Get Support
Recently active
From mid-November through the final weeks of the year, many IT teams shift into a different rhythm. Projects wrap up. User demand slows. Emergency tickets still happen, but the pace usually lightens. This quieter stretch creates one of the best opportunities to build new skills, strengthen existing ones, and earn certifications that keep you growing. Technology does not slow down when the calendar does. Platforms update, security threats evolve, and new tools enter the stack faster than most teams can adopt them. Staying sharp takes intention. If you wait for the “perfect time” to learn something new, it rarely comes. But late Q4 offers a natural runway that is easy to miss if you are not looking for it. Using this time for learning sends a clear signal to yourself and your team. It shows that continuous upskilling is not a checkbox, but a habit. Whether you manage devices with Jamf, work in security, support end users, or build infrastructure, the problems you solve tomorrow will n
We’re a year into Apple shipping Apple Intelligence (though technically still in Beta) but Apple hasn’t shipped a clear matrix of which features are on-device vs. require Private Cloud Compute (PCC). If you haven’t read part 1, then click here and go back and read it. And then follow up and read part 2, by clicking here. But what if… all that information was hiding on your very Mac in a system diagnostics, your Mac quietly generates a Model Catalog inside sysdiagnose that lists feature availability, languages, and — critically — which resources are server-side! For those that do not know, you can run a system diagnostics and explore the zip file created to potentially find some interesting tidbits about your Mac.Open Terminal.app and typesudo sysdiagnose -f ~/*** Disclaimer, system diagnostics bundles can potentially contain sensitive information *** Follow the prompt and this will create a system diagnostics zip bundle eventually in your home directory. Double click the zip file crea
🎉 Happy New Year! 🥳 It is traditional to use the beginning of the year to make plans. Conferences and the associated travel require quite a bit of planning. I keep an overview of the larger conferences in the Mac and wider Apple management and security community on my website, but thought a bit of a more detailed overview might be useful.Whether you want to "just" attend or even hand in a proposal for a talk, here is a list of conferences this year with links to their websites. MacAD.UK: Brighton, UK, April 21–22This conference in Brighton on the British coast, south of London, has been bringing together Apple management professionals from the United Kingdom and all over Europe for several years. This year, they are moving to a new venue in Brighton. ACES Conference: Minneapolis, MN, USA, May 12–13ACES focuses more on the business side of providing IT services in the Apple space and as such, is quite interesting for partners and service providers. This year, they have a new track ded
As part of Apple’s unveiling of Declarative Device Management (DDM) at WWDC 2023, Apple announced that DDM management included the ability to deploy MDM configuration profiles using DDM as the delivery mechanism in place of using MDM to deliver the profiles. Jamf Pro’s Blueprints leverages this capability to support device restrictions. Let’s see how this works using a device restriction configuration, using the example of setting the following Apple Intelligence management functions to false in order to block the corresponding Apple Intelligence functions on macOS:For more details, please see below the jump.As of Jamf Pro 11.18.0, there is not a Blueprints template available for creating blueprints which manage device restrictions so the blueprint will need to be configured manually. To do this, use the following procedure:1. Log into Jamf Pro.2. Select Blueprints3. Click the Create blueprint button.4. Give it a name when prompted and click the Create button. For this example, I’m usi
Earlier this week, our Community team brought members of Jamf Nation together for a special event — an hour of inspiration, celebration and gratitude. World-renowned keynote speaker, author and all-around good guy, Chris Schembra, led the conversation: Jamf Nation 2026: The Power of Human Connection. As the largest online community of Apple admins in the world, Jamf Nation members understand the power of connection. They’ve been using it to move mountains in the Apple space for the better part of two decades. But as the environment around us changes, Chris challenged the group to consider mindset shifts that could lead to even better outcomes. He encouraged them to move both fast and slow, referencing the Emilia-Romagna mindset of “holding the tension of opposites to achieve world-class excellence.” He asked, Where in your life do you need to go slower? Where in your life do you need to go faster? How do you hold the tension between those two? The chat lit up. Thoughtful, deeply mea
It must be 8 or 9 years ago that I started supporting customers with ZuluDesk (now Jamf School). This was my first step into the device management world. Before that, I was a repair technician. As my curiosity grew, I was lucky enough that my employer allowed me to do the Jamf 100 and 200 courses. Managing iOS devices is all good and well, but with Mac you need a little more tools. Things like setting a wallpaper sound easy, but they actually require a bit more work than I expected. Welcome to the world of Mac Admins! I discovered that for everything I wanted to figure out how to do, there is usually someone with the same question, and maybe they’ve already found a solution for it. Coming in as a completely new Mac Admin, it might be a bit difficult to find your way. But knowing the right people, tools or places to ask for help are really valuable and make all the difference. So I thought, why not try and create some sort of list with starting points for f
Enrolling in a Jamf Training Course is an exciting step in expanding your skills, but once your class is scheduled on the calendar, you might wonder: How should I prepare for training? What devices should I use? How should I set up my workspace? While Jamf will send you important setup instructions prior to your course beginning, here are additional preparation steps and strategies you can take to ensure you’re fully ready to succeed. 1. Review the Student Setup GuideOne week before your training begins, you will receive an email from Jamf Training with important details about your course. This email will look like the following: This email will contain:Instructions to log into Jamf Account to view customer requirements and prerequisites A link to access the remote training session the following week A link to the Student Setup Guide A contact for your instructor. If you have questions, you can reach out to them. The Student Setup Guide is essential. It outlines:Device Requirements R
Originally posted in MacAdmin Musings Why I Try to Stop Working Before Everything Is Finished For a long time, I treated the end of my workday as a finish line.I’d keep going until the problem was solved, the task was complete, or I was too drained to continue. If something was still broken or unanswered, I felt pressure to push through it before logging off. Ending the day with loose ends felt like failure, like I wasn’t completing my tasks.Over time, I realized that approach was quietly working against me.Not because unfinished work is bad, but because how you leave work unfinished matters. The Hidden Cost of Draining the Tank When you work until you have nothing left, you don’t just end the day tired. You also make tomorrow harder.The next morning starts cold:You have to remember what you were thinking You have to reconstruct context You have to re-load mental state before you can make progressThat ramp-up cost is real, whether you’re writing small scripts or a large project. Moment
Jamf Pro has superior automation and scripting tools. Jamf School has a simple interfaces and blueprints. Do you feel the loss of customizable security features and scripting is worth the trade off for the tools given by Teacher and Student apps?
Hello all you IT Rockstars! I’d like to get some of your thoughts on Patch Scheduling. Since there are so many tools available to use with Jamf Pro, it really gives us a wealth of options for customizing. What and When:The way I look at things, there are 3 basic categories of patching urgency on macOS.Feature: Non-Security OS Patches, New macOS versions, and specific software that is a deliberate manual rollout. Example: corporate VPN software. This is something that we would want uniform version across the fleet. These are planned and don’t have a standard cadence.Critical: Security OS Patches, Zero-day patches, and other applications that the security issue addressed by the patch is important to your organization. I am thinking of having these install once a week, short deferral period, force update within 24 hours.Routine: Basically, all other application patches. I am torn between doing these on a weekly basis with the critical patches, or draw th
Starting in March, you will no longer be able to log in to Jamf School using a Jamf School account. Instead, you will need to log in using Jamf ID or single sign-on (SSO) through Jamf Account. Note: This post will be updated when a specific date for the change is determined. To receive updates for this post, click Subscribe. What you need to know: ✓ Already using Jamf ID or SSO through Jamf Account to log in? You are good to go—no further action is needed. ✓ Don't have a Jamf ID yet? Create a Jamf ID now, or wait and one will be automatically created for you in March. If a Jamf ID is automatically created for you, your Jamf ID credentials will match your Jamf School account credentials. After your Jamf ID is created, you can log in to Jamf School by navigating to your Jamf School instance URL (e.g., "yourdomainname.jamfcloud.com") and using your Jamf ID credentials. ✓ Two-factor authentication (2FA) changes: SMS based 2FA will no longer be supported. 2FA through a third party app will
Hey Jamf Nation,Your favourite time of year is just around the corner...the JNUC Call for Sessions! 📣This year, we’re doing something a little different for our Jamf Nation community. We’re bringing the inner workings of JNUC and the session selection process straight to you!Join us for a live session with two of our very own JNUC session team, where we’ll cover:• Tips and tricks for submitting a standout JNUC session• The 2026 subject themes• When the Call for Sessions officially opensWe’ll also hear from a community member and past JNUC presenter, who’ll share how their session idea came together and what they learned along the way. 🗓️ Date: Wednesday, February 25⏰Time: 9–10 a.m. CST / 10–11 a.m. EST / 8–9 a.m. MST / 7–8 a.m. PST / 3–4 p.m. GMT / 4–5 p.m. CET / 8:30–9:30 p.m. IST / 11 p.m.–12 a.m. SGT / 12–1 a.m. JST+1🚨 REGISTER HERE ➡️ https://jamf.it/JamfNationEvents Have a question for the team? Add it to the thread below!Don’t forget to register! See you soon!
I need to use the JAMF School API to retrieve a list of devices. When I call the /api/devices/ API in PowerShell, it returns *all* the devices as part of the JSON response - which could run into many thousands. That’s a response size of tens of MBs, probably larger.This could cause problems with the code and the memory of server on which the script is running. I don’t see a way to paginate the response. Neither the documentation nor the Postman project have any information about paging the response to keep the response to a reasonable size.Am I missing something in the documentation that could allow me to paginate the response? Or is there another API that I can use to retrieve devices in smaller sets?
Is there a way to disable iPad access during certain hours of the day?!--a=1-->
Hello all, Does anyone know how to build a Static Computer Group from a list of computers? It doesn’t matter what the list format is. That should be simple enough to reformat. Any help or ideas are appreciated.-Pat
A workflow improvement to Import would be to have a default assumption that if the Asset Tag is already defined and is blank in the device CSV that the system maintains the same asset tag.Currently if you fail to enter the asset tag on a subsequent import, the data is wiped. If you are rapidly setting up classes, you may not have the asset tag information - you have the serial number and the student details. Finding it again from previous data and then adding it to a device placeholder adds unnecessary time to the process. In the cases I’m working through, the system already knows the asset tag, and it hasn’t changed - and it won’t change for the life of the device.If the asset tag should be reset, allow a character like dash - to signify please reset / delete the asset tag.
I received this feedback from one of our teachers testing out Jamf Teacher- When I take control and lock them in an app, it literally clears their ipads from all other apps. Which is great! Except when I clear the locks on my end, all of their apps end up in different locations on their device. So I had a few angry students that spend hours organizing and categorizing folders and apps then suddenly I come along and clear things and then their apps are all messed up and scattered. That isn't a nice feature of this app for sure. I get it. I love having my iPad organized by apps I use and in folders. It's a shame that this developer didn't think of that aspect of things when designing the app. Just a little feedback for you. Are others experiencing this?
I am a Jamf Pro customer and think Jamf Teacher has great potential! However, our teachers are struggling to fully integrate it because of some missing key features. 1.) We are not enforcing the home screen layout payload so students can customize their iPads and organize their apps in a manner that works best for them. After restrictions are cleared, their apps lose their organizational structure and end up anywhere on their iPads. Apps that were in folders don't stay in those folders. 2.) Lack of status window/confirmation pop-up to see when you have a lesson in progress or have issued a command to student iPads. Teachers would like more visibility/confirmation as they issue commands and place restrictions.
Since November 2025 you can find the warranty information for your Mac devices in Apple Business Manager. You can call this information using API calls. Is there any information if Jamf is going to make an Jamf integration? This warranty information would be a cool feature to have in Jamf. As an MSP it would be great for Life Cycle Management for our customers.I’ve seen no information from Jamf jet.Sofar I've been working on local scripting in python to get the ABM warranty information in Jamf as an Extension Attribute. For Computers I've succeeded I'm however not successful yet for mobile devices. The Jamf Classic and Pro API’s won’t let me update Extension Attributes for mobile. So I'm stuc.Anybody there who would like to help? Or can somebody tell me how to update an extension attribute for mobile, if it is possible and not blocked in api.Kind Regard Remco.
We currently have the “Erase All Content and Settings” option blocked on our student iPads. However, we would also like to block the “Transfer or Reset” option, or at least the “Reset All Settings” option, on those devices.Is this something that can be configured? Thank you
Hello all,I just started with an existing system that isn’t really documented. This means I have to do a lot of jumping around to determine what something does, where it applies, and even if it is working. I want to create some good documentation for this, but I’m don’t know what the best method for doing this would be.Thank You in advance,-Pat
We manage our ipads using Jamf Pro. We load the students google email accounts onto the device using a Jamf configuration profile with the Google payload. The mail account will appear on the device (ipad iOS mail app) and prompt user to enter google password. The user enters the password and the iOS mail app will display the students google email. However, several times through out each day, the iOS mail app will stop displaying google email and prompt user to re-enter their google password. After re-entering the google credentials, the Mail app will not always start working again. I have had Jamf support review our config file with the google payload - they said it is set up correctly. I have contacted Google and they said that it is a Jamf issue. Has anyone else experienced this issue? How did you resolve it? thanks.
Howdy everybody! Time for my annual post about how we all need to get our budgets prepped and ready to go for all the hardware we need to replace that Apple is dropping from its OS Compatibility list!I've modified my previous regex statement to take out the models that were lost to us this year to the latest macOS version. It looks like Apple is taking a big ole axe to the intel macs, minus only a couple of exceptions that seem to tie to the devices that were still being sold at the time of the M1 release. One tricky piece are the specific intel MacBook Pro's that Apple has listed. In that grouping are the MacBookPro16,x models, where x is 1,2 and 4, but not the 16,3 model, so keep that in mind. If anyone has details that contradict that, please let me know here and i'll quickly change the posted regex.I've tested this in my own Jamf instances to verify its returning the data that i'd expect to see, and am confident this will be able to match everything that is no longer supported by M
Issue: Mobile Devices on iOS and iPadOS 26 or later Booting are occasionally booting into Recovery Mode. Standard expected workflow: We have Microsoft Entra ID SSO extension configured with the Jamf Setup and Jamf Reset apps. When a user signs out using Jamf Reset three different configuration profiles are removed:Profile with a Passcode payload Profile with a Restrictions payload Profile with a Lock Screen Message payload When the above profiles are removed, two profiles are installed:Profile with a Restrictions payload Profile with a Lock Screen Message payload The issue appears to occur during Jamf Reset sign out as one configuration profile is removed (confirmed by completed command logs) and can vary between the Passcode payload profile or the Restrictions payload profile while the other two commands are left pending.Example pending commands that occur at the time of issue:Clear PasscodeEnable App StoreProfile ListCertificate List I have not been able to reproduce the issue on tes
After poking around Jamf Pro and Jamf Protect, it seems that JSC/RADAR/Wandera is the only source of storage for CVE-level details for managed client app inventories. I can plainly see them in the default web dashboard. So I set up a Risk API key, and enabled the option to see user and device details.Both the docs [1] and manual exploration seem to conclude that only “Device risk” can be gathered from the public API, whereas things like “Average CVSS score” (or anything related to CVEs) cannot. Which would be fine if those two had a tight relationship, but I can plainly see things like an endpoint with six (6) high-scoring app vulnerabilities (including a 10 and a 9.8) per CVSS that only has two (2) app vulnerabilities reported per device risk and grading overall as low-risk.I did notice that app vulns as a category can be force-upgraded from low to high to influence device risk more, but it’s possible that device risk will entirely miss the presence of vulnerable apps and this still d
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!