Get Support
Recently active
Hey Jamf Nation,Jamf is offering 10 individuals from the tech sector a fully sponsored experience at the Jamf Nation User Conference (JNUC) - happening September 23–25, 2026 in Kansas City, Missouri!🎟️ Here's what the sponsorship includes:• Full conference registration• Exclusive meet-and-greet with Jamf leaders• Networking happy hour with fellow recipients• $500 stipend to cover expenses• Access to social events and networking opportunitiesThe application deadline is May 1, 2026 at 5:00 p.m. CST. All applicants will be notified of decisions by July 1, 2026. Note: past recipients are not eligible to reapply.Apply here: https://www.jamf.com/blog/jnuc-diversity-sponsorship/Don't miss this incredible opportunity to connect, learn, and be part of the most connected community in high tech!❓Got questions? The folks behind it will be joining an open office hour session to answer any questions you may have about applying! The zoom room will be open for drop in for 30 minutes.When: April 16 Ti
Hoping someone can help as this has been making me pull my hair out.Running Jamf Pro with AD CS Connector delivering machine certs via SCEP. Macs are domain joined. Two SSIDs, one through Meraki APs with two NPS servers in the RADIUS config, another through a Cisco Z3 pointing to a separate NPS server. Same cert template, same Jamf profile structure across everything.The Z3 SSID works perfectly, Macs connect no problem. The Meraki SSID fails on every Mac. Windows machines on the same Meraki SSID and same NPS policy work fine.The CA is definitely issuing the cert, visible in certsrv. The Mac is also prompting to select a cert manually when it shouldn't be. NPS logs are completely silent, no 6273 events at all when the machine cert is used. The only time 6273 shows up in logs is when I manually pick a randomly assigned JAMF cert that belongs to a machine not in AD, and that's just "user account does not exist" shows up in my logs.eapolclient on the Mac shows the full TLS handshake comple
Hi, I have created a profile to only allow system settings and Pages apps. It worked as expected, but I keep getting the prompts below. Is there any way for me to disable them? Thank you.
Our desk side support manager is pushing for his team and the service desk to have full access to our console in terms of systems settings, creating/modifying groups, creating and modifying configuration profiles, creating and modifying policies ,etc. I am of the opinion that these are administrative functions which require some specialized knowledge and should be limited to administrators. Presently, they have access to view device information, assign policies, and push some MDM commands. I’m curious to know how your organizations manage access to the console. How many full administrators do you actually have in your consoles? What is your policy on tracking changes? What permissions do you give to your help desk and desk side support?
We’re moving away from Cisco Secure Client. But this utility is cool, and helpful. • A macOS utility to repackage Cisco Secure Client DMG files for unattended deployment via Jamf Pro (or any MDM solution).• huexley/CiscoRepackager• https://github.com/huexley/CiscoRepackager?utm_campaign=MacAdmins.news&utm_medium=email&utm_source=MacAdmins.news_385
Hello there!I’m using Jamf School synced with ASM with shared iPads. I wanted to start using Jamf Teacher app on teacher’s shared iPads, so I’ve just configured Jamf Teacher following Jamf’s guidelines. It started working fine with all classes and students showing up correctly. But since I needed to rename all classes. I renamed in ASM, synced Jamf School, and reassigned teachers to their renamed classes. But now I get this error on Teacher’s iPads “You are not allowed to add students to manages classes. Contact your IT administrator for support” (I’m IT support). Any idea how to resolve this?Thanks!
Apple Classroom on Teacher Macs in Jamf School - Possible without Managed Apple IDs?We're migrating from Jamf Pro to Jamf School. Previously had Apple Classroom working with Macs and iPads via ASM roster syncing from our SIS—no Managed Apple IDs needed.Current status in Jamf School:✅ Apple Classroom works on teacher iPads and student iPads ✅ Jamf Teacher app works on teacher Macs (shows rostered classes) ❌ Apple Classroom on teacher Macs won't load rostered classesTeacher Macs aren't receiving the Education Profile despite fresh enrollments. I suspect it's related to MDM-capable users, but can't confirm. Class data is clearly flowing (iPads get it, Jamf Teacher gets it), so it seems like a device-specific enrollment issue.Is Apple Classroom on teacher Macs possible in Jamf School without Managed Apple IDs?The solution seems tantalizing close based a on a checkbox still available in Jamf School - just that it only applied to pretty dated OS versions. Other 2 year old post
Hi everyone,We’re currently using Jamf School to manage our Apple devices and are running into issues with Microsoft’s enforcement of strong certificate mapping as outlined in KB5014754.Our environment relies on certificate-based authentication with Active Directory. While we’ve configured UPN mapping using the RFC 822 SAN field, our domain controllers (now in Full Enforcement mode) are rejecting certificates that don’t meet the new strong mapping requirements.Unfortunately, Jamf School doesn’t appear to support:Inclusion of SAN URIs with SID Custom certificate templates Scripting or automation for explicit mapping via altSecurityIdentitiesWe’ve temporarily enabled Compatibility Mode on our domain controllers, but this is only viable until 10 September 2025, when Microsoft will enforce Full Enforcement by default.Questions for the community and Jamf staff:Are there any confirmed plans for Jamf School to support strong certificate mapping before the enforcement deadline? Has anyone foun
Hello, I’m just getting started with SUPERMAN and have only done test computers and some alpha users. Right now I have mine very simple. I have JAMF API setup to run this so that the users do not need to have admin privleges.I have a PPPC Config Profile to enable this.I’m using Static / Smart Groups to target devices for deploying the Configuration Profile, and the Policy.The Configuration profile is the main area when I am configuring the Script behavior.Default Defered Timer = 30 minutesMenu Defered timer = 1hr, 2hr, 4hr, or 8hrSoft Count Deadline = 3And using a custom branding Icon. How aggressive have you been with your users to get MacOS upgraded? My experience so far is that users like to be on the latest OS and don’t mind the upgrde (even when it changes some of the appearance).Do you prefer Hard Count over Deadline Date?What messaging or communication do you like to do with the end users? We have a whole communication protocol in place, but I haven’t gotten any direction
In any technology job across industries there’s an evident gender gap. As a young professional, I was fortunate enough to find role models who shared their tips on claiming a seat at the table, which helped me overcome imposter syndrome. When I think about “men’s overrepresentation” in technology, I’m always reminded that community and networking is one of the most powerful tools to make your mark.I wrote this article to celebrate International Women's Day, but even better to bring up this topic in April. Celebrating women is never wrong to do beyond the month of March. I connected with leaders I admire in the Mac Admins space about the moments which defined their career, the advice that spurred them on to pursue their dreams, and the big wins defining their career so far. Kim Trojanowski, @ktrojano Systems Administrator II - School District of Waukesha & Admin - Women in Tech Apple AdminsJamf GroupThe “oh no” moment:It was my first day at a new job and I was shadowing my new co-
We’ve been using the jamf provided MakeMeAnAdmin shell script for temporary user account elevation without any issues for a while, but as of the last week or so it appears to have stopped working. jamf/MakeMeAnAdmin: Provides temporary admin access for a standard user via Jamf Self Service This has failed on two separate devices, one 26.2 and another on 26.4. When reviewing logs, it mentions a group no longer being found. I’ve looked around on Reddit and these forums and haven’t seen any other mentions of this issue recently, so figured it would not hurt to check in with the community. Typically we have been using the script via the Self Service app with no issues. I know Self Service + is coming fast - could this be related? Or is this just awkward timing on that front. We don’t use Jamf Connect, but putting a partial configuration for it and using the Self Service + app is successful in elevating the user temporarily to Admin permissions. It is just the standard method of Self S
Hi all,I’m looking for guidance on how to fully automate macOS updates across our company-managed Mac devices.We currently manage our Mac fleet using Jamf Pro version 11.24.1-t1769438062288. At present, macOS updates are being deployed manually through Self Service using packaged installers, but we would like to move to a more reliable and scalable automated process.So far, I have tried the following methods, but I have not been successful with either approach:Mass Action Command Managed Software UpdatesFor context, all company devices are:Enrolled via PreStage Enrollment Supervised Configured with Bootstrap Token allowed and escrowedIf anyone has successfully implemented a fully automated macOS update workflow in a similar Jamf environment, I would greatly appreciate your advice on the recommended process, prerequisites, or any known limitations.
Inherited a Jamf Pro deployment and looking to upgrade a piece of software that is being pushed out. This is what the policy looks like:GeneralEnabledTrigger: Recurring Check-InExecution Frequency: One per computerPackagePKG file, action InstallMaintenanceUpdate Inventory If I want to upgrade this with a new package, do I need a new policy with the same scope and disable this one? Or can I put a new PKG file in there?Thanks for any nudges in the right direction!
Hi Jamf Folks,I use nginx file distrubtion server. It works, but I have errors in the nginx log everytime I install something via Self Service +```2026/02/17 12:54:16 [error] 13387#0: *1 open() "/<pathToPkg>/Package.pkg/index.bom" failed (20: Not a directory), client: <ip-addresse>, server: webserver.de, request: "GET /<pathToPkg>/Package.pkg/index.bom HTTP/1.1", host: "webserver.de"```When I download it via webbrowser or wget, I do not get an error.here is my nginx.conf```worker_processes 1;events { worker_connections 1024;}http { include mime.types; default_type application/octet-stream; server { listen 443 ssl; http2 on; server_name webserver.de; ssl_certificate fullchain.pem; ssl_certificate_key privkey.pem; location /Packages/ { alias /<pathToPkg>/Packages/; auth_basic "Downloads"; auth_basic_user_file /<pathto>/htpasswd; types { appl
AI is changing how we work and it’s a huge area we’re all focused onOne of our engineers recently shared in an AMA some prompts customers are using with Ask Jamf right now:Help me identify OS versions in my fleet, highlight devices that can't be updated and need to be replaced. Can you explain how this policy and its script work? Survey our policies, profiles and groups and help write documentation. How do webhooks work in Jamf Pro? How do I get started with them? Do I have any configuration profiles that will conflict with this Blueprint?Now it's your turn, what prompts are actually working for you?Drop your best Ask Jamf prompts in the comments. I'll collect them and turn this into a community resource we can all learn from.Go 🚀 !
I am interested in how we can automate some reports or feed data into a SIEM like Splunk of Jamf Connect activity. The most important data point is when a user uses the privilege elevation feature. Does anyone have any experience or advise on this? Thanks in advance, -Pat
Shifting compliance checks left—giving control directly to end users via Self ServiceAs part of improving endpoint security and reducing operational overhead, I built a macOS compliance dashboard using SwiftDialog and Jamf, available to users via Self Service.This solution focuses on managing third-party vendor applications that are not updated through Jamf VPP/App Catalog or Installomator. These apps are maintained using internal PKG deployments, with the script enforcing organization-defined required versions.From an admin perspective, the key objective is to eliminate dependency on service desk tickets for compliance. Users can proactively check their device status and remediate issues themselves, without needing to raise a ticket.The script performs real-time validation of critical security controls such as FileVault, Firewall, SIP, and MDM enrollment, along with verifying that required security applications are installed and up to date.If any application is missing or outdated, re
Apologies if this is covered elsewhere and I’ve missed it!I’ve noticed that with the latest version (15.1.1) of Keynote, Numbers and Pages, the new version installs, and the old version remains. Using my Mac as an example, I currently have Numbers 15.1.1 and 14.6.2 installed. Trying to sort out a way to remove old versions from our Macs using Jamf Pro? I’ve tried a few scripts that claim to work even on Apple apps, but haven’t had any luck.
HiWe use Mac and Windows with Outlook in our schoolIn the group policy I can configure default fonts for Windows How can I configure Default Fonts for Mac for all the users in the organization Kind regards,
Am working on a project to migrate to Blueprints in Jamf Pro as much as I can and something I’m finding exceptionally frustrating is how to plan for future management of Apple Intelligence. We disable it by default for a host of privacy/protection reasons, but everywhere I look I see that the current tools will be deprecated (or were with 26.4) and there’s zero guidance on how to manage this going forward.Currently resorting to some Custom Settings payloads but am under the impression this will soon also not work after 27.0’s release. Couldn’t find anything searching the boards, but would love if I could get clarification from the community on if I’m correct or not in my concern or where to look for future-proofing.
Hey Jamf Heroes! I need some of that superhero good will.Going wide on my PSSO Pilot today. Testing went very smoothly, but we all know that sometimes the difference between dev and prod can be expansive.(Yes, I copied and pasted this from Slack. ;-)
I’m looking for a good printer for home use and would like some advice. I mainly need it for printing documents, school work, and occasional color pages. My old printer has been slow and expensive to maintain, so I’m thinking of upgrading.What printer would you recommend for reliable and cost-effective home use?
We set our users to be Standard users on their Macs, and which prevents them from being able to delete Wi-Fi SSIDs. Sometimes, we've needed to allow them to do so, so we have a script in Self Service that will delete a known SSID when run.#!/bin/sh ## Get the wireless port ID WirelessPort=$(networksetup -listallhardwareports | awk '/Wi-Fi|AirPort/{getline; print $NF}') ## Run a SSID removal if its present networksetup -removepreferredwirelessnetwork $WirelessPort "NAMEOFTHESSID" 2>/dev/nullBut we've run into a situation where a work-from-home user wants to delete an SSID from their home network, etc. I was wondering if there's a way to a have a script that would allow the user to choose from existing "preferred wireless networks" SSIDs and choose which one to delete? That way, we could just have one "Remove Wi-Fi Networks" item in Self Service, and users could remove whichever one they want.
We would like to restrict our admin user from installing any applications via installer files (pkg or dmg) on their Mac. There is a functionality in the configuration profile under Restrictions that allows us to check "Restrict the App Store," but this only prevents users from opening the App Store. They can still download package files from the web and install them. Is there any way to restrict admin users through a script or configuration profile?
Today we released Jamf Connect 3.8.0; this release addresses the following product issues:[PI-995] Fixed: The Jamf Connect login window presents the following error after a failed ROPG password verification: ERROR: Unknown error. Message: The credentials provided were invalid., STATUS: 400. [PI155825] Fixed: Jamf Connect configurations with Okta Identity Engine as the identity provider fail to use the preferred_username attribute during user creation, causing the user to have the incorrect login information assigned to them. To access new versions of Jamf Connect, log in to Jamf Account with your Jamf ID. The latest version is located in the Solutions section under Jamf Connect.Product DocumentationFor additional information on what's included in this release, review the release notes via the Jamf Learning Hub.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!