Get Support
Recently active
Hello Jamf Nation!We’ve released Jamf Pro 11.27.0 beta. This release includes A setup assistant for configuring OIDC-based single sign-on (SSO) with Jamf Account, Active User Display, and more! For full details, check out the release notes after enrollment.How to join the beta: Enroll in the Beta Program under Product Feedback at account.jamf.com. Click “Join Community” to join the beta forum once enrolled. If you encounter an error on Jamf Nation joining the beta forum, please log into Jamf Nation and then click “Join Community” again. Please also check out this recent blog on Configuring SSO in Jamf Account prior to testing Compliance Benchmarks, Blueprints, and App Switcher. Email beta@jamf.com with questions.The beta program is covered by the Jamf non-disclosure agreement; please do not share any information regarding your testing on any public forum, including the non-beta areas of Jamf Nation. Use the Jamf Nation Beta Forum or contact Jamf via beta@jamf.com with any questions. Th
Due to changes being made by our network team we’re required to deploy a new Trusted Root Certificate within our Wifi Configuration Profile. DigiCert are changing Root Certificates.What I’m encountering is even though I can successfully deploy the Certificate and Trust it within the Configuration Profile if I deploy more than one Root Certificate the Mac will not connect.I’m hoping that I can deploy the new certificate without impacting the existing wifi connection before Networks make the backend change.
To install Creative Cloud at my company, end users are directed to the Adobe Creative Cloud website (https://www.adobe.com/creativecloud/desktop-app.html). Every two weeks I get a report from our Security team listing device vulnerabilities. There's frequently a fair number of devices that need one or more Creative Cloud apps updated. I started emailing users individually, reminding them to update their Creative Cloud apps. Wondering if there's a better way, because emailing users and following up when they don't respond is too manual and too time-consuming. Curious how other admins approach this.
Is there a better way to update Users chrome app via JAMF? I’ve been using Mac Apps and it’s working for the purpose, however the issue is with the force quit. Sometimes while users are in an online meeting, chrome just force quit to update. I want to force update but not while they are using chrome.
I have been having this issue where some of our Mac computers are being force to change their password approximately every 90 days. First thing comes in mind is if we have a Jamf policy for password expiration. As per checking we don’t have any policy enforced for a password expiration. I’ve been researching if what may be the cause, most says that it’s due to an MDM.Anyone having this kind of issue? how did you resolved it. We don’t want to set an expiration date for our Mac passwords.
Subsequent to extensive logging, analysis, and corresponding packet captures I have correlated results from two managed endpoints under the following conditions:With Netskope active/tunnelingWith both Netskope/GlobalProtect active/tunnelingWithout eitherLog streams captures were correlated against corresponding pcaps; results are presented as pasted herein. Sanitized logs and reports available upon request. TIME ───────────────────────────────────────────────────────────▶STEP 1: DNS RESOLUTION (Resolver Layer)────────────────────────────────────────Client → DNS Query ← Response: hostname → IPs (TTL = 60) [TTL countdown begins immediately] Example: cityofphoenix.jamfcloud.com → 184.32.98.75, 54.218.86.150, 34.215.108.82 TTL = 60sSTEP 2: TTL DECAY (Cache Reality)────────────────────────────────────────Time passes (milliseconds → seconds)Observed TTLs:- 60 → 57 → 32 → 7 → 2(Netskope system shows fragmented snapshots: multiple partial TTL views si
Hoping someone can help me out.I have a script in JAMF that is very simple and runs the KLIST command only. #!/bin/bashklistexit 0When run on a machine with valid kerberos ticket I get a klist: Cache not found: error. Wehn I run this script in a terminal window with sudo I get valid results. Not sure ehy running it thru JAMF is returning an error. Thank you in advance.
Mac Admins Europe is a new conference built by and for the European Apple Admin community, bringing together admins from education, enterprise, and beyond to share knowledge, swap war stories, and find their people closer to home. Organizers @mischavdbent , @rob_potvin, @Armin and me reflect on what's driving the growth of the community, why now felt like the right moment and what success looks like.When you look at the European Mac admin community today versus a few years ago, how has it changed, and what made you feel the time was right for a dedicated European event?A few years ago, the European Mac admin community felt more fragmented. There were great people doing great work, but a lot of it happened in smaller pockets — local meetups, Slack channels, or at events outside Europe.What’s changed is confidence and scale. macOS and Apple platforms are now firmly embedded in education and enterprise across Europe. That’s created more Mac admins, more diverse roles, and more shared c
Hey folks! I know it’s a stupid question but.. quick sanity check before I flip a switch in Jamf ProI'm working on a custom enrollment flow using Okta SSO, which requires enabling the “Use SAML authentication for end users” option.Right now, admins are logging into Jamf via Jamf Account and everything works fine there.Just want to confirm that turning this on won't impact admin access, correct? Admins should still be able to log in the same way as before?Anything I should be careful about before enabling it?Thanks in advance!
I have some MacBooks that are pre-stage enrolled that have stopped checking in and stopped inventorying. I have others that are User initiated enrolled that stopped checking in but I just had them remove the profiles and redo the enrollment and they are working again. These are all remote users so I cannot be hands on. I had a few of the pre-stage enrolled devices attempt to run sudo jamf recon and sudo jamf policy from terminal but they are receiving "Device Signature Error - A valid device signature is required to perform the action" Other postings I've seen that are quite a bit older mention unenrolling devices and reenrolling them. Not really an option if they are pre-stage enrolled from what I understand. Does anyone know what I can do get these devices reporting properly?
With Jamf Pro 11.26, session options configured in Jamf Account are enforced, computers with macOS 26 or later are automatically registered with the Jamf device compliance integration with Microsoft Entra ID during enrollment, and administrators can programmatically manage Jamf Pro user accounts with the Jamf Pro API! Be sure to check out the Jamf Pro release notes for all of the exciting new features and enhancements.Thank you for your continued support and feedback!
Today we are releasing Jamf Pro 11.26; highlights include:Support for Session Timeout Settings in Jamf AccountJamf Pro now respects "Inactivity timeout" and "Session duration" settings configured in Jamf Account for environments integrated with OIDC-based single sign-on (SSO) through Jamf Account. Device Compliance with Microsoft Entra Supports Simplified Setup for Platform Single Sign-OnJamf Pro's integration with Microsoft Entra device compliance now supports automatic device registration with Microsoft Entra when using Simplified Setup for Platform Single Sign-on (Platform SSO). This eliminates the need for end users to respond to a notification to manually register their devices. For additional information on what's included in this release, review the release notes via the Jamf Learning Hub.To access new versions of Jamf Pro, log into Jamf Account with your Jamf ID. The latest version is located in the Solutions section under Jamf Pro. Cloud Upgrade ScheduleYour Jamf Pro server, i
Hey all - Ran into a thing that has been mentioned before, but it was a year ago and a few Jamf Connect login versions ago. We are now up to 3.6 Had a user who had their Microsoft Authenticator switch from sending them push notification to enter a number to requiring her to enter the 6 digit number. She would get the Jamf Connect Login window and enter her MS login, PW and the 6 digit 2FA code. The Jamf Connect Login window would stay up, but load her profile page. She would also see an error that password needed to be at least 7 characters, and contain one number and one alphanumeric character. It took me a VERY long time (and a computer wipe) to figure out that it looks like the Jamf Connect login window is passing that 6 digit number to the OS for login instead of the users Password. Once we reset her Authentication Methods in EntraID so that the push notification workflow returned, her login issues on her laptop went away. Has anyone else run into this before? If so is there a se
I am a jamf admin working on getting our enrollment modernized. Within the last year we got our connection setup with ABM and Jamf so that our devices will have automated enrollment during setup. The issue we are running into is that our company requires all devices on internal network to be trusted (typically using a certificate)Since the enrollment is happening during the setup experience, I cant see how there would be a way to get the device the certificate before reaching out to our enrollment server. If we are on internal we get an immediate block. We have to connect it to an external network to enroll. I put in a request with our security team and after some back and forth I asked if our specific enrollment URL could be allowed access on the network without being trusted. Understandably they are not too keen on this idea. I can’t find anything from jamf on getting around this, has anyone had a similar experience in their enterprise on anything like this?
Hey folks! Dropping in for another quick Self Service+ post on how to: determine available URL schemes for a macOS app (in this example, Self Service+.app) how to map policy URLs from Jamf Pro to the new schema and have the actions load within Self Service+ The Self Service app has historically supported URL schemes to automatically run a policy or open the app directly to a description of a given policy. Within the Self Service settings of an app policy in Jamf Pro there are installation and description URLs provided. Those URLs tie into URL schemes for the Self Service app, and can be launched in scripts and by sharing them directly via link. For example, running the simple Terminal command open "jamfselfservice://content?entity=policy&id=392&action=view" one can launch Self Service classic and deep link right into a policy and view the description. Self Service+ also includes this functionality, though the URL schemes are not displayed in Jamf Pro for pol
Hi I’m trying to set a wallpaper for Apple Tvs in a school. I’ve set a configuration profile which locks the Apple TV in the conference display mode. I’ve also created a smart device group where i’ve uploaded a test jpg file, but it doesn’t want to pickup the wallpaper. Does anyone have have suggestions?
Hi, I want to deploy an initial default Dock layout after enrollment is completed, where the end user can later change it to whatever suits them.I’ve heard of multiple methods, such as using Dock items in Jamf Pro settings, scripts, Outset with docklib, and dockutil. I was wondering what the easiest and most hassle-free approach would be as an MDM administrator. Thanks in advance.
Before we get too far into this I want to say one thing. I am not a medical or mental health professional. I’m a Jamf Engineer who has thought a lot about this but by no means am an authority on the subject. The following article is my reflections and not any type of mental health treatment. Now that that’s out of the way…here we go! Nobody goes to school to be a Jamf Engineer or Admin. The vast majority of us ended up in this field because we like to tinker with things, eventually break them and are forced to fix them without any help or education. For a lot of us, we ended up in this field by doing other things in a job where we do have formal training.When you fix what you’ve broken, you feel great. But when you can’t fix it, some of us give up, others seek advice, some keep plugging along to find the solution. But what happens when you end up in a corporate environment and you have to tackle things that you inherited, need an upgrade or you just need to do maintenance, most of it
We are having problems with apps signing out each time our students try to to use them on their iPad. They sign in with Google Single Sign on or use the QR code. As an example our students use the IXL app, sign in with google sign in and the next day they are signed out again. Does anyone have this problem or have solution on if something set in JAMF School would be able causing this problem?
Hi everyone i'm trying to understand the best way to configure Jamf Protect with our jamf instance. I set up a smart group in jamf to alert users about security issues and that works fine. Unfortunately the jamf protect documentation is a bit incomplete imho. What are the next steps i need to follow? Any suggestion or guide to suggest? Do i need to manually remove the mac from the smart group? Jamf Protect has some removing capabilities or i need to clean the mac manually?
Took me awhile to discover this and could not find a solution anywhere in Jamf Nation so thought I would post my solution I used. I have several Extension Attribute scripts that require a user to be logged in (including 2 provided by Jamf Onboarding, Jamf Connect First Run and Entra Registration statuses). Problem is if Inventory Update runs when no user is logged in (yes, this happens) the script does not detect current user so it cannot access current user folder to check plist file so it updates the EA to Not Found losing the Entra Registration completed or Jamf Connect First Run Completed (or any other EA that uses user directory).I created a script to detect if user logged in and if not to use a cached status created/updated from previous run when a user was logged in. Hopefully this helps someone else or someone else has an improvement to it: #!/bin/bash# 1. CREATE EA CACHE# Set this to match your EA name exactly (avoid spaces if possible)EA_NAME="EA_Name"# Create a dedicated hid
AI is moving fast. We want to know where you actually stand. Four questions, under three minutes -- your anonymous answers will shape how we think about what matters most for Apple enterprise IT and security teams right now. Take the survey here: https://www.surveymonkey.com/r/jamfaipulse26
Any on know how often is the built in Jamf External Applications repository updated in Jamf Pro?Also is Jamf pulling these from https://github.com/Jamf-Custom-Profile-Schemas/ProfileManifestsMirror?I noticed com.microsoft.autoupdate2.json was update on the github Feb 17 2026 but is does not seem to be updated in the built in Jamf External Applications repository (still says Revision: 2024-12-13)
Hello all you Jamf Rockstars,I was building a new package and decided to add the script I needed to run at the end as part of the package instead of a separate component in the Jamf policy. When I tried to deploy it I got “Installation failed. The package could not be verified.”Turns out this can happen when Gatekeeper rejects the package because the package is unsigned, and included a postinstall script.Composer has a setting for signing packages, I do not have that configured. There is also a field for “Default Bundle Identifier” under the advanced tab. Is anyone signing their packages? Do you use a third-party cert?Are you populating the “Default Bundle Identifier”? Thanks in advance,-Pat
With the update of iOS 26.4 there is now a prompt for age verification in the UK for content. Most of our managed phones do not have apple id’s associated with them and all apps are distributed through self service. Is there a blanket way to say all the phones are with users who are over the age of 18 to avoid having to deal with many service tickets.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!