Get Support
Recently active
Is it possible to deploy the OneDrive plist config file via jamf or does it have to be packaged in composer so it installs in the correct location?
Since July 4 I haven’t seen any Daily Digests. Did they get turned off as part of the upgrade to the new JamfNation?
Hi All, We are running JAMF Pro on the local server / on prem "Windows Server" (not the cloud version). I want to use the Patch management to update the Apps (Chrome, Firefox VLC Office apps etc..), macOS etc.. I'm new to this is there any way I can get some help to set up this? Article videos etc..
This might be a silly question but is there no way to search for a mobile device by it's Jamf Pro Management ID in the web ui? I couldn't find any filter options for it in advanced search.Not the Mobile Device ID but the Management ID.Thanks in advance!
Hi all,I am trying to do a user initiated enrollment on a Mac Neo. I’ve done this same user initiated enrollment on many other Macs without issues, but this one only accepts some configuration policies and no packages can be scoped to the machine. Additionally, on my Jamf Pro instance, it says that the machine is not managed.I have already done sudo jamf policy commands and updated the inventory, but that hasn't changed things. There don't seem to be any policies in Jamf Pro that I can scope to the Mac. The Mac is not listed under computers that I can scope, however, the Mac does show up when I click on the inventory tab.Has anyone seen this before where the device shows up in inventory but remains unmanaged and unscopable? Any suggestions?
DDM Software Update is working fantastic for the most part.Majority of the fleet has updated.I’ve created static groups to act as manual rings. I have few stranglers that will not update. There is enough storage, user has secure token, computers are ADE enrolled. Computers are checking in.I have the following screenshot from one endpoint.Management, Operating System shows “No Updates in progress”.How do I fix this?
I was trying out the Jamf Return to Service app and it wiped my Verizon esim. Does anyone know how to prevent that from happening? I don’t see a key in the documentation and I do have a restriction set up to enforce preserving the esim on an erased device. Edit: it looks like i got it back by toggling on the Verizon service in the settings after a network reset, but I thought the Jamf RTS app was supposed to preserve that setting?
I have been working on jamf setup manager and wanted to get some inspiration and see the creativity of other minds in the community. Currently I just have it wait for user entry for the users email and machine name and then it installs chrome enterprise and office 365. I want to try some role based access and install applications depending on the role of the user entered in the beginning, I got some ideas brewing.
We’ve been testing Self Service + (deployed via a policy since we can’t use Jamf Cloud Services). First impression is: why did they change what the user first sees when they open Self Service?In Self Service classic the user would see the items that they can run. Now in + they have to click in a few spots to get a list of items to run - aren’t we going backwards in making this easier for our end users?I hope that Jamf will provide some way to customize this behaviour - I want to be able to specify what section of of Self Service + loads at startup. I also don’t like that our administrator account is listed on that initial screen that loads - would be good to be able to suppress that completely since we don’t use Jamf Connect. And does anyone know what Jamf means by deprecating classic Self Service? Is it simply not going to function anymore or will it simply not be updated? And is it not going to install on new Macs and will it be removed from existing Macs automatically - could we ove
Jamf clients can not connect off campus to our Jamf Pro server DMZ server. Our F5 is forwarding off campus traffic on port 8443 to that DMZ server and port 8443 is open. Connecting off campus to the Jamf console on the DMZ server in a web browser with the same URL Jamf client uses works. The client is getting a 403 error.
When trying to resolve certain messages in the notfication page, the following error is coming up - Our development team is notified about this problem. Problem identification: #52c7d9c084285505This has been happening for some time and I was wondering if anyone has been able to come up with a solution.
I am trying to create a cloud distribution point using Amazon S3. The JSS returns the error: Unable to create distribution for this bucket But when I check my buckets there is a bucket similar to jamf235a039ede4741fe831b0e31287c6c7d created. Anyone have any luck with this?Thanks!
Hi, Im currently working on setting up Self Service+ in time for the deadline of March 2026. We currently have over 400 machines with Self Service instaleld and looking to deploy this to new machine in batches first for testing. Ive currently been testing on my self and manually installed the application and Ive had some issues with the Keychain popping up, which I saw was an issue on past threads. What would be the best way to go around this in a production environment?
Good morning, I am currently working with a MacBook that is on preparing a script to help my team to control power settings. At this time pmset does not have a direct way to change this setting via terminal. I also do not see any configuration profiles settings that allow us to set the limit either. Has anyone else tried to test the charge limit on MacBook?
How can I manage the new* AI Controlswithin Firefox with a Configuration Profile?Is there a way to configure it via a JSON?Thanks in advance!
I have successfully setup PlatformSSO for EntraID authentication and after running it for a while I have some oddities.If the token expires Safari will offer passkey as an option for logging into EntraID federated applications. Our conditional access policies allow passkeys, MFA, Strong Auth (FIDO etc). Once the login is complete the Mac will passthrough creds for any access in any browser.If the token has expired then in non-Safari (Edge, Chrome and Firefox) the user is only offerred password as the option to login unless they have a passkey in Authenticator or an external FIDO token registered in EntraID (Yubikey etc).If you go to User/Groups and press the Authenticate button in the user account then the token is refreshed without any user interaction.Trying to work out if I’ve missed something in the config profile or if there is another issue.Anyone else seen similar and worked out a way to resolve so passkey/biometrics is offered across all browsers rather than just Safari?
Having worked at Jamf for nearly a decade, I’m so humbled to learn and grow amidst some incredibly smart, capable and kind women - both colleagues and customers.Just to name a few: @KatieE, @ktrojano, @woaikonglong - you’ve been bright lights in the tech space, for myself and the broader Apple community. Thank you for sharing your wisdom to help those around you! And of course, to @LysetteB and @JoannaB - thank you for all the hard work and dedication you put into serving our customers. I’m grateful for your partnership every day!☀️ Do you know a woman who deserves some recognition? Let her know below! ☀️
With the release of MacOs 26.3.2 for the Macbook Neo only today - all of our other Mac devices fail to enroll through prestage enrollment when the minimum version is set to ‘Latest Based on Device Eligibility’. It seems the 26.3.2 update is trying to be installed on non-neo macs and it fails the process.I’ve set the requirement in our environment to specific version - 26.3.1 and I am testing it currently. I assume this is more an Apple problem than a Jamf problem however. ETA: Dropping it to a specific version fixes the issue.Image below is from a MacBook Pro (14-inch, Nov 2023) [M3 Pro] model.
As MacAD.UK approaches its ninth year, and the tenth anniversary of its very first gathering, the conference has become a fixture in the Mac admin community. What began as a small, ambitious idea from a handful of passionate techs has grown into one of the most recognizable Apple admin events in Europe. This year marks another milestone: a move to the iconic Brighton Dome, a venue that has hosted musical legends To understand how MacAD.UK evolved, what makes it different from a typical tech conference, and why the community keeps coming back, we sat down with the organizers, Liam Donnelly, Ade Leader, and Alex Hawes to talk origins, ethos, and the moments that remind them why they do this work. Macaduk is now in its 9th year. What was the spark that started it all, and did you ever imagine it would grow into what it is today? The event was started by a couple of senior techs at Amsys, including David Acland, who was our CTO at the time, and Dean from Jamf, if I recall correctly. They
I asked this same question on the Clearpass forum, in case there are more people there that are doing similar things, but I'm hoping for someone with the conceptual understanding to just give me a nudge in the right direction regarding this setup. We have been using 802.1x with Machine certificates issued by AD, with ClearPass and Windows machines for a couple years now. I understand the process that the windows machine joins the domain, get's a certificate, and then our clearpass servers are domain joined and can authenticate the machine with Active Directory using some of our various AD servers. All of that works well, and makes sense to me. Now we're extending it to macbooks and adding Jamf, so that we can also set up certificates on the macbooks (they will not be domain joined) via SCEP/NDES integrated with our windows CA, with the goal of them also doing 802.1x with EAP-TLS. So far, we have the SCEP process working fine, and the macbooks obtain their certificates from our CA via S
I am wondering if it is possible to block a managed iPad from using a mobile hotspot as a connection. I did not find anything in the documentation or configuration profiles that would block using one, only disabling the device from being the hotspot itself. My goal would be to restrict this option from students who have personal devices in an attempt to circumvent filtering. So far our filters do not care but it is also another distraction tool.
This is more of an informational post that hopefully helps someone one day. I recently discovered a weird situation where if you have an Extension Attribute script that contains a particular single character it completely breaks the entire Jamf tenants ability for any Macs to update inventory.Notice the difference in the two images. The first is my view in my script editor (CodeRunner in this case). The second is the view of the script in Jamf while editing the EA. There is an odd character on the third line that appears to be an invisible backspace (apparently ctrl-H). I verified that it does show in multiple web browsers, just not in CodeRunner (does show in SublimeText).Aside from finding the bug in the code eventually, if a script contains this character in particular, just having the script active seems to break Jamf’s ability for devices to recon. Once I enabled the script, ALL Macs started receiving the following error. sudo jamf recon -verboseverbose: Timeout: 10verbose: Checki
I’ve created the below xml file for Chrome in Jamf School but students can still delete browsing data. Does anyone know what key I’m missing? <?xml version="1.0" encoding="UTF-8"?><!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN""http://www.apple.com/DTDs/PropertyList-1.0.dtd"><plist version="1.0"><dict> <key>IncognitoModeAvailability</key> <integer>1</integer> <key>BrowserSignin</key> <integer>0</integer> <key>SyncDisabled</key> <true/> <key>AllowDeletingBrowserHistory</key> <false/> <key>SavingBrowserHistoryDisabled</key> <false/> <key>SearchContentSharingSettings</key> <integer>1</integer></dict></plist>
Hello Has anyone else lost access to Blueprints & Compliance from Jamf pro this afternooon. I still have permissons, but seem to no longer be able to access them. Get the same if I try another account that should have permissons as well.
Need help installing an in-house Chrome extension. This is what I’m using but isn’t working.<?xml version="1.0" encoding="UTF-8"?><!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"><plist version="1.0"> <dict> <key>ExtensionSettings</key><dict> <key>Extension ID</key> <dict> <key>installation_mode</key> <string>force_installed</string> <key>update_url</key> <string>https://URL/Extension.crx</string> </dict></dict> </dict></plist>
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!