Get Support
Recently active
Hi all, I have a policy running a script and restart options enabled. A restart message is also in place under “user interaction”. Everything is working fine so far. However, if the script is triggering an exit code other than 0, I want to stop the policy without restarting and showing the restarting window. Ist that possible? Or is there any workaround? Thanks, Stefan
Hi everyone, we have recently bought a Brother MFC-L2800DW type printer and I was wondering what would be the steps to deploy it and configure it. It will be our first printer installation so we are very new to the process. CUPS and IPP and PPD shows up in many places.We want this printer to be a network attached printer and I think we need to also deploy a driver as well, I am assuming. I would appreciate any expert’s opinion on what would be the default way to configure a network attached Brother printer. Can we use macOS built in generic PPD file? Or We need to deploy something frmo Brother printer’s end? Thanks in advance.
We are a K-12 school district migrating from Jamf School to Jamf Pro I have already rostered our students and classes.Only able to begin device migration after school ends. As there can only be one MDM to rule them all. And our students and staff are still using Jamf School.I am starting to build our our profiles.I noticed that you must create separate profiles for iOS and MacOS. No way to share profiles between them? I was just thinking it would be nice to share for wifi/networks and what not.Working on trying to get our macOS profiles for wireless working after a device wipe.It does not seem to be working. Which will mean we have to hardwire these devices. Has anyone got this working. I have added the profile to the pre stage. But like I said, it doesn't seem to work on return to service.They Does any have some important tips, blockers and solution they would be able to share?
With the recent release of the M5, we’ve been trying to connect MacBook Pro’s to our 802.1x secured Wifi Network.We’re using the same configuration profile that has worked on the rest of our fleet. Our network team have looked at the logs and have determined the issue is on the endpoint side “WLC keep sending EAP-TLS request and no response from client”.Wondering if anyone else has encountered this issue and what if anything was done to fix it.Thanks
Since NoMad has stopped working with the new macOS 26, we are looking for its replacement.We tried implementing JAMF Connect, but since we use ADFS, JAMF Connect is not compatible.Can anyone suggest any other replacement for NoMad, which can work as a password sync between Mac devices and our Entra environment.Thanks
Today we're opening the public beta of the Platform API Gateway – a single, unified way to access any combination of Jamf APIs, current and new. You manage all of it from the new Integrations space in Jamf Account.Jamf is no stranger to integrations. The Platform API Gateway takes that further – one place to manage access, one consistent way to authenticate, and a growing set of APIs that cover the full Jamf platform. Unify your workflows, reduce friction, and realize the full value of your Jamf journey.As Apple continues to grow in the enterprise, the way organizations build, automate, and integrate is evolving too. Workflows are becoming more extensible, more autonomous, and more agentic – and we want Jamf to be the foundation customers and partners build on to get there. The platform that manages and secures millions of Apple devices worldwide is opening up fully – rooted in what you know, built for what's next.This beta is the first step.What's available in the Platform API Gateway
I was creating a configuration profile to setup a webclip that redirects to a URL. I accidentally put a name for the bundle ID: com.apple.webapp with an XYZ name and now Jamf has made that association and has changed or plugged in that XYZ name into all my other profiles that have that bundle ID. This created a bunch of orphan icons on a test device I was working on. How do I remove remove that? I am working to remove that bundle ID in all my Restrictions profiles, and will have to reset my devices. SOS! I am new to jamf, so def learning as I go.
I am having hard time deleting smart user groups, I get the spinning wheel when I click on delete. The groups are empt. So annoying!
Hello, I’m hoping someone has some insight into this issue. I have two internal distribution points that run on Mac minis. They have both been up and running for several years. Recently, one of them stopped working after I renewed the SSL certificate. I accidentally let the certificate expire by less than a day. Now, after renewing the certificate, I can’t get it to serve files over HTTPS anymore. Here’s what I have done so far:- Renewed the certificate several times- Verified that the certificate information is correct and matches what is listed in Jamf- Verified that the setting in my httpd.conf and http-ssl.conf files- Restarted Apache (multiple times)- Restarted the DP that is not working- Compared the settings of the DP that is working with the one that is not-re-entered the password for the jamfread account in Jamf and on the passwords file on the DP- Pasted the link for one of the files that fails to download into a browser window and confirmed that I can access and download th
Apple Business Manager is now just Apple Business.Remember to log in and agree to the new terms and conditions so that devices can continue to be added.https://business.apple.com/
Does jamf offer a better setting for how to find the Approximate location of the device (iPad) on the Jamf School system. Other MDMs show the location much better. Is there something that I am doing wrong? Please advise.I am using Jamf School.
I just got to 250+ “bytes”! That XL Gamer Desk Tech Mat is so close…I am dangerously low on swag. Seriously, I only have the jamf shirt I goyt when I got my CCT.-Pat
I am seeing a Keychain not found alert after I recently started enforcing OneDrive Desktop and Documents sync. This just happened on my newly enrolled test Mac after I registered platform single sign-on. The alert appeared as I was logging in to OneDrive. There is actually an entry in Keychain. I looked up the ID shown in the screenshot. Reset to Defaults is NOT the right choice. I found that unlinking the Mac from OneDrive and then signing in again helps, but this prompt came up as I was in the process of logging in. We use platform single sign-on so there is no password prompt. Has anyone else seen this and solved it?
Hi Guys,We are facing very weird issue at our Orgs, where none of the packages are getting installed during enrollment for some devices. The issue is not for all the devices, and usually for few devices but been having this issue once in a while.All the packages are signed, and works perfectly fine for most of the device. And for god sake, we cant replicate this issue whenever we do a testing.Those devices who have issue with package installation, usually works once wiped and re-run the enrolment process.Does anyone have idea on how to get this sorted?
Not sure if I am the only one experiencing this or not. We are using code 42 and some users folder /Library/Application\\ Support/CrashPlan was deleted. The app cannot be removed because it is locked and the uninstall script cannot be run because the aforementioned folder has been deleted. We also cannot reinstall the backup agent as we get a "Install failed contact the software manufacturer" error message. Has anybody experienced this and found a fix? I tried using the uninstall script from another computer but it failed saying that the script is not originally from the computer.
New and somewhat confused JAMF-user here, and thus: silly questions.I'm using Entra as my Cloud Identity provider and I'm trying to create a smart user group based on membership in an Entra-group (JAMF_KLA) in order to build configurations for said usergroups. But I cannot for the life of me get it to work (nor do I know if it's actually possible).Looked at the mapping of both the SUG and in the CIP-setup, and everything there looks like it should work. Can also do a test against various users, and it works (User that is in the Entra-group gets green checkmark, user that is not in group gets red checkmark). Which tells me that the lookup is working.I see that I can also add users from a Directory Service from the Settings-menu. However, is that only for admins/auditors? I see that there's an option for Enrollment Only. Does this mean that the imported users do *not* have access to the JAMF-console?
Jamf is thrilled to announce the brand-new Jamf 140 Course; a free, self-paced course that builds foundational skills to manage, secure and deploy Apple devices in K-12 environments.Check out the blog post about the 140!
A complete, step-by-step deployment guide - including macOS Onboarding and Jamf ConnectAuthor: Meir ElimelechWith contributions from: Omer Ninyo / @Ninyo Why this guide exists – and who should read it Jamf’s move to make Self Service+ mandatory for macOS has prompted many organizations to re-evaluate their deployment and enrollment workflows. While Jamf’s documentation covers the supported installation and migration paths, real-world environments often include a mix of enrollment models, identity integrations, and timing-sensitive workflows that are not always addressed in isolation.This guide exists to provide a single, practical reference for migrating to Self Service+ across all common macOS scenarios — from brand-new enrollments to existing fleets, with or without Jamf Connect.It is intended for Jamf administrators, partners, and consultants who want to understand not only how to deploy Self Service+, but when different approaches are appropriate. In particular, it highlights a cr
Hey, So, after lots of tests and struggling with new ways to migrate DMG file to PKG I found that none of them really works and the agent never starts and works properly... I found this script (don't remember where) and this solved my issue! ``` !/bin/sh Downloading OSX Update Package to /tmp on the host curl -o /tmp/update.tgz http://YOUR_SERVER_NAME_OR_IP/SC_packages/update.tgz; sleep 3 Extracting update.tgz to /tmp tar -zxvf /tmp/update.tgz -C /tmp; sleep 3 Installing SecureConnector as a Daemon/Dissolvable w/ visible/invisible menu bar icon sudo -S /tmp/Update/Update.sh -t daemon -v 1; sleep 3 Checking/Starting processes in case they did not start on install daemon_pid=ps auxww | grep -v grep | egrep "ForeScout SecureConnector.-daemon" | awk '{print $2}'agent_pid=ps auxww | grep -v grep | egrep "ForeScout SecureConnector.-agent" | awk '{print $2}'daemon_plist=/Library/LaunchDaemons/com.forescout.secureconnector.daemon.plistagent_plist=/Library/LaunchAgents/com.forescou
School admins want us to set a restriction for students to not be able to use their iPads past 10pm. I asked Jamf AI but we currently don’t use Jamf Parent, nor Jamf Teacher. It also gave the option of using Screen Time Downtime, but when creating that Config profile, I don’t have that option available to me. Has anyone had any experience in doing this?
Soooooo with the new “Apple Business”, check out the new API endpoints!!https://support.apple.com/guide/business/create-an-api-account-axm33189f66a/1/web/1I’m drooling at the user options for scoping purposes. Been waiting forever for these to appear 😍
Hello,Google is our IdP for logging in to Jamf Connect Login. I am using Self Service+ which states that the local password is “In Sync”. If I change a users password in Entra (which then will sync to Google Workspace), the “in Sync” does not go away or update ever. If I were to reset the password locally though Self Service+ using the menu bar drop down (opens Entra password change portal) it then states that the password is out of sync and that I need to login again to Self Service+. Great! I login, it accepts the new password, and states that the password is “in Sync”. I am never prompted for the old password.If I log out of the user and log back in with the new password, I am successful at the Google SSO pane, but it then has a smaller Jamf Connect pane that asks for valid credentials, which is the previously set password. The local password will not update despite “being in sync”.I have to be doing something fundamentally wrong, any help would be really appreciated.
Hi Jamf Community, We're experiencing an interesting DNS registration issue with our Mac fleet that I'm hoping someone might have encountered before. Issue Description When our Mac devices connect to our corporate WiFi network, they register in DNS (Infoblox) with generic names like mac.domain or macbook.domain instead of their proper hostnames (e.g., mbp-dav.domain). However, when these same devices connect via Ethernet cable, they register correctly with their actual hostnames. Environment Details DNS/DHCP: Infoblox Mac devices: Various models running macOS All Mac devices have proper hostnames configured What I've Verified I've confirmed the hostname settings are correctly configured on the affected devices: scutil --get HostName mbp-dav.domain scutil --get LocalHostName mbp-dav.domain scutil --get ComputerName mbp-dav.domain System preferences show the hostname is correctly set in the Mac'
I have written a long time ago and still use an Automator workflow which runs an AppleScript which front-ends the built-in ZIP command line tool. Its main purpose is to provide a means to generate password protected ZIP files. The built-in 'service' does not give this option even though I suspect it also frontends the same built-in ZIP command line tool.This workflow for me still works fine even in macOS Sonoma.It used to be (back in the good old days 😁) that installing an Automator workflow was literally a simple matter of copying it to either -/Library/Services/ (to make it available to all users)or~/Library/Services/ (for an individual user)These days it is a lot more complicated.You still need to copy it to /Library/Services/ but you then apparently need to open it in Automator, re-save it in the same /Library/Services/ location which appears to cause Automator to register it in the list of available services - this of course requires using an Administrator authen
Hello Jamf Nation! Last month, we were excited to share the Get Started with Scripting series in the Jamf Online Training Catalog enjoyed a full refresh, covering topics from Terminal fundamentals to the Jamf API. Now, we’d love to hear what you think!Whether you’re just getting started or have already earned your Command Line Innovator badge, we’ve put together a quick, three-question survey for you to let us know how we can continue to serve you in your learning journey. Have questions? Let us know in the comments below.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!