Get Support
Recently active
We use Jamf Pro Cloud with Jamf Connect (for account creation + Entra ID password sync).After enabling “Use Self Service+ as the default end user app” in settings:Old Self Service was upgraded to Self Service+ on existing Macs Jamf Connect was removed, menu bar now has Self Service+ icon instead On new enrollments, we install Jamf Connect 2.45.1 → now it’s there alongside Self Service+I can’t find clear docs on this — so:Questions:Is Self Service+ intended to replace Jamf Connect completely? If yes, should we skip installing Jamf Connect post‑enrollment? Or should we move to Jamf Connect 3.x? Any official migration guide for 2.x → 3.x with Self Service+?Any experience or official Jamf resources appreciated.
Hello Jamf Nation!We’ve released Jamf Pro 11.28.0 beta. This release includes Mutual TLS Authentication for Webhooks, Jamf Pro API Changes and Enhancements and more! For full details, check out the release notes after enrollment.How to join the beta: Enroll in the Beta Program under Product Feedback at account.jamf.com. Click “Join Community” to join the beta forum once enrolled. If you encounter an error on Jamf Nation joining the beta forum, please log into Jamf Nation and then click “Join Community” again. Please also check out this recent blog on Configuring SSO in Jamf Account prior to testing Compliance Benchmarks, Blueprints, and App Switcher. Email beta@jamf.com with questions.The beta program is covered by the Jamf non-disclosure agreement; please do not share any information regarding your testing on any public forum, including the non-beta areas of Jamf Nation. Use the Jamf Nation Beta Forum or contact Jamf via beta@jamf.com with any questions. Thank you to all who participa
Hi everyone, I’m new here, so if this has already been asked before, please go easy on me 😅 Here’s the situation: I have a client who wants to prevent their developers from losing time every time they switch to a new machine (setting up their development environment, SSH keys, cloning repositories, etc.). Right now, their servicedesk team spends almost an entire morning preparing each device… but here’s the catch: instead of rebuilding the environment cleanly, they’re cloning everything from the user’s old machine. Personally, I don’t agree with this approach. I believe it’s better to go for a clean and automated process: regenerate SSH keys, clone repositories from Git, and configure the environment from scratch. So my question is:Is there any common approach or script within the community to handle this kind of scenario?For example, something that, using the user’s credentials, can generate SSH keys, clone repositories, and apply typical developer configurations. Any guidance, share
Trying to deploy device based certs to Non Domain MacOS devices, which will automatically connect to wifi. We have the following configured: AD (Ghost object created for the MacOS Device) ADCS (separate certificate template created for Mac) NPS NDES When we deploy the cert from Jamf, the cert deploys and installs on the device and I can see it’s issued with the correct template in ADCS. When we try connecting to wifi, we see ‘The specified user account does not exist. What am I missing? The domain controller is 2016, ghost object created, network policies created, we just can’t seem to bind the cert to the ghost object therefor it does not authenticate. Windows auth is obviously fine via the same NPS server. Any suggestions?
I was wondering if Jamf Hero’s is still open? Is there a application process?
Does anyone has a way to setup MS Outlook 365 as default mail app? If you want to setup it manually you have to do it in the Mac mail app, although you never used it. I have to send out something to the organization with an mailto: link and I do not want all people calling me to ask why Mail is opening instead of Outlook. Additionally it would be nice to set default programs via config profile in Jamf pro. Thank you for your help.
Any had this issue , devices where PSSO was already registered, users were prompted again to register. When they attempted to register, the process failed, and the devices entries are removed from Azure, resulting in loss of all organization access.we had to re-register the devices through System settings > User and Groups > Network account server > Edit, and then click repair.Note: We use Secure Enclave as authentication type, No changes where done at profiles
I’m well aware that there’s a big “old dog/new tricks” aspect to my reticence to move away from configuration profiles to blueprints, but my primary hangup with even exploring Blueprints too much is the limited scoping capabilities. In particular, I find it really useful with a configuration profile to just be able to exclude a single computer from the scope to remove it for testing or other reasons. But with Blueprints being entirely smart group dependent, the only way I know of to do that would be to modify the smart group to not include a computer name, or maybe link the smart group to a static group, but that feels janky. Help me think through this please.
Today we are releasing Jamf Pro 11.27; highlights include:AI Assistant in Jamf Pro General AvailabilityYou can use Jamf's AI-powered conversational assistant to support your organization's device management and security. AI Assistant consists of individual functionalities called "tools" that are organized in tool groups by product. When you enable AI Assistant, you enable AI Assistant Core, a foundational knowledge tool that can assist you with technical questions about Jamf's software and services. In addition, you can enable read-only tools for Jamf Pro. AI Assistant is disabled by default. Setup Assistant for Configuring OIDC-Based SSO with Jamf AccountA setup assistant for configuring OIDC-based single sign-on (SSO) with Jamf Account has been added to eligible Jamf Pro environments. This provides a convenient way to configure SSO through Jamf Account completely within the Jamf Pro interface, streamlining authentication and enabling platform capabilities in Jamf Pro. Enhancements to
I have searched AI and here but I can’t find anything that matches (or works) for our organization. I would like to have (as part of the pre-stage enrollment) the Mac device be renamed to a prefix + s/n. The configuration profiles logs all show MacBook Pro or Users’s MacBook Pro and not the naming scheme that is approved for the company. From what I understand, you can’t go b ack and rename machines in any log. and modify it.
Hi, First time poster here.We have a fleet of student iPads that we're managing through Jamf, and that have Microsoft Teams deployed on them for classwork.The students have learned that, if they tap "+ Add Account" within Teams, they can connect a personal Teams account within the app, and have been using this to send notes in class without oversight.We've been able to limit the Windows Desktop Teams App so that it'll only allow accounts on a specific Teams "tenant ID" to sign in - and we're hoping that a similar capability is possible in the iOS Teams app via Jamf, but have had trouble finding any information about it.Is this something that anyone has managed to accomplish, or has advice about? I'm relatively new to Jamf, so step-by-step guides are greatly appreciated.
Hey Jamf Nation! 👋 🚀 Free live LinkedIn workshop. April 22. Register now → https://jamf.it/JamfNationEvents Still here? Great. Here's the deal. 👇 Most of us in IT and security treat LinkedIn like a digital parking lot: set it up, forget it, and hope no one looks too closely. But LinkedIn is quietly one of the most powerful tools in your career arsenal. For finding your next role, building your network, and getting recognised as the expert you already are. We're bringing in Devin Reed, a content strategist who helps professionals and executives grow their LinkedIn profiles (and helped scale LinkedIn programs at Gong and Clari), for a live workshop built specifically for people like you. He'll break down exactly how to make LinkedIn work for you, without feeling like a self-promoter or spending hours every week on it. You'll walk away knowing: What a strong profile actually looks like (and how to fix yours fast) How the algorithm works and what actually gets you seen The sim
Can get some help with Packaging Xcode. We currently use Mac apps but it a hit and miss. I will like some help on the best practice to packaging and maintaining this app.
We’ve been using Jamf now for almost 10 years and are still struggling with users that don’t update their computers and mobile devices. So now we’re thinking of activating Software updates in Jamf. When we choose activate/enable it we get the message bellow. Is it just to continue or could it cause problems?
Enable Jamf’s AI-powered conversational assistant for Jamf Pro in Jamf Account, configure OIDC-based SSO using a new setup assistant in Jamf Pro 11.27, and add users from Jamf Account to Jamf Pro!Be sure to check out the Jamf Pro release notes for all of the exciting new features and enhancements.Thank you for your continued support and feedback!
The documentation from Cisco is pretty abysmal, it took me hours to finally make sense of it all. I made my own guide and an all-in-one config profile to use for deployment via Jamf. I hope this helps anyone in the future. https://scribehow.com/shared/Create_Cisco_Secure_Client_Jamf_Installer_pkg__ODli2lu5QiyylY4S5aCvMQ
As of macOS Sonoma 14.4 using "/System/Library/PrivateFrameworks/Apple80211.framework/Versions/A/Resources/airport --getinfo" no longer returns info about the active Wi-Fi connection. If you want to collect the active SSID for macOS 14.4 or later you can use the wdutil tool and here's an EA to do that: #!/bin/sh # EA - ActiveSSID # # Note: Using wdutil instead of networksetup so I don't need to know what # interface is Wi-Fi # Returns the currently active SSID activeSSID=$(/usr/bin/wdutil info | /usr/bin/awk '/SSID :/ { print $NF }') echo "<result>$activeSSID</result>"
Apple Intelligence is finally here now that iOS 18.1 and macOS 15.1 has shipped. However, many people and organizations want to know how they can block it.Apple Intelligence is an Opt-In service from Apple, so unless you Opt-In, there’s no concerns about AI, on or off device.Officially, Apple has provided the following configuration profile keys for the X.1 OSes for the preference domain com.apple.applicationaccess.allowWritingTools allowMailSummary allowGenmoji allowImagePlayground allowImageWandAnd DDM management of Math Notes.There’s also the key allowAssistant to disable Siri, which has become more intelligent with Apple Intelligence.Currently in the X.1 OSes, these are the features which are available and able to be restricted: Siri, Writing Tools and Mail Summary, even though there are controls for the other features not yet implemented.This will allow you to fully block those features. But is that it? …the answer is …No. So even if you implement all the Apple supplied restrictio
All the existing devices in our system stopped updating inventory on 21th-26th February. Any devices added since then are updating ok. How do we rectify this bug and what caused it? We cannot delete and start again on 200 devices.
Has anyone had to renew the built-in CA in Jamf Pro before and if so, mind sharing your experience with it? I'm primarily curious how many devices ended up having to unenroll and re-enroll as a result of MDM profiles failing to renew. With over 11,000 Macs in my environment, the suggestion shared by Jamf support by disabling automatic MDM profile renewals before renewing the built-in CA, then issue MDM renewal commands manually to no more than 100 devices at a time isn't realistic in my environment, especially when both the smart and the static computer groups aren't designed to group devices strictly by quantity into groups of 100 that easily.
We are deploying Xcode as a Mac App (VPP). Apparently after updates it is requiring admin creds to accept the End User License Agreement. I am stumped on how to fix this one. There’s not much I think we can do with Mac Apps.-Pat
Apple's Terms and Conditons have been updated ...
Hi everyone, we are currently exploring the Jamf Security Cloud and it’s capabilities with Jamf Trust app.So far we were able to create a connection between our Jamf Pro instance to Jamf Security Cloud, along with Entra ID for IdP integration.Current configuration deploys a Jamf Trust activation profile to end devices via Jamf Pro. However, I was wondering if the Jamf Trust app automatically gets installed via the activation profile. Or is there another process we need to configure to deploy the Jamf Trust app to end devices (for Mac and iOS). I would appreciate any expert’s opinion on how a typical Jamf Security Cloud and Jamf Trust configuration and deployment would get configured on end devices. Thanks in advance!
Hey all,Im using the JAMF Pro in house dock settings to remove apps though have hit a dead end with three Apple System Apps: Facetime, Apple TV and Apple StoreIm just wondering what is the best method for removing these last 3 from the dock. I have tried getting assistance from the JAMF Helpdesk and even with their assistance we were unsuccessful in finding the correct path to remove these with the in house option.If anyone could walk me through another method I would be very grateful.
Hi all, I have a policy running a script and restart options enabled. A restart message is also in place under “user interaction”. Everything is working fine so far. However, if the script is triggering an exit code other than 0, I want to stop the policy without restarting and showing the restarting window. Ist that possible? Or is there any workaround? Thanks, Stefan
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!