited a pretty banged up Jamf environment and im looking for a way to re-escrow 103 users’ personal recovery keys. I know how I can do this on the Mac itself, but im wondering if theres a safe way for me to do this in bulk. Thanks!
💙 Hi, Jamf Nation! 💙We’re gearing up for this year’s Jamf Nation Live (JNL) events, and we’d love to feature a few customer voices at each stop on the roadshow. If you’re planning to attend one of the JNL cities and would be open to speaking, we’d love to hear from you!✨ What we’re looking for:• A short customer story (5–7 minutes)• Focused on your Jamf journey, wins, or lessons learned• Comfort speaking to a friendly, community‑driven audience🗣️ How to participate:Drop a reply in this thread with:1️⃣ Which JNL city you plan to attend2️⃣ Whether you’re interested in speakingWe’ll review all responses and follow up directly.Thanks for helping us make JNL 2026 even more meaningful! 🙌🏻
On Wednesday, February 18, 2026, the New York City Jamf User Group (NYC JUG, or simply “the JUG” to its members) celebrated its 12th anniversary. The date marked exactly 12 years since the group’s first meeting.Meeting an average of four times a year, NYC JUG has built a long tradition of bringing together the Apple admin community in New York City. In the dozen years since its inception, more than 400 admins have participated in the group. Along the way, the community has helped launch several spin-off groups including Women in Tech, MacAdmins LATAM, and MacAdmins NYC, all started by NYC JUG members.How It StartedBack in 2014, as a longtime member of the Apple admin community and a Jamf customer, I posted on Jamf Nation to see if there was interest in getting a group together to share ideas and build a sense of community. Apple admins were often the minority at the companies where we worked, so the idea of getting together to help each other was something I felt strongly about. Wit
Does anybody know if there’s a way to deploy the Aurora Endpoint Defense (CylanceProtect) through Jamf? When deploying them on a 1 by 1 basis through Aurora, I create the user in Aurora Endpoint then that creates credentials for the user and sends them an email to download the app along with their credentials. I’m wondering if there’s a way to easily push this to iOS devices without touching each individual phone. Any help is appreciated!
How is everyone securely disposing or destroying their own Apple SSD storage units?Considering that MacBooks from 2016 to 2022 have an SSD (NAND storage) that is not upgradeable,and it is not replaceable either, since it is soldered onto the main board:If a company has decommissioned a MacBook and the device reaches its end-of-life,the NAND storage cannot be extracted and re-used on a different device.Also:How can businesses assert that their data is securely wiped before device disposal?
I am trying to create a Applications Usage Reports specially for Adobe App, I have tried:To create a usage report for a group of computers based on applications, you'll need to follow these steps:First, ensure Application Usage collection is enabled:Go to Settings > Computer management > Inventory collection Click Edit, then the Software tab > Applications Select "Collect Application Usage Information" checkboxNext, create a Smart Group for your computers:Navigate to Computers > Smart Computer Groups > New Add criteria using Application Title and optionally Application Version Configure operators and values to define your groupFinally, generate the report:Go to Computers > Search Inventory Create or select an advanced computer search with your criteria Click the Reports tab Select "Applications" as the inventory item to base results on Choose your file format and click Download ReportThis is jamf instructions and it did not work, when I reached out to support this is
Hi, I have a scenario where I want to use Entra ID during Automated Enrollment to authenticate end users and ensure Entra ID is the single source of truth for users and groups. I was also wondering whether if it would be possible to automatically create local accounts based on Entra ID.From what I have read, this is only possible with Jamf Connect. However, I've also heard that Jamf Pro has some IdP/SSO capabilities during enrollment, I'm trying to understand what can actually be achieved using Jamf Pro alone. If anyone with Jamf Pro expertise could clarify, I would greatly appreciate it. Thanks!
Our company recently installed Jamf on our Mac. Me and some colleagues on Sonoma are locked out of our accounts because a new password is required but the password is not accepted. In short:No Jamf installed. All is well.Upgrade to Sonoma. All is well. Install Jamf. Accept the certificate, check it out in System Preferences. All seems well.When the screen saver lock kicks in, try to log back in.A new password is requested. Enter it, in both fields. Password is rejected because "Your password does not meet the requirements of the server."Some notes:The built-in macOS password check shows all rules in green.I did try every password config that would make sense, no luck, and I don't think that's itI'm very puzzled about the need for "the server" to see my local admin password, WTF?!
We've recently been trying to get users to update passwords more regularly and with that of course, is keychain issues. I was trying to create a script to remove local wifi connections and server connections so when they accessed them, they could just recreate it by typing in their password. I've been struggling with this for a couple of days and had success locally, but not when deployed, and now I've broken it completely again.#!/bin/bashsecurity delete-internet-password -l "cwinprint" ~/Library/Keychains/login.keychainsecurity delete-internet-password -l "pwinfile" ~/Library/Keychains/login.keychainsecurity delete-internet-password -l "cwinfile" ~/Library/Keychains/login.keychainsecurity delete-internet-password -l "fwinfile" ~/Library/Keychains/login.keychainsecurity delete-generic-password -l "IS-EMP" -s com.apple.network.eap.user.item.wlan.ssid.IS-EMPsecurity delete-generic-password -l "CO-EMP" -s com.apple.network.eap.user.item.wlan.ssid.CO-EMPLooking to use this as a script to
Hi,my organization requires me to block all Adobe Creative Cloud AI features. Does anyone have experience with this? What can be done? Are there Configuration Profiles I can use that are already tested?Thanks in advance.
I created a script with sudo jamf policy; sudo jamf recon, added it to a policy, and made it available via Self Service. It runs and the check-in time and inventory updates but policies that are set to run on recurring check-in are not triggered. Is there a way to create a policy that I can make available in Self Service that will force the machine to check-in, run any available policies that are set to run on recurring check-in, and update it's inventory?
Also, I just realized JNUC 2026 starts on a Wednesday, ends on a Friday. 🍗🎉 Gives us time to protein up all weekend long with some bbq. 🍖• Link here
A Read-only Friday post by William Smith Only those in IT would ever get it. My dad loved listening to a radio broadcaster named Paul Harvey. Wow could that man tell a story! (I’m referring to the radio broadcaster, but my dad knew how to draw a crowd of listeners too.) Paul Harvey ended his daily broadcasts with a segment called “The Rest of the Story”. He would generally start with a seemingly simple and banal story about something or someone. But as he told the story, the details would take on some life, and the tale would grow bigger until he revealed the one key element he’d been holding back that tied everything together. A really weak glue was of no use at all ‘til an office secretary found a use for it… “And that’s how Post-It Notes were invented!” Or an author was shaving one morning and thought of a story but for years no one would buy it… “Until one day Frank Capra decided to produce it as It’s a Wonderful Life.” Harvey would end every one of these stories with his signature
From a security finding our Infosec team has task us with finding a way to “Enable any settings that can prevent download of unwanted and/or malicious software”. has anyone been able to prevent downloading in Safari and Chrome?
By using Jamf Pro to revoke the administrator privileges of users, we are now facing a problem. Applications like Cusros have a very high update frequency. However, we don't want to simply and brutally grant the users the administrator privileges and let them complete the automatic update by clicking once in the Self Service. Do you have any suggestions on how to solve this?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!