Get Support
Recently active
How is everyone securely disposing or destroying their own Apple SSD storage units?Considering that MacBooks from 2016 to 2022 have an SSD (NAND storage) that is not upgradeable,and it is not replaceable either, since it is soldered onto the main board:If a company has decommissioned a MacBook and the device reaches its end-of-life,the NAND storage cannot be extracted and re-used on a different device.Also:How can businesses assert that their data is securely wiped before device disposal?
I am trying to create a Applications Usage Reports specially for Adobe App, I have tried:To create a usage report for a group of computers based on applications, you'll need to follow these steps:First, ensure Application Usage collection is enabled:Go to Settings > Computer management > Inventory collection Click Edit, then the Software tab > Applications Select "Collect Application Usage Information" checkboxNext, create a Smart Group for your computers:Navigate to Computers > Smart Computer Groups > New Add criteria using Application Title and optionally Application Version Configure operators and values to define your groupFinally, generate the report:Go to Computers > Search Inventory Create or select an advanced computer search with your criteria Click the Reports tab Select "Applications" as the inventory item to base results on Choose your file format and click Download ReportThis is jamf instructions and it did not work, when I reached out to support this is
Hi, I have a scenario where I want to use Entra ID during Automated Enrollment to authenticate end users and ensure Entra ID is the single source of truth for users and groups. I was also wondering whether if it would be possible to automatically create local accounts based on Entra ID.From what I have read, this is only possible with Jamf Connect. However, I've also heard that Jamf Pro has some IdP/SSO capabilities during enrollment, I'm trying to understand what can actually be achieved using Jamf Pro alone. If anyone with Jamf Pro expertise could clarify, I would greatly appreciate it. Thanks!
Our company recently installed Jamf on our Mac. Me and some colleagues on Sonoma are locked out of our accounts because a new password is required but the password is not accepted. In short:No Jamf installed. All is well.Upgrade to Sonoma. All is well. Install Jamf. Accept the certificate, check it out in System Preferences. All seems well.When the screen saver lock kicks in, try to log back in.A new password is requested. Enter it, in both fields. Password is rejected because "Your password does not meet the requirements of the server."Some notes:The built-in macOS password check shows all rules in green.I did try every password config that would make sense, no luck, and I don't think that's itI'm very puzzled about the need for "the server" to see my local admin password, WTF?!
We've recently been trying to get users to update passwords more regularly and with that of course, is keychain issues. I was trying to create a script to remove local wifi connections and server connections so when they accessed them, they could just recreate it by typing in their password. I've been struggling with this for a couple of days and had success locally, but not when deployed, and now I've broken it completely again.#!/bin/bashsecurity delete-internet-password -l "cwinprint" ~/Library/Keychains/login.keychainsecurity delete-internet-password -l "pwinfile" ~/Library/Keychains/login.keychainsecurity delete-internet-password -l "cwinfile" ~/Library/Keychains/login.keychainsecurity delete-internet-password -l "fwinfile" ~/Library/Keychains/login.keychainsecurity delete-generic-password -l "IS-EMP" -s com.apple.network.eap.user.item.wlan.ssid.IS-EMPsecurity delete-generic-password -l "CO-EMP" -s com.apple.network.eap.user.item.wlan.ssid.CO-EMPLooking to use this as a script to
Hi,my organization requires me to block all Adobe Creative Cloud AI features. Does anyone have experience with this? What can be done? Are there Configuration Profiles I can use that are already tested?Thanks in advance.
I created a script with sudo jamf policy; sudo jamf recon, added it to a policy, and made it available via Self Service. It runs and the check-in time and inventory updates but policies that are set to run on recurring check-in are not triggered. Is there a way to create a policy that I can make available in Self Service that will force the machine to check-in, run any available policies that are set to run on recurring check-in, and update it's inventory?
Also, I just realized JNUC 2026 starts on a Wednesday, ends on a Friday. 🍗🎉 Gives us time to protein up all weekend long with some bbq. 🍖• Link here
A Read-only Friday post by William Smith Only those in IT would ever get it. My dad loved listening to a radio broadcaster named Paul Harvey. Wow could that man tell a story! (I’m referring to the radio broadcaster, but my dad knew how to draw a crowd of listeners too.) Paul Harvey ended his daily broadcasts with a segment called “The Rest of the Story”. He would generally start with a seemingly simple and banal story about something or someone. But as he told the story, the details would take on some life, and the tale would grow bigger until he revealed the one key element he’d been holding back that tied everything together. A really weak glue was of no use at all ‘til an office secretary found a use for it… “And that’s how Post-It Notes were invented!” Or an author was shaving one morning and thought of a story but for years no one would buy it… “Until one day Frank Capra decided to produce it as It’s a Wonderful Life.” Harvey would end every one of these stories with his signature
From a security finding our Infosec team has task us with finding a way to “Enable any settings that can prevent download of unwanted and/or malicious software”. has anyone been able to prevent downloading in Safari and Chrome?
By using Jamf Pro to revoke the administrator privileges of users, we are now facing a problem. Applications like Cusros have a very high update frequency. However, we don't want to simply and brutally grant the users the administrator privileges and let them complete the automatic update by clicking once in the Self Service. Do you have any suggestions on how to solve this?
Is it possible to deploy the OneDrive plist config file via jamf or does it have to be packaged in composer so it installs in the correct location?
Since July 4 I haven’t seen any Daily Digests. Did they get turned off as part of the upgrade to the new JamfNation?
Hi All, We are running JAMF Pro on the local server / on prem "Windows Server" (not the cloud version). I want to use the Patch management to update the Apps (Chrome, Firefox VLC Office apps etc..), macOS etc.. I'm new to this is there any way I can get some help to set up this? Article videos etc..
This might be a silly question but is there no way to search for a mobile device by it's Jamf Pro Management ID in the web ui? I couldn't find any filter options for it in advanced search.Not the Mobile Device ID but the Management ID.Thanks in advance!
Hi all,I am trying to do a user initiated enrollment on a Mac Neo. I’ve done this same user initiated enrollment on many other Macs without issues, but this one only accepts some configuration policies and no packages can be scoped to the machine. Additionally, on my Jamf Pro instance, it says that the machine is not managed.I have already done sudo jamf policy commands and updated the inventory, but that hasn't changed things. There don't seem to be any policies in Jamf Pro that I can scope to the Mac. The Mac is not listed under computers that I can scope, however, the Mac does show up when I click on the inventory tab.Has anyone seen this before where the device shows up in inventory but remains unmanaged and unscopable? Any suggestions?
DDM Software Update is working fantastic for the most part.Majority of the fleet has updated.I’ve created static groups to act as manual rings. I have few stranglers that will not update. There is enough storage, user has secure token, computers are ADE enrolled. Computers are checking in.I have the following screenshot from one endpoint.Management, Operating System shows “No Updates in progress”.How do I fix this?
I was trying out the Jamf Return to Service app and it wiped my Verizon esim. Does anyone know how to prevent that from happening? I don’t see a key in the documentation and I do have a restriction set up to enforce preserving the esim on an erased device. Edit: it looks like i got it back by toggling on the Verizon service in the settings after a network reset, but I thought the Jamf RTS app was supposed to preserve that setting?
I have been working on jamf setup manager and wanted to get some inspiration and see the creativity of other minds in the community. Currently I just have it wait for user entry for the users email and machine name and then it installs chrome enterprise and office 365. I want to try some role based access and install applications depending on the role of the user entered in the beginning, I got some ideas brewing.
We’ve been testing Self Service + (deployed via a policy since we can’t use Jamf Cloud Services). First impression is: why did they change what the user first sees when they open Self Service?In Self Service classic the user would see the items that they can run. Now in + they have to click in a few spots to get a list of items to run - aren’t we going backwards in making this easier for our end users?I hope that Jamf will provide some way to customize this behaviour - I want to be able to specify what section of of Self Service + loads at startup. I also don’t like that our administrator account is listed on that initial screen that loads - would be good to be able to suppress that completely since we don’t use Jamf Connect. And does anyone know what Jamf means by deprecating classic Self Service? Is it simply not going to function anymore or will it simply not be updated? And is it not going to install on new Macs and will it be removed from existing Macs automatically - could we ove
Jamf clients can not connect off campus to our Jamf Pro server DMZ server. Our F5 is forwarding off campus traffic on port 8443 to that DMZ server and port 8443 is open. Connecting off campus to the Jamf console on the DMZ server in a web browser with the same URL Jamf client uses works. The client is getting a 403 error.
When trying to resolve certain messages in the notfication page, the following error is coming up - Our development team is notified about this problem. Problem identification: #52c7d9c084285505This has been happening for some time and I was wondering if anyone has been able to come up with a solution.
I am trying to create a cloud distribution point using Amazon S3. The JSS returns the error: Unable to create distribution for this bucket But when I check my buckets there is a bucket similar to jamf235a039ede4741fe831b0e31287c6c7d created. Anyone have any luck with this?Thanks!
Hi, Im currently working on setting up Self Service+ in time for the deadline of March 2026. We currently have over 400 machines with Self Service instaleld and looking to deploy this to new machine in batches first for testing. Ive currently been testing on my self and manually installed the application and Ive had some issues with the Keychain popping up, which I saw was an issue on past threads. What would be the best way to go around this in a production environment?
Good morning, I am currently working with a MacBook that is on preparing a script to help my team to control power settings. At this time pmset does not have a direct way to change this setting via terminal. I also do not see any configuration profiles settings that allow us to set the limit either. Has anyone else tried to test the charge limit on MacBook?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!