Get Support
Recently active
Hi. Started seeing this error on applications pushed to Macbooks through DeviceGroups during enrollment. Apps are set to automatic installation. Tried to resync licenses with ASM without luck. Trying to reinstall the app sometimes gives the same error, or it works. I have been unable to see any reason for when this is happening. It seems totally random, and happens on all sorts of applications.Update! This also happens on random OnDemand applications where students adds them from Jamf Student.Anyone else seeing this, or know how to resolve it? This is how it looks from the Jamf Student application. The students are not able to retry, the teacher is not able to redistribute the app. Only “solution” is to hope that a reinstall from the managment site works. This is hit or miss.
One of my users cannot register for platform single sign-on. She can complete step 1, which is to authenticate with her Mac login password. Next, she can enter her email address. That’s when the process goes awry. After entering her email address, the window goes blank white. Behind it, we can see that Company Portal is doing something in the background. There’s the spinning progress icon. After seeing this, I removed and reinstalled Company Portal and ensured that the latest version was installed. She’s running macOS 26.3.1 and will have 26.4.1 soon since I just started enforcing that update. Has anyone seen this behavior and solved it? The PSSO login type used is Secure Enclave. We can’t do anything but cancel the registration.
I am testing Connect 2.45 and have had a popup appear on the Login Screen.Its a really "Helpful" Popup. All it says is SecurityAgentHelper wants to make changes, and it asks for an Administrator username and password. None of my users are Administrators, so they will not be able to fill this in.Is this a bug? Is there a way to fix it so that it does not pop up? What process is it that wants this access? Thanks Paul
I found out on a Monday evening in July, riding the subway home from work. I opened Gmail on my phone somewhere under Manhattan and saw I'd won the Jamf diversity scholarship, and I couldn't stop smiling the rest of the ride. I texted my partner right away. I'd applied because my department couldn't afford to send anyone, and JNUC had always lived in my head as this glowing space from the way senior engineers at old jobs talked about it. JNUC was in Nashville that year. I'd been to the city before for work, but never really gotten to enjoy it. Walking into the venue I just thought, wow, this is huge. I loved the vendor floor, finally putting faces to the account people I'd only ever emailed, and I got to meet up with an old coworker from a previous job, which made the whole thing feel less like a solo trip. One moment I keep coming back to: I was heading up the escalator and a woman struck up a conversation with me. Turned out she was also from NYC, and we ended up talking tech and Jam
PI-1152 involves the MDM Device Identity Certificate not being trusted on new enrollments after updating to version 11.26.PI-1153 concerns Device Identity Certificates being marked as untrusted in Keychain Access during enrollment in version 11.26.1.
• Starting as early as the next major software release, Apple operating systems (iOS, iPadOS, macOS, watchOS, tvOS, and visionOS) might refuse connections to servers with outdated or non-compliant TLS configurations due to additional network security requirements.• Requirements: Servers must support TLS 1.2 or later, use ATS-compliant ciphersuites, and present valid certificates that meet ATS standards. For complete network security requirements, reference the developer documentation• Link: https://support.apple.com/en-us/126655
I’ve had a bunch of Macs suddenly fail to get the Network Filter config apply for Defender. (Configured as instructed by Microsoft below)https://learn.microsoft.com/en-us/defender-endpoint/mac-jamfpro-policies?view=o365-worldwide#:~:text=Step%208:%20Configure%20Network%20ExtensionThis is resulting in a prompt "com.microsoft.wdav" Would Like to Filter Network Content that repeatedly appears in the middle of the screen and prevents users from working.It is effecting 90 macs out of over 1000, across different versions of macOS and on both Apple Silicon and Intel. Those affected are seemingly random, although only seems to affect our Lab environments connected via ethernet, not our staff devices on WiFI.Reseting a Mac and pulling down the same config seems to ‘fix’ the issue, so I’m guessing the issue is not with the config profile.I’ve tried descoping and rescoping the config and uninstall/reinstall of Defender to no avail. I’m thinking now the issue lies with the extension com.microsoft.
Fixed
What’s NewWe are excited to announce the next step in helping admins configure their user’s experience in Self Service+. With this extended beta release, admins will be able to configure the order of items in the left navigation bar, the presence of sections on the home page, and the appearance of the Self Service+ menubar item. With this first phase of the release, these three options above are configurable by configuration profile using the schema included in the release notes.In addition to this change, we are also currently working on a blueprints implementation within Jamf Pro to make changing these settings even easier. As we work through your feedback on these changes, we also want to be bringing even more customizations to help you bring a more tailored experience to your users. If you have any ideas for Self Service+ experiences that you would like to configure, we ask that you also share your ideas for us to consider as we prioritize next steps for customization.What we're
Today we are releasing a maintenance version of Jamf Pro; highlights include: Tomcat Version InstalledJamf Pro 11.27.1 includes Tomcat 10.1.54.Font Payload AlertAn alert has been added to the Font payload in configuration profiles to inform administrators that large font files or fonts scoped to large device groups can degrade performance or cause Jamf Pro to stop responding. Known issue: The alert message currently displays as a raw string rather than a formatted alert. Both the English and localized versions will be resolved in the next minor release. Resolved IssuesJamf Pro Server: Security IssuesJamf provides the CVE-ID for security issues with high or critical severity when possible.[PI169754] Fixed: A known vulnerability in a third-party library (CVE-2026-22752).Jamf Pro Server[PI-1133] Fixed: The Jamf Pro interface displays some policy payloads only in English, regardless of language settings [PI170473] Fixed: If a computer does not have an escrowed Activation Lock bypass code w
Hi all - has anyone managed to change Jamf-related notifications (Self Service, Jamf Connect, Management Framework) from persistent alerts to banners on macOS?On our supervised Macs, these are stuck as persistent, the alert style is greyed out, and users can’t change them.I tried pushing a custom Notifications profile (setting everything to banners), but it didn’t override the behaviour while the Jamf automatic notifications setting was enabled.When I disabled “Automatically install a Jamf Notifications profile”, my custom profile worked and switched them to banners - but it broke Self Service (lost the Elevate Admin option), so I had to roll it back.No other conflicting profiles in place.Just wondering if anyone has found a clean way to allow banner notifications without impacting Self Service, or if this is just expected behaviour with Jamf’s default setup.Thanks 👍
Hello,Since iOS 26.2, a passcode is required when using AirDrop, which quickly becomes cumbersome in a classroom setting.Is there a way to disable this requirement via Jamf School? I haven’t been able to find a relevant setting.Thank you in advance for your help.
• PSSO Utility is a native macOS app for inspecting and monitoring Platform Single Sign-On (PSSO) status. It queries the system app-sso tool and presents key metrics, IdP details, and raw JSON output in a clean interface. A menu-bar item is available for quick troubleshooting.• Link: https://github.com/jamf-concepts/psso-utility
Hey everyone, I have been going through different posts across here and Reddit, and I could really use some help. I am attempting to use the Jamf ADCS connector to push a machine certificate to a MacBook, which I can get it to do successfully. In the same profile, I have the network configuration in place there as well. The issue that I am running into is not anything with the certificate/Jamf side, but with the Windows RADIUS server. I have an unbound AD object for the machine created, but I am unsure what I need to do with the object. The machine currently is successfully attempting to authenticate with the certificate, but NPS is rejecting it for error 8 - User account does not exist. Does anyone have this set up in their environments, and is there a better way to do things? My security and systems teams won't let me domain bind the Mac devices, so I am using Jamf Connect for authentication, and I assume this is also why I am having account issues.
I am trying to make a smart group to see what computers have the PaperCut Client installed but i don’t see anything in the /Applications/PaperCut Print Deploy Client/ directory that i can select as the .app in the smart group. What can I use create this smart group?
I’ve read most documentation and searched the forums but I’m having trouble finding out how devices that are assigned to users are kept assigned to users during and after the migration. We have 1200 Mac devices and about 4k ipads that need to keep their assigned user during the migration. We plan to use the migration tool in Jamf Pro. Currently we are using LDAP Username and not email for the user assignment. However each user has an email brought in as well. Should we update LDAP values first in order to make the transition? Would it be better to use the API to pull all devices and users, do the migration, then put them back with new usernames? Any insight into the migration tool and things to look out for also welcome.
Hey folks,I have something odd on a few macOS devices after users change their AD/Entra password via Jamf Connect and sync it locally.Zscaler asking for auth again / certificate install Outlook asking to sign in again Self Service opens but is completely blank Company Portal acts like there’s no server connection Keychain won’t unlock or accept the correct new passwordThe only thing that consistently fixes it for us:Delete everything in ~/Library/Keychains Reboot Log back in Re‑enroll the Mac into Intune via Self ServiceAfter that, everything works normally again.
Hi, I have deployed a CIS benchmark under Compliance in JAMF Pro, I want to use this to justify how secure our Mac devices are and adjust the rules as needed. Is there a way to generate a report is a CSV or PDF format? having a detailed informations or executive summary options?
I have recently taken responsibility of jamf pro from a previous employee and have never really used it before so this is a learning experience. I have a Macbook Pro on Ventura OS in a computer group with a Staff Restrictions profile applied. This profile is somehow completely disabling Control Center and the ability to set a Screen Saver with the message "Control Center settings are not available. These settings are controlled by a profile." I can exclude the device from the profile and gain access to the Control Center and Screen Saver settings but not when it's applied. I figured these settings would be located under the Restrictions payload under Preferences but I see no such setting specifically targeting these. Does anyone know where / what is the setting that controls these? Is it another name or in another location? What am I missing? I see no specific setting to enable / disable. Thanks in advance
Anyone want to share best practice for this? Blueutil doesn’t work as great/possibly at all in our environment after updating to macos 26.As a workaround I’ve been using the api to send the MDM command in a policy/script to those macs that turn it off. We have an outset login script that manages to lock out bluetooth changing in the control center and system settings, but there’s a short window of 5 seconds or so where students can turn it off before it is locked.
Hello Jamf Nation,Don't miss your chance to secure your 2026 JNUC tickets at the Early Bird rate of $1399 ($1199 for education and non-profit organizations). Starting April 1st, the Just in Time rate of $1,499 will apply ($1,299 for education and non-profit organizations).If you need help getting approval to attend, we've prepared a Convince Your Boss Letter to ensure you don't miss out.Have questions or need additional assistance? Visit our JNUC FAQ or email us at jnuchelp@jamf.com.Ready to secure your spot? Register for JNUC 2026!We look forward to seeing you in Kansas City this September! Best regards,Jeff
We got Defender working on our Macs about a year ago - deployed via JAMF Pro and with configuration profiles. We are not bound to the domain and do not use JAMF Connect.I am trying to follow along with Microsofts documentation (Onboard and offboard macOS devices into Microsoft Purview solutions using JAMF Pro | Microsoft Learn) which seems to be written for setting this up from scratch rather than adding it in to an existing setup. It seems to be doing something as we are getting better feedback under Device Onboarding, but still not making much progress. Here is an example of the details in Device Onboarding in Microsoft Purview with the error messages before and the more informative messages after I have created the configuration profiles in JAMF from the above guide:View under Device Onboarding: Before the configuration profiles were updated: After the configuration profile was updated: In the documentation that I linked to near the top, there is a "Before You Beg
Hey Jamf Nation! With JNUC getting closer you may have noticed that Level Up training options were recently added to the registration page. If you’re not familiar or you’ve never attended Level Up before, I wanted to share a little bit more about these training sessions and what you can expect this year. Level Up at JNUC returns as one day, exclusive, in-person training opportunities that take place the day before the conference kicks off. They will be held at the same location as JNUC, the Kansas City Convention Center, on Tuesday, September 22nd.These learning experiences are supplementary to the Jamf Training Courses like the Jamf 200, 300, and 400 Courses, but you don’t need to already have taken any of those as there are no prerequisites to participating in Level Up besides being registered for JNUC. If you have already taken some or all of these courses before, you may recognize some familiar faces at Level Up as they are taught by the same Jamf Trainers that design and teach our
Today, Jamf Training turns 20, and the milestone is worth pausing on.More than 40,000 people trained through instructor-led courses. Over 120,000 reached through the Online Training Catalog. 60,000+ certifications issued to IT professionals who've built careers on what they learned here.When we started this journey, the term "Mac Admin" didn't exist. There were no careers in Apple endpoint management. The path you're on today? It wasn't there yet. You, and people like you, built it.Now Jamf certifications are the industry standard for Apple device management and security. The admins who get trained deploy faster, run leaner operations and support their users better.But here's the thing: none of those numbers belong to us.They belong to you.To every admin who took a course before they felt ready. To everyone who earned a certification and finally had the credential to back up what they already knew. To the ones who stayed up late, asked questions on Jamf Nation, and showed up to JNUC re
We use Jamf Pro Cloud with Jamf Connect (for account creation + Entra ID password sync).After enabling “Use Self Service+ as the default end user app” in settings:Old Self Service was upgraded to Self Service+ on existing Macs Jamf Connect was removed, menu bar now has Self Service+ icon instead On new enrollments, we install Jamf Connect 2.45.1 → now it’s there alongside Self Service+I can’t find clear docs on this — so:Questions:Is Self Service+ intended to replace Jamf Connect completely? If yes, should we skip installing Jamf Connect post‑enrollment? Or should we move to Jamf Connect 3.x? Any official migration guide for 2.x → 3.x with Self Service+?Any experience or official Jamf resources appreciated.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!