Get Support
Recently active
Today we are releasing a maintenance version of Jamf Pro; highlights include: Resolved IssuesJamf Pro Server: Security IssuesJamf provides the CVE-ID for security issues with high or critical severity when possible.[PI148977] Fixed: A security vulnerability in the Jamf Pro API.Jamf Pro Server[PI134850] Fixed: Packages with special characters in their filenames appear to upload successfully to the Jamf Cloud Distribution Service but are unavailable until renamed or re-uploaded. For additional information on what's included in this release, review the release notes via the Jamf Learning Hub.To access new versions of Jamf Pro, log into Jamf Account with your Jamf ID. The latest version is located in the Solutions section under Jamf Pro. Cloud Upgrade ScheduleYour Jamf Pro server, including any free sandbox environments, will be updated based on your hosted data region below. Review this guide if you need assistance identifying the Hosted Data Region of your Jamf Cloud instance.To upgrade
Hi, The available guide is for JAMF Pro. Any advice for JAMF School how to deplay the XML? Thank you
Hi,I am experimenting with Compliance in Jamf Pro. I setup CIS lvl 1 monitoring as a start and without any Azure connection. But somehow it keeps giving the error: “Management settings deployment failed”. We run 43 Macbooks, all rolled-out with DEP and correct registered in Jamf (and Protect). Any idea?
Hi all, I'm trying to upload a guidance from Compliance Editor to Jamf pro. I'm at the portion where it's asking for a client ID and secret. I haven't used the jamf API before and I know you need to create a API role first, but I'm not sure what privileges I would need for a compliance editor upload.
I am currently using an iphone 16 as a work phone and on our last cruise (MSC) the phone was not able to connect to the ship’s wifi. I was told by the cruise line that it was because of Jamf protect running on my phone and that was blocking the phone from recognizing the wifi signal since it was a new wifi network. I have had this same issue in the past while attempting to connect to a wifi network in a hotel or restaurant that was not a typical network for my phone. I am trying to figure out if this is indeed correct or if there are settings on my phone that should be toggled on or off to allow it to access the internet through a wifi network that is not familiar to my device. Any help would be appreciated.
We are facing issue with screen recording permission. To unlock security and privacy the device is asking for admin username and password. First of all, we don't know who those admin creds are. Second, we want to allow all users to be able to access security and privacy. This issue arrived only after we configured jamf connect with Azure AD. Not sure how to resolve it.
Hi Jamf Nation, we're thrilled to announce that compliance benchmarks capability in Jamf Pro is now generally available! This release transforms how your organization manage compliance across Apple devices, making compliance validation and enforcement simpler than ever before. Benefits At the heart of this new capability is a streamlined approach to security compliance: Quick Setup and Implementation - we've integrated both CIS Level 1 and Level 2 benchmark templates from macOS Security Compliance open source project (mSCP) to allow rapid deployment of compliance rules. Using compliance benchmarks, IT teams can quickly create compliance configurations across your organization. Flexible Options - IT teams can assess compliance status in monitoring mode before enforcing changes, allowing them to understand impact and prepare users. This provides a risk-free way to evaluate compliance status without disrupting productivity. Automated Remediation - when devices fall out of com
We currently are not syncing our ASM data over to Jamf. We are, however, using Jamf Teacher in some small instances by mnually creating Classes. We are manually creating rosters for a credit recovery classroom where students come and go. The result in Jamf Teacher? A Jamf Teacher roster that is not alphabetized. The credit recovery facilitator sees students who were in there “first” by the IT department’s selection and Save. Each new student added just gets appended to the end of the Jamf Teacher roster in the Jamf Teacher app. This makes it a mess for selectively adding or removing lesson restrictions for an individualized experience.Has anyone figured a way around this?It would make sense for the app to have a sort option built in, but it doesnt!
Today we released Jamf Connect 3.6.0. This release includes the following: Changes and ImprovementsThe Jamf Connect login window now includes Dutch as a supported language. The authchanger command-line tool now recognizes Microsoft's macOS Platform Single Sign-on (SSO), allowing administrators to safely use the authchanger -reset command without affecting deployments of macOS Platform SSO. For more information, see macOS Platform Single Sign-on overview in the Microsoft Entra documentation. In Jamf Connect Configuration, the Quit and Preferences options in the "Hidden menu items" section are now selected by default. Additionally, the About option is no longer available. Resolved Issues[PI140308] Fixed: When switching networks from the Jamf Connect login window, disconnecting from Wi-Fi and attempting to reconnect will prompt users for the Wi-Fi password instead of connecting without a prompt. [PI144503] Fixed: The Jamf Connect login window presents the following error after entering
JAMF Nation, I am trying to configure a plist file to disable Bluetooth Sharing. It appears this could be done in com.apple.Bluetooth in the "By Host" folder of preferences in finder. (Users/$user/Library/Preferences/By Host) I have come up with the following plist, when I push it via the JSS it is installed on the endpoint but the setting isn't enforced. Has anyone enforced this setting in this manner? Additionally I am aware of the JAMF Github with the CIS benchmarks and @franton Github with the benchmarks as well. I would just like to enforce this via config profile if possible. <?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"> <plist version="1.0"> <dict> <key>PrefKeyServicesEnabled</key> <false/> </dict> </plist>
Hello Jamf Nation!We’ve released Jamf Pro 11.25.0 beta. This release includes Branding Self Service+ for macOS via Jamf Pro, Improvements for OIDC-Based Single Sign-On Through Jamf Account and more.How to join the beta: Enroll in the Beta Program under Product Feedback at account.jamf.com. Click “Join Community” to join the beta forum once enrolled. Please also check out this recent blog on Configuring SSO in Jamf Account prior to testing Compliance Benchmarks, Blueprints, and App Switcher.Email beta@jamf.com with questions.The beta program is covered by the Jamf non-disclosure agreement; please do not share any information regarding your testing on any public forum, including the non-beta areas of Jamf Nation. Use the Jamf Nation Beta Forum or contact Jamf via beta@jamf.com with any questions. Thank you to all who participate in this program!
Hi All,we currently use Jamf School to manage our iPad estate. it works great for what we use it for, but the goalposts have been changed on us.Moving forward, Cyber Essentials requirement are set to change so that our devices need to be trusted. Our trusted IP address will no longer satisfy the requirements. So we will need to add our devices to Microsoft Intune. I believe that this is configurable with JAMF Pro, but not JAMF School. Is this the case? Is this a feature that will be added in the near future?We are currently having to evaluate using Microsoft InTune as an MDM alternative to JAMF School if it cannot fulfill this requirement, and it is already covered in our Microsoft Licence.Any advice would be much appreciated.
We are using Jamf School to send a profile that blocks certain apps on student tablets from 8:30 AM to 3:00 PM. However, for the past few weeks, this profile—and all other profiles—activate as scheduled but then get removed by themselves after 5-10 minutes, causing a continuous loop of removal and reinstallation throughout the day. Has anyone experienced this issue or knows a solution to prevent profiles from repeatedly removing themselves?
I just found out that Microsoft Office has been automatically saving all files to the cloud for several months. I would like to disable this feature for my environment via Jamf Pro. I guess the easiest option would be to uncheck “Enable automatic saving by default” in Office via Configuration Profile. Where can I find the plist that controls this setting? Are there other ways to set this centrally via Jamf Pro?
Hi everyone,I need help understanding the correct way to disable password sync in Jamf Connect while still using Google Workspace authentication during ADE enrollment.Our current setup (Jamf Connect + Google Workspace + ADE) behaves like this: During initial login, the user signs in with their Google Workspace account Jamf Connect creates the local macOS user account based on the Google workspace account (First name and Last name) The initial local mac password is set to the Google password If the user later changes their Google password, Jamf Connect detects a mismatch and prompts:“Your local password and network password are different. Please enter your local password to sync.” Once the user enters it, the Mac password gets updated to match the new Google password What we want instead: Users authenticate with Google Workspace ONLY for the first login Jamf Connect creates the local account After that, the macOS password and Google password must be completely independent
We have one user with a Macbook Pro M1 Laptop. Big Sur is installed on the machine and the logged in user is a Mobile Account and has admin rights. File vault 2 is also enabled.Deployment was some month ago and everything worked fine. Two days ago the user approached me as he was not able to login with his account credentials at home. He was in the office yesterday and after I logged in with my local admin account everything was fine and he could work. So told him to also to update his Big Sur installation from 11.2.x to the latest version 11.5.2. But as he tried to enter his password the following screen states that Authentication is disabled.I grabbed this screenshot from the internet cause our dialogue is in German.Anybody have seen this? Where does this come from and how can we fix this? I would greatly appreciate your help.Thanks
Hello everyone!I’m currently going through a PCI audit process and we need to collect logs for specific events within macOS, we aim to do this with Jamf Protect (Telemetry, Analytics, Unified Logging, whatever fits best honestly). But having rather low success so far, given the amount of noise we get from, probably, too general predicates.Have you had to set this up? Do you have hints or tips (or, even better, your analytics/filters)? This is the list of events we want to get logged: a. all administrative actionsb. accessing audit trailsc. invalid access attemptsd. successful access attemptse. elevation of privilegesf. creation/deletion/changing an account with admin privilegesg. start/stop/pausing of audit logsh. creation of system-level objects Thanks in advance!
We're having an issue with the Jamf Setup app (iPadOS) displaying in single app mode. We've configured the app so that the user can enroll their device during the process with Entra Login. However, the Jamf Setup app requires Safari to display the Entra registration window. Unfortunately, when I launch the Jamf Setup app in single app mode, I can't enroll my device because the Entra registration window doesn't appear. I don't want to use the "restriction" profile to only allow Jamf Setup and Safari, because our users might simply browse with Safari without registering their device. Do you have any suggestions or experience on how I can lock my iPad in the Jamf Setup app and registering the device using Entra Login?
Here’s the problem we need to address: many of the things IT teams do aren’t documented because they’re seen as busy work, there’s no time, people forget, or they just don’t want to. But here’s the thing: documentation may take some time, but it takes exponentially more time to research a solution every time you need it. For example, it might take 20–30 minutes to create a quality document. Researching a solution can take 10–15 minutes, and if you need to research it 2–3 times, that’s 20–45 minutes of research. Meanwhile, it only takes about 5 minutes to re-read a well-written document. So, let’s get started on how to do this. It happens all the time: you figure out a solution or process, implement it, and move on to the next task on your never-shrinking to-do list. A few months later, you need to do the same thing again and must dig through scripts, tickets, blogs, Slack, or wherever you found the solution, trying to recreate it. It takes a lot of time, and you think, “I really should
I am having a separate issue but need to submit ticket. When I log into Jamf Account and try to click the “Contact Support” button, nothing happens. Is anyone else experiencing the same issue?
I’m trying to deploy a Mac App that was purchased through Apple School Manager VPP.When I go to Computers → Mac Apps → App Store and add the app from the App Store, I can find the app and click Add, but the page spins and never moves past for me to actually finish adding the app to my tenant. I’ve checked the VPP token and ensured everything is connected properly. This is not an issue when working in the Devices, only when adding apps from the app store for computers.
Hi,Could any one guide on how we can migrate data between two managed macOS devices and same for iOS devices?
We’ve been using a script that automatically downloads and installs the latest version of Google Chrome when we push a prestage policy to our Macs. This script no longer works on Tahoe. This is the error that shows up in the logs:Script result: Wed Jan 21 16:08:00 CST 2026: Create temporary directoryWed Jan 21 16:08:00 CST 2026: Download 'https://dl.google.com/chrome/mac/universal/stable/GGRO/googlechrome.dmg' Wed Jan 21 16:30:23 CST 2026: Check downloaded DMG hdiutil: attach failed - no mountable file systems find: : No such file or directoryI’d like to find out how I can update this script to work with Tahoe. Here’s the script we’re currently using:#!/bin/bash bundle="Google Chrome.app" tmp="/private/tmp/GoogleChrome" echo "$(date): Create temporary directory" mkdir -p "${tmp}" echo "$(date): Download 'https://dl.google.com/chrome/mac/universal/stable/GGRO/googlechrome.dmg'" curl -s -o "${tmp}"/"GoogleChrome.dmg" "https://dl.google.com/chrome/mac/universal/stable/G
Is there a way to send alert messages to iPhones manage by JAMF. I can do it in Mac via policy using the JAMF helper. Is there a same method in doing this to iPhones?
Hi! We finally upgraded Bomgar or BeyondTrust Remote Support to 24.3.2 to support Sequoia. The only issue I'm having is finding a way to allow standard users to toggle on, or allow applications in System Settings > Privacy & Security > Remote Desktop.I didn't see anything in the PPPC Utility tool and wasn't able to find anything in Jamf Pro under the Privacy Preferences Policy Control config settings. Wasn't sure if it's possible to allow currently or not but thought I'd ask here.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!