Get Support
Recently active
How can I manage the new* AI Controlswithin Firefox with a Configuration Profile?Is there a way to configure it via a JSON?Thanks in advance!
I have successfully setup PlatformSSO for EntraID authentication and after running it for a while I have some oddities.If the token expires Safari will offer passkey as an option for logging into EntraID federated applications. Our conditional access policies allow passkeys, MFA, Strong Auth (FIDO etc). Once the login is complete the Mac will passthrough creds for any access in any browser.If the token has expired then in non-Safari (Edge, Chrome and Firefox) the user is only offerred password as the option to login unless they have a passkey in Authenticator or an external FIDO token registered in EntraID (Yubikey etc).If you go to User/Groups and press the Authenticate button in the user account then the token is refreshed without any user interaction.Trying to work out if I’ve missed something in the config profile or if there is another issue.Anyone else seen similar and worked out a way to resolve so passkey/biometrics is offered across all browsers rather than just Safari?
Having worked at Jamf for nearly a decade, I’m so humbled to learn and grow amidst some incredibly smart, capable and kind women - both colleagues and customers.Just to name a few: @KatieE, @ktrojano, @woaikonglong - you’ve been bright lights in the tech space, for myself and the broader Apple community. Thank you for sharing your wisdom to help those around you! And of course, to @LysetteB and @JoannaB - thank you for all the hard work and dedication you put into serving our customers. I’m grateful for your partnership every day!☀️ Do you know a woman who deserves some recognition? Let her know below! ☀️
With the release of MacOs 26.3.2 for the Macbook Neo only today - all of our other Mac devices fail to enroll through prestage enrollment when the minimum version is set to ‘Latest Based on Device Eligibility’. It seems the 26.3.2 update is trying to be installed on non-neo macs and it fails the process.I’ve set the requirement in our environment to specific version - 26.3.1 and I am testing it currently. I assume this is more an Apple problem than a Jamf problem however. ETA: Dropping it to a specific version fixes the issue.Image below is from a MacBook Pro (14-inch, Nov 2023) [M3 Pro] model.
As MacAD.UK approaches its ninth year, and the tenth anniversary of its very first gathering, the conference has become a fixture in the Mac admin community. What began as a small, ambitious idea from a handful of passionate techs has grown into one of the most recognizable Apple admin events in Europe. This year marks another milestone: a move to the iconic Brighton Dome, a venue that has hosted musical legends To understand how MacAD.UK evolved, what makes it different from a typical tech conference, and why the community keeps coming back, we sat down with the organizers, Liam Donnelly, Ade Leader, and Alex Hawes to talk origins, ethos, and the moments that remind them why they do this work. Macaduk is now in its 9th year. What was the spark that started it all, and did you ever imagine it would grow into what it is today? The event was started by a couple of senior techs at Amsys, including David Acland, who was our CTO at the time, and Dean from Jamf, if I recall correctly. They
I asked this same question on the Clearpass forum, in case there are more people there that are doing similar things, but I'm hoping for someone with the conceptual understanding to just give me a nudge in the right direction regarding this setup. We have been using 802.1x with Machine certificates issued by AD, with ClearPass and Windows machines for a couple years now. I understand the process that the windows machine joins the domain, get's a certificate, and then our clearpass servers are domain joined and can authenticate the machine with Active Directory using some of our various AD servers. All of that works well, and makes sense to me. Now we're extending it to macbooks and adding Jamf, so that we can also set up certificates on the macbooks (they will not be domain joined) via SCEP/NDES integrated with our windows CA, with the goal of them also doing 802.1x with EAP-TLS. So far, we have the SCEP process working fine, and the macbooks obtain their certificates from our CA via S
I am wondering if it is possible to block a managed iPad from using a mobile hotspot as a connection. I did not find anything in the documentation or configuration profiles that would block using one, only disabling the device from being the hotspot itself. My goal would be to restrict this option from students who have personal devices in an attempt to circumvent filtering. So far our filters do not care but it is also another distraction tool.
This is more of an informational post that hopefully helps someone one day. I recently discovered a weird situation where if you have an Extension Attribute script that contains a particular single character it completely breaks the entire Jamf tenants ability for any Macs to update inventory.Notice the difference in the two images. The first is my view in my script editor (CodeRunner in this case). The second is the view of the script in Jamf while editing the EA. There is an odd character on the third line that appears to be an invisible backspace (apparently ctrl-H). I verified that it does show in multiple web browsers, just not in CodeRunner (does show in SublimeText).Aside from finding the bug in the code eventually, if a script contains this character in particular, just having the script active seems to break Jamf’s ability for devices to recon. Once I enabled the script, ALL Macs started receiving the following error. sudo jamf recon -verboseverbose: Timeout: 10verbose: Checki
I’ve created the below xml file for Chrome in Jamf School but students can still delete browsing data. Does anyone know what key I’m missing? <?xml version="1.0" encoding="UTF-8"?><!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN""http://www.apple.com/DTDs/PropertyList-1.0.dtd"><plist version="1.0"><dict> <key>IncognitoModeAvailability</key> <integer>1</integer> <key>BrowserSignin</key> <integer>0</integer> <key>SyncDisabled</key> <true/> <key>AllowDeletingBrowserHistory</key> <false/> <key>SavingBrowserHistoryDisabled</key> <false/> <key>SearchContentSharingSettings</key> <integer>1</integer></dict></plist>
Hello Has anyone else lost access to Blueprints & Compliance from Jamf pro this afternooon. I still have permissons, but seem to no longer be able to access them. Get the same if I try another account that should have permissons as well.
Need help installing an in-house Chrome extension. This is what I’m using but isn’t working.<?xml version="1.0" encoding="UTF-8"?><!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"><plist version="1.0"> <dict> <key>ExtensionSettings</key><dict> <key>Extension ID</key> <dict> <key>installation_mode</key> <string>force_installed</string> <key>update_url</key> <string>https://URL/Extension.crx</string> </dict></dict> </dict></plist>
Is this supposed to happen? Our automatic upgrading of the Self Service+ app has changed back to /Applications/Self Service.app (was /Applications/Self Service+.app). Also is prompting for keychain access since, well, the application name changed. Anybody else?
Is there anyone here who is already using Jamf School integrated with Jamf Connect and Self Service+?I found the article below, but the information seems a bit inconsistent.This link explains how to deploy it:https://support.jamf.com/en/articles/13550577-deploying-jamf-connect-self-service-with-jamf-schoolHowever, in the tutorial it includes a Jamf Pro video, not a Jamf School example:https://trainingcatalog.jamf.com/path/get-started-with-jamf-connect/prepare-to-configure-jamf-connect/614276Also, based on the technical documentation in the following link, Self Service+ does not mention Jamf School, and only refers to Jamf Pro:https://learn.jamf.com/en-US/bundle/self-service-plus-documentation/page/About_Self_Service_Plus.htmlThere are also a few other things I noticed: In Jamf School, there is no option for “Make apps available in Self Service.” In the Jamf School settings, there is no menu for Self Service+ or branding options. If anyone has already tried this setup, I would really
From here https://learn.microsoft.com/en-us/defender-endpoint/mac-jamfpro-policiesAdded configuration profile Microsoft Defender – Scheduled ScansEveryday at 14:45 and Wednesday at 10:00 <?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"> <plist version="1.0"> <dict> <key>features</key> <dict> <key>scheduledScan</key> <string>enabled</string> </dict> <key>scheduledScan</key> <dict> <key>ignoreExclusions</key> <true/> <key>lowPriorityScheduledScan</key> <true/> <key>dailyConfiguration</key> <dict> <key>timeOfDay</key> <integer>884</integer> <key>interval</key> <string>1</string>
we are currently experiencing an issue with our iPads managed via JAMF School.Since yesterday, all apps on the devices are hidden except for the Settings app.Key details: The devices are managed with JAMF School. Some restrictions are configured in the profile. No changes have been made to the configuration recently. Everything was working correctly until yesterday. If we disable the profile, all apps appear again as expected. Age rating is set to 16+. There are no apps configured in the allow list or block list. Could you please help us identify why the apps are being hidden and what might have caused this behavior?Thank you in advance.Best regards
All, after extensive testing, logging, and analysis the longstanding, intermittent issues affecting the managed endpoints in my enterprise has been traced to how the policy decision engine in GlobalProtect handles traffic destined for our cloud instance.To further explain:For some time upon execution of jamf commands (policy, primarily) in terminal following has been seen:“An error occurred. There is no message.”Subsequent runs would be successful. Nevertheless log captures of “mdmclient” and “com.apple.ManagedClient” are replete with various and sundry errors. Correlating these with netstat commands shows that jamf policy would be begin execution over the VPN tunnel (utunX)… and then quickly gets denied and directed to physical interface (en0). That this occurs, regardless of how quick, during initial TLS handshake hasn’t really helped matters.Further attempts running jamf terminal commands shows that while most traffic appears to head out via native interface some was now allowed via
Hello all.I am getting this error in my notifications when I login to Jamf Pro. I cannot seem to determine what is wrong with this, and it appears that our Jamf Connect configuration is working properly. Thanks in advance.-Pat
Today we are releasing a maintenance version of Jamf Pro to address the following product issue:Jamf Pro Server[PI-1068] Fixed: Mobile device smart groups and advanced mobile device searches using the "Device Ownership Type" criteria with a manually entered value incorrectly include institutional devices.Note: Smart group membership will correct itself as mobile devices check in. To speed up the recalculation process, administrators can edit and then save any affected smart group. For additional information on what's included in this release, review the release notes via the Jamf Learning Hub.To access new versions of Jamf Pro, log into Jamf Account with your Jamf ID. The latest version is located in the Solutions section under Jamf Pro.Subscribe to product alerts to receive real-time updates.
Overview This document walks through how to configure and use temporary privilege elevation on macOS using Self Service+.End users can request temporary local administrator rights directly from the Self Service+ app, authenticate via Touch ID or password, provide a business reason, and receive time-limited elevation, all without IT intervention.The elevation duration, reason requirements, authentication requirements, and permitted reasons are all administrator-controlled via a Jamf Connect configuration profile deployed through Jamf Pro.PrerequisitesUpdated: 3/6/25- To add clarification to Prerequisites Before following this guide, ensure the following are in place:Self Service+ v2.0 of greater installed on the target Mac. Jamf Pro access to create and deploy configuration profiles. The target Mac is enrolled in Jamf Pro. A valid Jamf Connect licence assigned to the device or user. Walkthrough Step 1: Configure the Jamf Connect Preference Domain in Jamf Pro In Jamf Pro, create a new co
Today we released Jamf Connect 3.5.0; this release addresses the following product issues: [PI143260] Fixed: Importing a configuration profile into Jamf Connect Configuration with the User Promotion Choices (UserPromotionChoices) setting in use causes the array for the setting to be replaced by the following text: (. [PI143263, PI144134] Fixed: Jamf Connect presents the following one-time prompt on computers with macOS Tahoe 26.1 beta, both on the login window and on the desktop: Self Service+ wants to use your confidential information stored in "Jamf Connect" in your keychain. [PI143435] Fixed: When RapidIdentity is the identity provider, the Jamf Connect login window requests the local account password during the password verification workflow instead of the identity provider password. To access new versions of Jamf Connect, log in to Jamf Account with your Jamf ID. The latest version is located in the Solutions section under Jamf Connect.Product DocumentationFor additional informati
We are upgrading Standard Cloud environments to a maintenance version of Jamf Pro which addresses the following product issue:Jamf Pro Server[PI-1068] Fixed: Mobile device smart groups and advanced mobile device searches using the "Device Ownership Type" criteria with a manually entered value incorrectly include institutional devices.Note: Smart group membership will correct itself as mobile devices check in. To speed up the recalculation process, administrators can edit and then save any affected smart group. Cloud Upgrade ScheduleYour Jamf Pro server, including any free sandbox environments, will be updated based on your hosted data region below. Review this guide if you need assistance identifying the Hosted Data Region of your Jamf Cloud instance. A full general availability release is being scheduled for the week of 9 March.Subscribe to product alerts to receive real-time updates. Hosted Region Begins Ends ap-southeast-2 8 March at 1300 UTC 8 March at 1900 UTC ap-northea
Does anyone else get the Device is busy, will try again response or just stays pending when pushing configurations to a locked ipad or iphone? Even update inventory just stays pending. This is happening to us consistently and magically works when the device is unlocked. Any fixes for this or is this by design?
Hi everyone! My team is currently exploring the implementation of LAPS into our workflow, and we’d love to hear from those of you in Education (or similar sectors).For those who have made the jump: how has the experience been? Specifically, I'm curious about the initial setup complexity and how user-friendly the password retrieval process is for your team. Also, from a security standpoint, do you find that simply rotating the local admin password provides enough protection, or are there other factors we should consider? Thanks in advance for any insights.
Microsoft has put a new “unlock premium” button in teams. Has someone found plist / custom profile setting to disable this?I don’t see teams as an option in iMazing Profile Editor.
I am having an issue creating a PreStage enrollment in Jamf Pro, The 'New' PreStage button hangs immediately on click. I have verified the ADE token is new and UIE is enabled. I just see a spinning wheel when I click New to create a PreStage enrollment for Computers. The Devices/ios one works fine. I did try chrome, firefox, safari browser, same issue.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!