Get Support
Recently active
we are currently experiencing an issue with our iPads managed via JAMF School.Since yesterday, all apps on the devices are hidden except for the Settings app.Key details: The devices are managed with JAMF School. Some restrictions are configured in the profile. No changes have been made to the configuration recently. Everything was working correctly until yesterday. If we disable the profile, all apps appear again as expected. Age rating is set to 16+. There are no apps configured in the allow list or block list. Could you please help us identify why the apps are being hidden and what might have caused this behavior?Thank you in advance.Best regards
All, after extensive testing, logging, and analysis the longstanding, intermittent issues affecting the managed endpoints in my enterprise has been traced to how the policy decision engine in GlobalProtect handles traffic destined for our cloud instance.To further explain:For some time upon execution of jamf commands (policy, primarily) in terminal following has been seen:“An error occurred. There is no message.”Subsequent runs would be successful. Nevertheless log captures of “mdmclient” and “com.apple.ManagedClient” are replete with various and sundry errors. Correlating these with netstat commands shows that jamf policy would be begin execution over the VPN tunnel (utunX)… and then quickly gets denied and directed to physical interface (en0). That this occurs, regardless of how quick, during initial TLS handshake hasn’t really helped matters.Further attempts running jamf terminal commands shows that while most traffic appears to head out via native interface some was now allowed via
Hello all.I am getting this error in my notifications when I login to Jamf Pro. I cannot seem to determine what is wrong with this, and it appears that our Jamf Connect configuration is working properly. Thanks in advance.-Pat
Today we are releasing a maintenance version of Jamf Pro to address the following product issue:Jamf Pro Server[PI-1068] Fixed: Mobile device smart groups and advanced mobile device searches using the "Device Ownership Type" criteria with a manually entered value incorrectly include institutional devices.Note: Smart group membership will correct itself as mobile devices check in. To speed up the recalculation process, administrators can edit and then save any affected smart group. For additional information on what's included in this release, review the release notes via the Jamf Learning Hub.To access new versions of Jamf Pro, log into Jamf Account with your Jamf ID. The latest version is located in the Solutions section under Jamf Pro.Subscribe to product alerts to receive real-time updates.
Overview This document walks through how to configure and use temporary privilege elevation on macOS using Self Service+.End users can request temporary local administrator rights directly from the Self Service+ app, authenticate via Touch ID or password, provide a business reason, and receive time-limited elevation, all without IT intervention.The elevation duration, reason requirements, authentication requirements, and permitted reasons are all administrator-controlled via a Jamf Connect configuration profile deployed through Jamf Pro.PrerequisitesUpdated: 3/6/25- To add clarification to Prerequisites Before following this guide, ensure the following are in place:Self Service+ v2.0 of greater installed on the target Mac. Jamf Pro access to create and deploy configuration profiles. The target Mac is enrolled in Jamf Pro. A valid Jamf Connect licence assigned to the device or user. Walkthrough Step 1: Configure the Jamf Connect Preference Domain in Jamf Pro In Jamf Pro, create a new co
Today we released Jamf Connect 3.5.0; this release addresses the following product issues: [PI143260] Fixed: Importing a configuration profile into Jamf Connect Configuration with the User Promotion Choices (UserPromotionChoices) setting in use causes the array for the setting to be replaced by the following text: (. [PI143263, PI144134] Fixed: Jamf Connect presents the following one-time prompt on computers with macOS Tahoe 26.1 beta, both on the login window and on the desktop: Self Service+ wants to use your confidential information stored in "Jamf Connect" in your keychain. [PI143435] Fixed: When RapidIdentity is the identity provider, the Jamf Connect login window requests the local account password during the password verification workflow instead of the identity provider password. To access new versions of Jamf Connect, log in to Jamf Account with your Jamf ID. The latest version is located in the Solutions section under Jamf Connect.Product DocumentationFor additional informati
We are upgrading Standard Cloud environments to a maintenance version of Jamf Pro which addresses the following product issue:Jamf Pro Server[PI-1068] Fixed: Mobile device smart groups and advanced mobile device searches using the "Device Ownership Type" criteria with a manually entered value incorrectly include institutional devices.Note: Smart group membership will correct itself as mobile devices check in. To speed up the recalculation process, administrators can edit and then save any affected smart group. Cloud Upgrade ScheduleYour Jamf Pro server, including any free sandbox environments, will be updated based on your hosted data region below. Review this guide if you need assistance identifying the Hosted Data Region of your Jamf Cloud instance. A full general availability release is being scheduled for the week of 9 March.Subscribe to product alerts to receive real-time updates. Hosted Region Begins Ends ap-southeast-2 8 March at 1300 UTC 8 March at 1900 UTC ap-northea
Does anyone else get the Device is busy, will try again response or just stays pending when pushing configurations to a locked ipad or iphone? Even update inventory just stays pending. This is happening to us consistently and magically works when the device is unlocked. Any fixes for this or is this by design?
Hi everyone! My team is currently exploring the implementation of LAPS into our workflow, and we’d love to hear from those of you in Education (or similar sectors).For those who have made the jump: how has the experience been? Specifically, I'm curious about the initial setup complexity and how user-friendly the password retrieval process is for your team. Also, from a security standpoint, do you find that simply rotating the local admin password provides enough protection, or are there other factors we should consider? Thanks in advance for any insights.
Microsoft has put a new “unlock premium” button in teams. Has someone found plist / custom profile setting to disable this?I don’t see teams as an option in iMazing Profile Editor.
I am having an issue creating a PreStage enrollment in Jamf Pro, The 'New' PreStage button hangs immediately on click. I have verified the ADE token is new and UIE is enabled. I just see a spinning wheel when I click New to create a PreStage enrollment for Computers. The Devices/ios one works fine. I did try chrome, firefox, safari browser, same issue.
Hi Jamf Nation! Exciting news - the JNUC 2026 Call for Sessions is officially open through April 10!Thinking about becoming a JNUC speaker? Check out the Speaker Prospectus for all the details. We can’t wait to see your ideas - submit your session here! Questions? Email us at jnuchelp@jamf.com
It would be great to introduce a more granular approach to scoping Blueprints in Jamf Pro.Having the ability to define exclusions within Blueprint scope would be extremely valuable.
Hi folks,I’m doing an audit of our config profiles and would like to break our baseline configuration profile into multi profiles. Right now, we have a massive baseline profile. If I need to edit a specific feature or settings, the whole profile gets push out everywhere.I would like to create smaller profiles that are specific to subsets of settings so I have more granular control over updating settings and the distribution of those settings.For example I may have profiles like the following as opposed to one massive profile:Baseline- Network UsageBaseline- FunctionalityBaseline- Setup StepsBaseline- Hidden AppsI can certainly created those subset profiles now without any scope assigned. My question is whether people have suggestions on the best order of steps to accomplish this task without the world exploding :-)For example, if I replicate everything currently in effect within multiple profiles, and I scope those new profiles to my all devices group, then I remove the current massive
Today we are releasing a maintenance version of Jamf Pro; highlights include: Engage Settings for In-App MessagingYou can use the Engage settings in Jamf Account to opt-out of web interface messaging or surveys. Opting-out affects all Jamf platform interfaces for your user account. For more information, see Profile Management in the Jamf Account Documentation. Resolved IssuesJamf Pro Server: Security Issues[PI149568] Fixed: A known vulnerability in a third-party library (CVE-2025-67735). [PI158236] Fixed: A known vulnerability in a third-party library (CVE-2026-25896).Jamf Pro Server[PI139067] Fixed: Jamf Pro may intermittently invalidate active JCDS download tokens, causing all cloud distribution downloads to fail with 401 errors until a new token is generated. [PI140295] Fixed: Advanced inventory searches and smart groups do not add criteria correctly if the selected criteria contains 2-byte characters. For additional information on what's included in this release, review the release
I’m a little bit disappointed about so much missing endpoints in the API. So many Informations about devices, groups, profiles that i can’t get or set over the API. I often like to write shell-scripts that could solve problems automatically, for example with profiles not installing, but because of missing endpoints for these functions i can’t and have to do it by hand. For example: Sometimes Apps on Devices use Single App Mode für Exam-Mode and stuck in it after that. Its not visible on the device but inhibit that profiles with whitelists can be installed. Thats a problem for profiles that are time based. The solution is to set this device in a profile with single app mode, wait until it is installed and remove the device out of this profil. But i cannot automate this, because the API have no Endpoint for installation status of profiles. So i cannot get a list of devices that cannot install the white list profile with a reason and also not the status if the repair profil is installed.
Hey guys, I'm in the process of testing Jamf Connect, I noticed this as a sign-in option Would it be possible to remove it since no one will use it to sign in to their Mac!!? I couldn't find any related settings in our Azure AD. Thanks in advance
Hello all,We are finally moving our labs away from AD, and our admins are setting up JamfConnect for authentication. I’ve been able to repurpose most of our apps/config profiles etc but I wonder if anyone has had success with WEPA and passing credentials via JamfConnect / PlatformSSO etc. TIA
Hello All, I can’t seem to make sense of this one. So I was looking at Patch management and Jamf Connect.Jamf Connect 3.7 came out recently, so I’m thinking I’ll add it to patch management.I look at the definitions and I see 3.14 as the newest, and there isn’t even a 3.7 listed.I am lost.-Pat
Today we released Jamf Connect 3.7.0; this release addresses the following product issues: [PI-923] Fixed: Authenticating via web view with Entra ID using a FIDO2 passkey prevents users from authenticating with Jamf Connect via the login window. [PI140159] Fixed: After two incorrect login attempts, the Jamf Connect login window fails to accept the correct password and prevents the user from authenticating after the lockout timer is complete. [PI152763] Fixed: The Sign In window displays two arrows that do nothing when clicked. Fixed: The installer for Jamf Connect does not force quit the Jamf Connect login window while deployment tools, such as Jamf Simplified Device Enrollment, are in use. To access new versions of Jamf Connect, log in to Jamf Account with your Jamf ID. The latest version is located in the Solutions section under Jamf Connect.Product DocumentationFor additional information on what's included in this release, review the release notes via the Jamf Learning Hub.
Anyone having a keychain issue and the onboarding window not opening automatically upon first login (newly imaged machine that hasn’t been logged into before)? Tried 3 times and get the same result.Self Service+ Version: 2.4.0Jamf Connect Version: 3.4.1Jamf Connect Preference Domain Version: 3.2.0macOS Version: 15.5 (24F74)
Reading documentation about 3rd party SSL certs and Jamf Pro. We are in the process of automating our Jamf Pro SSL cert renewal and I keep seeing that you need upload the 3rd party cert using the Jamf Pro interface. Is this that case? We already have a script for renewal that stops tomcat, edits the server.xml file with the correct cert info and re-starts tomcat. Do you also need to upload the cert into the Jamf console? is the cert also stored in the Jamf Pro DB?“Note:If your environment is clustered, you must log in to the Jamf Pro web app for each Apache Tomcat node and create or upload any SSL certificates for each node””This also comes up with migrating Jamf Pro to another server documentation (which we are also working on)
Dear community,I am facing a major issue with our Jamf Pro environment.We are running Jamf Pro 11.21 On-Prem and have several working PreStage enrollments—until today.I had a device that was already upgraded to macOS Tahoe. After erasing the Mac, I started the PreStage enrollment. The macOS installation completed normally, and the device enrolled in MDM.However, after the Setup Assistant finished, Self Service never appeared, and only half of the expected configuration profiles were installed.I waited over 30 minutes, thinking it might be a timing or network delay, but nothing happened. I also tried: restarting the Mac running sudo profiles renew -type enrollment manually installing Self Service.pkg and jamf.pkg copied from a working machine Even after manual installation, the agent could not connect to the server.It looks like the Jamf framework does not install correctly on macOS Tahoe during enrollment.Has anyone seen this behavior, and what could be causing it?Thank you in adva
If anyone runs into this when trying to install the Nessus Agent with Jamf Pro: Installation failed. The installer reported: installer: Package name is Tenable Nessus Agent installer: Certificate used to sign package is not trusted. Use --allow Untrusted to overwrite. I have a fix. Thanks to Bartłomiej Sojka for pointing out that it's a hard link, and suggesting the solution. It’s the package downloaded directly from the vendor https://www.tenable.com/downloads/nessus-agents, in the section Nessus Agents - 7.4.3, NessusAgent-7.4.3.dmg I think the visible package in the disk image is actually a hard link to a hidden package in the disk image, named .NessusAgent.pkg. I have no idea why. Here is me using “ls -la” to get a long listing of all the files, even hidden files, in the disk image: MacBookPro:Nessus Agent Install ladmin$ ls -la total 28120 drwxr-xr-x 5 ladmin staff 238 Sep 10 16:11 . drwxr-xr-x+ 4 root wheel 128 Oct 31 19:55 .. -rw-r--r-- 1 ladmin staff
Greetings All!, Just getting started on my road to JAMF admin and am slowly building up my library of First Aid apps inside of Self service. Trying to eliminate tickets coming my way and empowering the Help Desk to do some of this stuff. I created this script to view the Personal FV Keys from the server without have to give anyone rights into the server. This script is not perfect in any way, but I thought I would share it with the group nonetheless. This using SwiftDialog for the GUI and was taken from a lot of GitHub scripts and customized it for my needs. Enjoy! #!/bin/zsh # This script retrieves the Personal FileVault Key for a particular computer # # Written by: Scott Kendall 12-20-2024 # Last Modified on: 12-20-2024 jamfpro_user=${4} jamfpro_password=${5} declare api_token declare api_authentication_check declare ID declare reason declare serial_num ###################################################################################
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!