Get Support
Recently active
Need help installing an in-house Chrome extension. This is what I’m using but isn’t working.<?xml version="1.0" encoding="UTF-8"?><!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"><plist version="1.0"> <dict> <key>ExtensionSettings</key><dict> <key>Extension ID</key> <dict> <key>installation_mode</key> <string>force_installed</string> <key>update_url</key> <string>https://URL/Extension.crx</string> </dict></dict> </dict></plist>
Is this supposed to happen? Our automatic upgrading of the Self Service+ app has changed back to /Applications/Self Service.app (was /Applications/Self Service+.app). Also is prompting for keychain access since, well, the application name changed. Anybody else?
Is there anyone here who is already using Jamf School integrated with Jamf Connect and Self Service+?I found the article below, but the information seems a bit inconsistent.This link explains how to deploy it:https://support.jamf.com/en/articles/13550577-deploying-jamf-connect-self-service-with-jamf-schoolHowever, in the tutorial it includes a Jamf Pro video, not a Jamf School example:https://trainingcatalog.jamf.com/path/get-started-with-jamf-connect/prepare-to-configure-jamf-connect/614276Also, based on the technical documentation in the following link, Self Service+ does not mention Jamf School, and only refers to Jamf Pro:https://learn.jamf.com/en-US/bundle/self-service-plus-documentation/page/About_Self_Service_Plus.htmlThere are also a few other things I noticed: In Jamf School, there is no option for “Make apps available in Self Service.” In the Jamf School settings, there is no menu for Self Service+ or branding options. If anyone has already tried this setup, I would really
From here https://learn.microsoft.com/en-us/defender-endpoint/mac-jamfpro-policiesAdded configuration profile Microsoft Defender – Scheduled ScansEveryday at 14:45 and Wednesday at 10:00 <?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"> <plist version="1.0"> <dict> <key>features</key> <dict> <key>scheduledScan</key> <string>enabled</string> </dict> <key>scheduledScan</key> <dict> <key>ignoreExclusions</key> <true/> <key>lowPriorityScheduledScan</key> <true/> <key>dailyConfiguration</key> <dict> <key>timeOfDay</key> <integer>884</integer> <key>interval</key> <string>1</string>
we are currently experiencing an issue with our iPads managed via JAMF School.Since yesterday, all apps on the devices are hidden except for the Settings app.Key details: The devices are managed with JAMF School. Some restrictions are configured in the profile. No changes have been made to the configuration recently. Everything was working correctly until yesterday. If we disable the profile, all apps appear again as expected. Age rating is set to 16+. There are no apps configured in the allow list or block list. Could you please help us identify why the apps are being hidden and what might have caused this behavior?Thank you in advance.Best regards
All, after extensive testing, logging, and analysis the longstanding, intermittent issues affecting the managed endpoints in my enterprise has been traced to how the policy decision engine in GlobalProtect handles traffic destined for our cloud instance.To further explain:For some time upon execution of jamf commands (policy, primarily) in terminal following has been seen:“An error occurred. There is no message.”Subsequent runs would be successful. Nevertheless log captures of “mdmclient” and “com.apple.ManagedClient” are replete with various and sundry errors. Correlating these with netstat commands shows that jamf policy would be begin execution over the VPN tunnel (utunX)… and then quickly gets denied and directed to physical interface (en0). That this occurs, regardless of how quick, during initial TLS handshake hasn’t really helped matters.Further attempts running jamf terminal commands shows that while most traffic appears to head out via native interface some was now allowed via
Hello all.I am getting this error in my notifications when I login to Jamf Pro. I cannot seem to determine what is wrong with this, and it appears that our Jamf Connect configuration is working properly. Thanks in advance.-Pat
Today we are releasing a maintenance version of Jamf Pro to address the following product issue:Jamf Pro Server[PI-1068] Fixed: Mobile device smart groups and advanced mobile device searches using the "Device Ownership Type" criteria with a manually entered value incorrectly include institutional devices.Note: Smart group membership will correct itself as mobile devices check in. To speed up the recalculation process, administrators can edit and then save any affected smart group. For additional information on what's included in this release, review the release notes via the Jamf Learning Hub.To access new versions of Jamf Pro, log into Jamf Account with your Jamf ID. The latest version is located in the Solutions section under Jamf Pro.Subscribe to product alerts to receive real-time updates.
Overview This document walks through how to configure and use temporary privilege elevation on macOS using Self Service+.End users can request temporary local administrator rights directly from the Self Service+ app, authenticate via Touch ID or password, provide a business reason, and receive time-limited elevation, all without IT intervention.The elevation duration, reason requirements, authentication requirements, and permitted reasons are all administrator-controlled via a Jamf Connect configuration profile deployed through Jamf Pro.PrerequisitesUpdated: 3/6/25- To add clarification to Prerequisites Before following this guide, ensure the following are in place:Self Service+ v2.0 of greater installed on the target Mac. Jamf Pro access to create and deploy configuration profiles. The target Mac is enrolled in Jamf Pro. A valid Jamf Connect licence assigned to the device or user. Walkthrough Step 1: Configure the Jamf Connect Preference Domain in Jamf Pro In Jamf Pro, create a new co
Today we released Jamf Connect 3.5.0; this release addresses the following product issues: [PI143260] Fixed: Importing a configuration profile into Jamf Connect Configuration with the User Promotion Choices (UserPromotionChoices) setting in use causes the array for the setting to be replaced by the following text: (. [PI143263, PI144134] Fixed: Jamf Connect presents the following one-time prompt on computers with macOS Tahoe 26.1 beta, both on the login window and on the desktop: Self Service+ wants to use your confidential information stored in "Jamf Connect" in your keychain. [PI143435] Fixed: When RapidIdentity is the identity provider, the Jamf Connect login window requests the local account password during the password verification workflow instead of the identity provider password. To access new versions of Jamf Connect, log in to Jamf Account with your Jamf ID. The latest version is located in the Solutions section under Jamf Connect.Product DocumentationFor additional informati
We are upgrading Standard Cloud environments to a maintenance version of Jamf Pro which addresses the following product issue:Jamf Pro Server[PI-1068] Fixed: Mobile device smart groups and advanced mobile device searches using the "Device Ownership Type" criteria with a manually entered value incorrectly include institutional devices.Note: Smart group membership will correct itself as mobile devices check in. To speed up the recalculation process, administrators can edit and then save any affected smart group. Cloud Upgrade ScheduleYour Jamf Pro server, including any free sandbox environments, will be updated based on your hosted data region below. Review this guide if you need assistance identifying the Hosted Data Region of your Jamf Cloud instance. A full general availability release is being scheduled for the week of 9 March.Subscribe to product alerts to receive real-time updates. Hosted Region Begins Ends ap-southeast-2 8 March at 1300 UTC 8 March at 1900 UTC ap-northea
Does anyone else get the Device is busy, will try again response or just stays pending when pushing configurations to a locked ipad or iphone? Even update inventory just stays pending. This is happening to us consistently and magically works when the device is unlocked. Any fixes for this or is this by design?
Hi everyone! My team is currently exploring the implementation of LAPS into our workflow, and we’d love to hear from those of you in Education (or similar sectors).For those who have made the jump: how has the experience been? Specifically, I'm curious about the initial setup complexity and how user-friendly the password retrieval process is for your team. Also, from a security standpoint, do you find that simply rotating the local admin password provides enough protection, or are there other factors we should consider? Thanks in advance for any insights.
Microsoft has put a new “unlock premium” button in teams. Has someone found plist / custom profile setting to disable this?I don’t see teams as an option in iMazing Profile Editor.
Hi, Our company WiFi uses user network creds to join, but the window that pops up for this has a certificate dropdown box (with several items available). The users get confused and start trying these. Is there a way to remove this box for at least this one SSID? Thanks in advance, -Pat
I am having an issue creating a PreStage enrollment in Jamf Pro, The 'New' PreStage button hangs immediately on click. I have verified the ADE token is new and UIE is enabled. I just see a spinning wheel when I click New to create a PreStage enrollment for Computers. The Devices/ios one works fine. I did try chrome, firefox, safari browser, same issue.
Hi Jamf Nation! Exciting news - the JNUC 2026 Call for Sessions is officially open through April 10!Thinking about becoming a JNUC speaker? Check out the Speaker Prospectus for all the details. We can’t wait to see your ideas - submit your session here! Questions? Email us at jnuchelp@jamf.com
It would be great to introduce a more granular approach to scoping Blueprints in Jamf Pro.Having the ability to define exclusions within Blueprint scope would be extremely valuable.
Hi folks,I’m doing an audit of our config profiles and would like to break our baseline configuration profile into multi profiles. Right now, we have a massive baseline profile. If I need to edit a specific feature or settings, the whole profile gets push out everywhere.I would like to create smaller profiles that are specific to subsets of settings so I have more granular control over updating settings and the distribution of those settings.For example I may have profiles like the following as opposed to one massive profile:Baseline- Network UsageBaseline- FunctionalityBaseline- Setup StepsBaseline- Hidden AppsI can certainly created those subset profiles now without any scope assigned. My question is whether people have suggestions on the best order of steps to accomplish this task without the world exploding :-)For example, if I replicate everything currently in effect within multiple profiles, and I scope those new profiles to my all devices group, then I remove the current massive
Today we are releasing a maintenance version of Jamf Pro; highlights include: Engage Settings for In-App MessagingYou can use the Engage settings in Jamf Account to opt-out of web interface messaging or surveys. Opting-out affects all Jamf platform interfaces for your user account. For more information, see Profile Management in the Jamf Account Documentation. Resolved IssuesJamf Pro Server: Security Issues[PI149568] Fixed: A known vulnerability in a third-party library (CVE-2025-67735). [PI158236] Fixed: A known vulnerability in a third-party library (CVE-2026-25896).Jamf Pro Server[PI139067] Fixed: Jamf Pro may intermittently invalidate active JCDS download tokens, causing all cloud distribution downloads to fail with 401 errors until a new token is generated. [PI140295] Fixed: Advanced inventory searches and smart groups do not add criteria correctly if the selected criteria contains 2-byte characters. For additional information on what's included in this release, review the release
I’m a little bit disappointed about so much missing endpoints in the API. So many Informations about devices, groups, profiles that i can’t get or set over the API. I often like to write shell-scripts that could solve problems automatically, for example with profiles not installing, but because of missing endpoints for these functions i can’t and have to do it by hand. For example: Sometimes Apps on Devices use Single App Mode für Exam-Mode and stuck in it after that. Its not visible on the device but inhibit that profiles with whitelists can be installed. Thats a problem for profiles that are time based. The solution is to set this device in a profile with single app mode, wait until it is installed and remove the device out of this profil. But i cannot automate this, because the API have no Endpoint for installation status of profiles. So i cannot get a list of devices that cannot install the white list profile with a reason and also not the status if the repair profil is installed.
Hey guys, I'm in the process of testing Jamf Connect, I noticed this as a sign-in option Would it be possible to remove it since no one will use it to sign in to their Mac!!? I couldn't find any related settings in our Azure AD. Thanks in advance
Hello all,We are finally moving our labs away from AD, and our admins are setting up JamfConnect for authentication. I’ve been able to repurpose most of our apps/config profiles etc but I wonder if anyone has had success with WEPA and passing credentials via JamfConnect / PlatformSSO etc. TIA
Hello All, I can’t seem to make sense of this one. So I was looking at Patch management and Jamf Connect.Jamf Connect 3.7 came out recently, so I’m thinking I’ll add it to patch management.I look at the definitions and I see 3.14 as the newest, and there isn’t even a 3.7 listed.I am lost.-Pat
Today we released Jamf Connect 3.7.0; this release addresses the following product issues: [PI-923] Fixed: Authenticating via web view with Entra ID using a FIDO2 passkey prevents users from authenticating with Jamf Connect via the login window. [PI140159] Fixed: After two incorrect login attempts, the Jamf Connect login window fails to accept the correct password and prevents the user from authenticating after the lockout timer is complete. [PI152763] Fixed: The Sign In window displays two arrows that do nothing when clicked. Fixed: The installer for Jamf Connect does not force quit the Jamf Connect login window while deployment tools, such as Jamf Simplified Device Enrollment, are in use. To access new versions of Jamf Connect, log in to Jamf Account with your Jamf ID. The latest version is located in the Solutions section under Jamf Connect.Product DocumentationFor additional information on what's included in this release, review the release notes via the Jamf Learning Hub.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!