Get Support
Recently active
Using Escrow Buddy. Its rotating keys as expected, but the keys are not working to unlock the disk. I have run sudo fdesetup validaterecovery and it returns with false. I re-run the Escrow Buddy policy and get a new PRK, still says the new PRK is false. Anyone experience this? It seems like no matter what, even though Jamf is saying the PRK is Valid, its not escrowing properly.
We launched Phase 1 of our new Jamf Learning Hub today. In addition to a cleaner layout and crisper learning experience, we now have a better performing and more extensible platform that gives us the foundation to deliver the new features you have been asking for.A few things to know as you explore the new Jamf Learning Hub:📌 BookmarksIf you had pages bookmarked using the Jamf Learning Hub bookmark functionality, you'll need to re-save them: Sign in to the Jamf Learning Hub. Go to the page you want to bookmark. Click the button shown below. Change the name for the bookmark if you like. Click the Save button. If you had bookmarked pages using your web browser bookmark functionality, you will not need to re-save those as we have redirects in place.📄 Creating PDFsThe PDF process has a new flow: Click the button shown below. Select Print this topic. Choose the topics you want to include from the publication and click Print. Set your Destination to PDF and click Save
Hello all, Today and last week Friday, we’ve been seen users get the Jamf Connect Keychain pop up. Computer will show JC 3.5 is installed and it’s getting the latest Self Service + and the popup reoccurs on restart. I’ve opened a ticket but wanted to reach out here and see if something clear and apparent is happening.
Hello All,We’ve just started to implement Jamf Pro in our company. Nearly all configurations are completed except sending compliant information to Microsoft Intune. We have to do this because we’re using Azure (Entra) Conditional Access rules in our company. If a macOS device is not compliant it cannot reach internal company resources. Just a simple rule. Steps CompletedJamf <> Intune compliance partner connector connected successfully. Microsoft Device Compliance configuration policy prepared in Jamf Policies -https://learn.microsoft.com/en-us/intune/intune-service/protect/jamf-managed-device-compliance-with-entra-idProblem SummaryAfter enrolling to jamf, we are trying to sign in to Company portal and jamf compliance popup appears. Then we are entering our user account details again but somehow Microsoft login page shows that “get app”. It behaves like Company Portal is not installed. Briefly some of our computers are being Compliant without any problem, but some of others canno
Hi everyone,I'm working on upgrading our Mac fleet from Jamf Connect 2.39 to 3.7.1 and running into some cleanup issues I'd love some guidance on.Environment:Jamf Pro 11.26.1 macOS 15 Sequoia Apple Silicon and Intel endpoints Devices enrolled via Apple Business Manager (ABM) using Automated Device Enrollment (ADE) Identity Provider: Azure AD / Entra IDCurrent situation: All of our managed Macs have Jamf Connect 2.39 installed. I have already built and validated a Jamf Connect 3.7.1 configuration profile in Jamf Pro and scoped it to a handful of test machines successfully.The problem: When pushing JamfConnectLogin.pkg (3.7.1) via policy, it does not remove or replace the existing 2.39 installation. After the policy runs I can confirm:Jamf Connect.app (2.39) remains in /Applications The 2.39 menu bar app is still present and running JamfConnectLogin.bundle does get updated to 3.7.1 via the pkgI also want to note that sudo is restricted on our endpoints via BeyondTrust Privilege Managemen
Hello,I have multi-user workstations on which I do not have FileVault activated so as not to have a problem when connecting a new user with Jamf Connect. Unfortunately, the TAHOE update automatically activates FileVault and suddenly at the start of the station an account is requested that can activate FileVault before having the Jamf Connect window. How can we get around the problem or how can TAHOE not activate FileVault?
As a Jamf trainer, there are two questions I’m asked time and time again:How much scripting is involved in the Jamf certification courses? How can I prepare before attending a remote instructor-led course?If you’re planning to take a Jamf certification course and want a clearer idea of what to expect, and how to set yourself up for success, this guide is for you.The Jamf Pro Training PathThere are three core Jamf Pro instructor-led courses, each designed to build on the previous one as your skills develop:Jamf 200 – Core understanding of Jamf Pro, as well as an enterprise-focused examination of the macOS and iOS platforms Jamf 300 – Deeper understanding of the macOS and iOS management capabilities within Jamf Pro Jamf 400 – Automation and APIsLet’s take a look at what scripting knowledge is expected at each level, and how you can prepare. Jamf 200The Jamf 200 course provides a solid introduction to Jamf Pro, along with an enterprise-focused overview of macOS and iOS device management.
I have had success with scripts to insert the auth code for SPSS in past but SPSS 30 will not apply code through script. Popup still comes up. Script that used to work was this one. I have tried few option using the SPSS instruction manual but no success. What's working for you all?
Reading over the Jamf documentation it’s not clear how to schedule MySQL backups using the Jamf pro server tool cli on windows when the DB is on its own server. I have Jamf server tools copied over to the DB server and I see you can set a schedule in the config file but that will not actually do anything since jamf-pro is not running on this server. It says you can use Schtasks to schedule this but what command do you put in the schedule task? jamf-pro database backup ?If i do it this way should I have no schedule task in the config? Also what account does this need to run as?
Like many of you, part of my job involves erasing and reimaging test machines over and over. This morning I attempted to do something I've done hundreds of times before - erase the drive on my M4 Tahoe test machine and reinstall Sequoia. This time, Sequoia is not available, only Tahoe.It's possible Apple may have restricted the Sequoia installer from Tahoe machines, much like they did with the iOS 18.x installers on iOS 26.x devices.I wanted to get word out there as a word of caution.
BLUF: ASM shows 314 devices assigned to our Jamf Pro (cloud) server, but Jamf Pro is stuck at a 255-device count, preventing macOS Tahoe's native migration lockout from triggering for 50+ migration targets.Hi everyone,I’m running into a sync issue between Apple School Manager (ASM) and a new Jamf Pro instance. For backstory, we are migrating from several independent Jamf Cloud installs to a centralized version. While many of the devices will need to be manually touched, I have more than 50 that can be migrated between Jamf instances. Those devices are on Tahoe, have a T2 chip on Intel hardware or are Apple Silicon, and are DEP enrolled with a valid MDM Profile (not expired) on the legacy Jamf instance. I successfully migrated a separate Jamf Cloud instance into our new, centralized Jamf instance using ASM just a week ago, so the process has proven valid.Currently, ASM shows 314 devices (all endpoint Macs save for 5 iPads) assigned to our MDM server via Device Management Services. Howev
My Jamf Connect environment is interfaced with Entra ID. In our testing and pilot phases the deployment went well. However, now that I’m deploying to production we’ve had a sporadic issue where the Jamf Connect login window will claim that the network password doesn’t match the local password and also temporarily locks the account. The user might have to reboot and try again to get it. Anybody else deal with this?
Hi All,AD bound Mac’s with macOS Tahoe 26.4. When a new user login I got “Sign in to Your Apple Account” and “Age Range” message , any idea how do disable these?thanks
Today we are releasing a maintenance version of Jamf Pro; highlights include:AI Assistant in Jamf Pro General AvailabilityYou can use Jamf's AI-powered conversational assistant to support your organization's device management and security. AI Assistant consists of individual functionalities called "tools" that are organized in tool groups by product. When you enable AI Assistant, you enable AI Assistant Core, a foundational knowledge tool that can assist you with technical questions about Jamf's software and services. In addition, you can enable read-only tools for Jamf Pro. AI Assistant is disabled by default.To enable AI Assistant for Jamf Pro, log in to Jamf Account and navigate to Organization > AI Assistant.Note: This feature was made available on 31 March 2026 for Jamf Pro environments that support the AI Assistant, regardless of version. For more information, see AI Assistant in the Jamf Account Documentation.Enhancements to OIDC-Based Single Sign-On (SSO) with Jamf AccountYo
Hi,I work at a small creative arts UK University and our IT department has recently contracted a service provider to manage all our Mac devices via JAMF. I am being told that as a new security policy any new OS must be deployed via JAMF within 7 days and any Mac devices not updated will lose web browser functionality.As a Faculty that uses a wide range of audio, video and graphics software on our Macs - often simultaneously on the same device- we have never previously adopted the latest OS for at least a couple of months until any major bug/conflict fixes from Apple and software providers have been implemented. We have also refrained from updating Mac devices whilst in use for art installations in exhibition or live events in rehearsal/performance - so as to ensure continuity of service over a period of weeks.I am wondering how this is handled in other University or education institutions? Do other institutions reasonably manage security concerns through a policy of delaying the new OS
How is everyone handling cleaning up stale devices in Entra? I have the Jamf Compliance Connector setup to register macs with Entra. The compliance reporting is working fine, but the computers show in Entra as registered and last activity as the same date, no activity after registration completed. I normally have cleanup scripts running to disable computers with no activity in the last 90 days but my Jamf macs are not showing activity and I don’t want to disabled them if they still active. My mac used daily shows no activity for over 60 days (since it was registered) in Entra (Company Portal shows connected today):
Your Mac is Ready for FileVaultFileVault keeps your Mac safe by encrypting your data andprotecting it with the password you use to log in. If youforget your password, you can use your Recovery Key toreset it.
Hi Jamf Nation!We are excited to announce Beacon by Jamf Threat Labs.What is Beacon by Jamf Threat Labs? It is a Mac-only threat hunting service delivered by Jamf Threat Labs. It’s designed to help you detect, analyze and respond to threats impacting your macOS environment. Whether you’re building your Mac security program from the ground up or looking to elevate an existing one, Beacon delivers the expertise, visibility and operational support to make it happen.Beacon by Jamf Threat Labs is currently available to limited customers in Private Beta. If you want to learn more, read our blog here or contact your Jamf representative.
On Saturday, April 11, 2026, Jamf Cloud Infrastructure will be patched. During this time, you will be logged out of your Jamf Pro instance. The purpose of patching is to ensure that Jamf Cloud infrastructure and the database service are up-to-date, stable, and safe from security threats. Please see the times for our regions below. Hosted Data Region Date Start Time End Time us-gov-west-1 April 11, 2026 0800 AM CT 1200 PM CT
Hi,our macOS Sequoia clients get the macOS Tahoe Upgrade offered by Notifications since 25th of March.Despite a distributed Configuration Profile which includes the 90 days delay (and worked fine passing those 90 days), Clients get the Upgrade Notification.Did anyone experience the same issue?Is there another way to turn off those notifications?Thanks!
Teachers have been using Apple Classroom to lock iPads if students are misbehaving on them. However, the students have found that if they restart their iPad, the lock clears and they can access it again. Wondering if anyone knows of any other ways for teachers to be able to lock their student’s iPads that doesn’t just clear if a student restarts it. After some testing, I found that if I put it in Lost Mode, that works, but the problem with that is the teachers would need to tell me to do it. I also considered putting a passcode on the device, but the teacher would need to unlock the device for these students each time they use it, and if a student gets locked out, I could see them trying to guess the password too many times and getting locked out for a long period of time. I am looking for tools other than Apple Classroom that teachers could have access to, or any other ideas for how to lock a student out of an iPad and keep them locked until the teacher clears the lock.
why do some Dock items path have /localhost and some other don’tfile://localhost/Applications/*****.appfile:///Applications/GarageBand.app/the main ones i see that have /localhost are applications that don’t come preinstalled on a mac.
Not sure if this is possible; having trouble thinking out the logic. We have systems that are setup with macOS Tahoe, but we also have systems that are being upgraded from macOS 14 and 15 to Tahoe. I am wondering if it is possible to come up with a smart group to differentiate systems that came with vs upgraded to?One thought is to “mark” systems during setup with a flag file during enrollment and use an extension attribute. Maybe a plist that has an array of discovered operating system builds. This way it can be used in the future, not just for macOS Tahoe.Curious if anyone has a better way.
Our goal is to distribute (wifi)certs to about a couple of thousands of iPads, and we have Microsoft and NDES as our infrastructure. Seems to be impossible to find information about how to assign SCEP in JAMF School, especially how to configure Challenge. Does anybody here know how to use the SCEP section? Have done some trials and, all, errors...
Hello, I succeded to deploy SCEP with Jamf School for our iPhones and iPads device. They received certificates and they are able to connect to our WiFi. But the problem is they don’t renew their certificate when they’re about to expire. It seem JamfSchool SCEP don’t send a new request for renew certificate before expiration. Others MDM have an option to set renew before X days of expiration but JamfSchool don’t have that option. How to do it? I did’nt find any documentation.Thank yoU!
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!