Get Support
Recently active
With the update of iOS 26.4 there is now a prompt for age verification in the UK for content. Most of our managed phones do not have apple id’s associated with them and all apps are distributed through self service. Is there a blanket way to say all the phones are with users who are over the age of 18 to avoid having to deal with many service tickets.
Hello,I am trying to update our method of deploying out the essential sounds for GarageBand through Self Service. In the past, I had leveraged the Carl Ashley AppleLoops script (it worked great!). After Apple removed Python from the base installation of macOS, I had been limping along with installing Python on the devices that were needing the sounds. This has posed other complexities.Currently, I am testing out installing all of the sound packages needed for the Essential Sounds from a cached copy of those packages on the laptop. This has not produced the desired results yet. The user is still prompted to install the sounds when launching GarageBand. All of the sounds that should be available from the Essential Sounds are present in GarageBand. The loops have also been reindexed in hopes that would resolve the issue.I would appreciate any help that anyone has to offer.Thanks!
Has anyone successfully implemented Epic Bedside using JAMF? I have the MyChart URL but anything after that I am lost. If so I could use some help with the AppConfig for Bedside. Epic has not been much help and our Epic team is not familiar with the values needed. Here is the only information Epic sent us. Work with your MDM representative to pass your MyChart server URL to hospital-owned tablets so the tablets can be activated with a numeric code. The MyChart Bedside application must be updated to version 10.9 or higher to receive the server URL. Pass your MyChart URL to the Bedside tablets. The exact setup to include the MyChart URL in the managed app configuration varies, so you should refer to your MDM system's documentation to determine how to provide the configuration value. Add the Configuration Key of MyChartURL to your sent configuration options. Set the Value Type as String Add your full MyChart Server URL (e.g. https://mycserver/MyChart-instance/)
I'm trying to configure the app request for our iPad users but I'm not seeing the App Request option in the Self Service app. I'm testing this on myself. So far I've... Created a static group and added myself to it In Settings > Self Service > App Request App Request Form > Checked "Enable App Request in Self Service for iOS" App Request Form > Added some request form fields and set the App Store Country/Region Requestors and Approvers > Set the Requesters to the static group Requestors and Approvers > Added myself as an Approver Email Address In Settings Self Service > iOS General > InstallType = Automatically install Self Service app General > Checked "In-house app updates" General > Landing Page = Home App Options > User Login = Allow users to log in to the login menu Signed into the Self Service app on my iPad What else am I missing?
Hello all, I am working on deploying the updated company wallpaper. Current attempt is using the script below, but it gives the user a that “Jamf wants access to control Finder...” (screenshot attached). Maybe there is a better way to do this. #!/bin/shcurrentUser=$(/bin/ls -l /dev/console | /usr/bin/awk '{print $3}')sudo -u "$currentUser" -H osascript -e 'tell application "Finder" to set desktop picture to POSIX file "/Library/DesktopWallpaper/backgroundDefault.jpg"'exit 0
Update your iPhones and iPads right now’'Darksword' exploit just went global: Millions of iPhones now wide open to hackersiPhone exploit DarkSword has been released in the wild | Mashable
Hi, everyone!We are in the “Pilot” stage of our Self Service+ deployment. For the most part everything has run smoothly while deploying as a policy to our “test” group and our “pilot” group. I scoped the policy to our “pilot” group on 3/23/26 and did not receive any reports of any strange activity or concerns. However, this morning, three different users reported seeing a Self Service+ pop-up when they logged into their machines for the start of the work day. When my colleague and I were testing this policy on our test machines, we did not see this pop-up or anything else happen out of the ordinary. I know that this is considered “expected behavior” but, I would like to figure out why it has only happened for three spereate individuals and no one else (as of yet).Has anyone else experienced or heard of this pop-up occuring on there end? TIA!-Michael G.
• https://support.apple.com/en-us/100100• iOS - 30+ CVEs patched• macOS - 70+ CVEs patches
I'm trying to upload a signed config profile and I keep getting "Unable to create object from file." It worked a few months ago, but I had to change the name. I changed the UUIDs, there is no duplicate named profile and the unsigned profile uploads fine. I tried both a couple signing certs I have in Xcode as well as creating a signing cert using these instructions.I can install the profile fine locally:We're running 10.41.0-t1661887915 in the Jamf cloud.
We have configured Jamf with Nudge. The action button Update Device launches the Self Service policy for the minor update of the current OS. However, with Self Service+, this does not work. The Self Service+ app launches, but the policy never begins. It simply spins. With the old self service, it works without a problem. This is a bit of an issue because it then becomes more difficult to enforce compliance with Nudge. Anyone has a solution? Thank you.
Hello, We have had "device compliance" for MacOS configured since August 2024 and it appears to be working correctly. I just enabled the iPadOS/iOS option and the test device appears in the Device Compliance = Compliant smart group in Jamf but continues to show as "n/a" for compliance in EntraID. It's been half a day and the EntraID compliance status has not changed. How quickly should the compliance status get updated in EntraID and is there a way to sync Jamf with EntraID to update the status? Is anyone seeing this work successfully?Thank you.
Hello For those running MacOS 26 how are you deploying background security improvements?Blueprints doesnt seem to understand the format. https://support.apple.com/en-gb/111333I could find anything in Jamf blueprint documentation either. thanks
Hi Team,I’m evaluating a potential integration between Jamf Pro and a third-party Threat Intelligence Platform (TIP), and wanted to validate feasibility from a technical/partner perspective.The TIP APIs provide: Stream of malicious IOCs (IP, domain, file hash, URL) (Usually need to run on schedule) On-demand IOC reputation lookup (malicious/suspicious/benign) File and URL scanning capabilities Planned approach: Integration will rely only on Jamf Pro APIs (no agent/kernel-level extensions) Key questions: Can Jamf Pro workflows leverage external IOC data to trigger actions on managed devices? Using Jamf APIs, is it feasible to: Enforce blocking of malicious domains/URLs via configuration profiles or policies? Act on files (e.g., remediation based on file hash via scripts)? Trigger automated responses (policies, scripts, device lock/wipe) based on external intelligence? Are there any recommended patterns or limitations when integrating external threat intelligence fe
I am using Jamf Pro with Google IdP, Enrollment Customization, PreStage Enrollment, and Single Sign-On. However, no matter what I try, when I enroll a device the fields populate as:Full name: Firstname LastnameUsername: firstname.lastname@emailaddressWhat I want instead is for the username to be first.last.I created a custom SAML attribute that maps to firstname.lastname, but I have not been able to get it to work. I’m not sure what else to try.Is it possible to have the home directory set to first.last instead of using the full email address?When I use $FULLNAME and $REALNAME in Enrollment Customization and PreStage Enrollment, the auto-populated information during device enrollment becomes:Full Name: Firstname LastnameAccount name (home directory): Firstname Lastname Not using Jamf Connect
Hello all you Apple Rockstars!I just noticed that there’s a whole reward system you can redeem points (“bytes”) for stuff. Very cool. Ivanti used to have something like this called Insiders, but the reward system was abruptly discontinued while I had lots of unspent points.I’m not sure I fully understand what actions get points, but it looks like you get 5 points for the first posting/replying each day, and then a single point for each subsequent post/reply.Doing some quick math: If you want to get to 500 points, that would take you 100 days. Assuming you only did 1 post/reply a day, on normal workdays, thats 20 weeks.Does that seem like an unreasonable amount of effort to get a tech mat or whatever?I know they are doing this to stimulate customer engagement, but I think they would need to get more generous with the points for people to participate more.What do you think?Anyone had experience with redeeming points? I’m not sure how long this has been a thing.
Today we are releasing a maintenance version of Jamf Connect which includes minor bug fixes and improvements. To access new versions of Jamf Connect, log in to Jamf Account with your Jamf ID. The latest version is located in the Solutions section under Jamf Connect.Product DocumentationFor additional information on what's included in this release, review the release notes via the Jamf Learning Hub.
For some reason there is an Item Failed notification in the Self Service+ App (with+ I mean the new version.So the old fix “sudo rm -R ~/Library/Application\ Support/com.jamfsoftware.selfservice.mac/”dont work any more. Its account related because if I login with a different account this issue is gone:Also its only there when you start SS.app (the 1 in the Dock appear if you close SS the ! disappear)Any idea? thanks
We have an iPad that switched on after 2 months now it has an expired certificate I cannot renew. (See the attached images)This iPad is connected to the wifi but it doesn't communicate with the JAMF server all the commands are in pending status.When I check the " JSS Built-in Certificate Authority " in the server it's expires in 2033Can anyone help regarding this issue what should I do? When I open the iPad from the JAMF server This is what I can see on the device When I got to the PKI certificate and checked the certificate expired in 2033 Most importantly self-service is not working
Hi everyone,We have a WPA2/WPA3-Enterprise network, and I am wondering if it is possible to use Jamf’s built-in CA to push certificates to end devices, so that users can be authenticated for Wi-Fi using those certificates.Additionally, what is the typical approach for this setup? I see docs recommend using AD CS, but our organization uses Azure rather than on-premises Active Directory.I would appreciate any guidance from someone with experience in this area. Thank you.
Hi, I am running a vendor bash script from self service as part of a remediation effort. As part of the script there is a device shutdown. This happens before the device feeds back policy logs so if it fails I cant see why. Would anyone know if sh scripts and their results get logged automatically somewhere or if there is a simple command to get them to do so? Alternatively presumably I could remove the reboot from the script and have the JAMF policy do that?
How to do we stop these notifications from popping up? Staff are receiving these throughout the day and it’s very annoying and disruptive. MB Air M2 and OS is 15.5.0 or later. Is there a config profile or settings to adjust in Jamf?
I inherited a pretty banged up Jamf environment and im looking for a way to re-escrow 103 users’ personal recovery keys. I know how I can do this on the Mac itself, but im wondering if theres a safe way for me to do this in bulk. Thanks!
💙 Hi, Jamf Nation! 💙We’re gearing up for this year’s Jamf Nation Live (JNL) events, and we’d love to feature a few customer voices at each stop on the roadshow. If you’re planning to attend one of the JNL cities and would be open to speaking, we’d love to hear from you!✨ What we’re looking for:• A short customer story (5–7 minutes)• Focused on your Jamf journey, wins, or lessons learned• Comfort speaking to a friendly, community‑driven audience🗣️ How to participate:Drop a reply in this thread with:1️⃣ Which JNL city you plan to attend2️⃣ Whether you’re interested in speakingWe’ll review all responses and follow up directly.Thanks for helping us make JNL 2026 even more meaningful! 🙌🏻
On Wednesday, February 18, 2026, the New York City Jamf User Group (NYC JUG, or simply “the JUG” to its members) celebrated its 12th anniversary. The date marked exactly 12 years since the group’s first meeting.Meeting an average of four times a year, NYC JUG has built a long tradition of bringing together the Apple admin community in New York City. In the dozen years since its inception, more than 400 admins have participated in the group. Along the way, the community has helped launch several spin-off groups including Women in Tech, MacAdmins LATAM, and MacAdmins NYC, all started by NYC JUG members.How It StartedBack in 2014, as a longtime member of the Apple admin community and a Jamf customer, I posted on Jamf Nation to see if there was interest in getting a group together to share ideas and build a sense of community. Apple admins were often the minority at the companies where we worked, so the idea of getting together to help each other was something I felt strongly about. Wit
Does anybody know if there’s a way to deploy the Aurora Endpoint Defense (CylanceProtect) through Jamf? When deploying them on a 1 by 1 basis through Aurora, I create the user in Aurora Endpoint then that creates credentials for the user and sends them an email to download the app along with their credentials. I’m wondering if there’s a way to easily push this to iOS devices without touching each individual phone. Any help is appreciated!
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!