Get Support
Recently active
We are new to Jamf Now. WE have been experiencing issues with deploying apps to some of our phones. I have tried to re-enroll it, restore the phones, re-create the blueprint and create a different blueprint. I also updated the tokens. Has anyone encountered this issue? If yes, would you tell me what troubleshooting steps did you do?
Hi everyone, I'm deploying the Global Secure Access (GSA) client on macOS using Jamf, following the official Microsoft documentation:https://learn.microsoft.com/en-us/entra/global-secure-access/how-to-install-macos-client The installation completes successfully, but on first launch, users are still prompted with the message:"Global Secure Access Client would like to add proxy configurations." Does anyone know how to pre-approve or automatically allow this proxy configuration request via a configuration profile or PPPC/extension setting? Thanks in advance!
We have had a PolicyBanner installed on our fleet for several years. We have not had an issue with it until users upgraded to 26. When the banner pops after user login, the window is stretched to almost full screen, regardless of screen size or resolution. Screenshot attached of my large screen monitor.I have tried editing the RTF file a few ways to change margins and it will change the text but does not affect how the window sizes.I have also tried changing Desktop & Dock > Windows to Prefer tabs to Always instead of Full Screen This screenshot shows after trying to change margin and text. I can share another with all the txt centered and nothing on the right of the txt but empty white space. Thoughts? Here is the original screen
Based on your feedback and a review of the potential impact of the Jamf Trust iOS/iPadOS 11.47.0 upgrade to your fleet, we delayed the rollout to allow additional time for preparation.Jamf Trust 11.48 is scheduled for release February 25, 2026 at 9:00 AM UTC. This update resolves the network connectivity issue that could affect devices running iOS/iPadOS 26.1 during the Jamf Trust update. This release replaces the previously paused 11.47.0 rollout.We continue to recommend updating devices to iOS/iPadOS 26.2 for the best experience. Only devices running iOS/iPadOS 26.2 or later will receive new versions of Jamf Trust, 11.48.0 included.For more details, please refer to the Jamf Nation community post: Action Required: Update Jamf Trust App on iOS/iPadOS 26.1Need Help? For additional questions or assistance, please log in to Jamf Account with your Jamf ID and click Contact Support in the upper right-hand corner.
I get a Lego block icon when trying to login to a Mac on a domain. It doesn’t happen on all computers. I recently wiped a MacBook, that I could log into, however, after enrollment... now I get the Lego block icon. I can log in with other accounts.I believe it has something to do with the AD binding and possible VPP issue (my logs have been flooded with VPP Invitation Usage notifications). I don’t know how to fix it.Any help, would be greatly appreciated.Thank you.
I have been checking my Change Management logs .. and I have hundreds of VPP Invitation Usage logs - is this normal, is it causing other issues?
Morning,Anyone else experienced this issue since updating to Logic Pro 12 - We’ve got Jamf Pro at my org and currently push out Logic Pro via Apps store on Jamf which takes care of the updates and deployment to our various smart groups but since updating to version 12 yesterday we receive this error everytime we launch LP: The application cannot be used because the App Store authentication failed or no Network is available.Any ideas?Any advice or tips is greatly appreciated.
Hello there everyone, I have come across a very weird issue lately.Any policy that I add to Self Service+ fail to run, while if I open Terminal and run jamf policy -event TRIGGER it works like a charm.The policy does not matter it if includes a package or a script. It has been driving me nuts.Tried on different machines and re-installing Self Service+ app. Thank you in advance,Spyros
Hey everyone!We are relatively new to Jamf School and iPads in general for our district!We come from a Chrome environment so of course there are some abilities we had with GAC that we would like to emulate with Jamf School! Are we are to lock Chrome or Safari to only sign-in/authenticate with our @Domain accounts? Our fear is that students will just be able to login to any personal account and message/interact with each other that way (our admin is very pro-restricting student's virtual communication platforms).I appreciate any and all help!Thanks all,
With Jamf Pro 11.25, customize the application name and icon of Self Service+, adjust the session duration and inactivity timeout with Jamf Account enhancements, and use your Jamf Pro server to host enrollment information for account-driven enrollment!Be sure to check out the Jamf Pro release notes for all of the exciting new features and enhancements.Thank you for your continued support and feedback!
We’re moving some devices from Jamf to Intune now when the new fuction with OS 26 is in place with School and Business Manager.We have encountered problems with two units so far, that you can't specify a date for the change. With that, it doesn't seem like they are being moved as intended and need to be deleted the old way. Does anyone know what could be causing this and/or if there is a solution?
Hey Nation,I’m normally not one to jump on a trend but this one was too fun not to! Who’s up for sharing theirs??Head to ChatGPT (I know it’s already open so shouldn’t take you long 😂) and ask: “Create a caricature of me and my job based on everything you know about me.”Here’s mine! Post yours in the thread 🧵! I can’t wait to see them all!!!
Hey There! Is there any way to obtain free voucher for Jamf 100 certification?
Even when Erase All Content and Settings is restricted, the option “Erase This iPad” still appears during sign out.Will it be possible to restrict this as well?The same behavior occurs even when using a Managed Apple Account...
HI everyone,I am trying to implement JAMF Connect in our organization. I was able to successfully configure the OIDC, but while testing the ROPG, I am getting the attached error. I have confirmed that the client secret ID is correct, as the ROPG login is working for just one account. Also, all the users have been given access to the Enterprise Application. Any leads would be helpful. Thanks
Has anyone successfully managed the following Safari settings via Jamf Pro (macOS and iPadOS)?• Hide IP Address from Trackers • Prevent Cross-Site Tracking (I have disabled this in Safari on Macs with the “WebKitPreferences.storageBlockingPolicy” key.We are trying to determine whether these can be enforced through a configuration profile or other supported method, rather than relying on per-user changes. This is for lab or classroom environments,If you’ve implemented this, could you share:- Whether it’s working on macOS, iPadOS, or both - The payload/key used (if profile-based) or the approach taken Thanks in advance for any insight!
Hi everyone, we’re currently testing Platform SSO (Secure Enclave) in combination with the Kerberos Single Sign-On Extensionon our Macs (managed via Jamf Pro).Since enabling Platform SSO, we’ve encountered issues with password synchronization as well as Single Sign-On authentication for ADFS-based web applications. As soon as Platform SSO is enabled, users receive the following prompt either after some time or following a reboot:Password SynchronizationVerify your Active Directory and Mac passwords. If they do not match, your Mac password will be synced. The passwords are identical (local macOS login = AD password). However, this prompt appears repeatedly — and only when Platform SSO is active. Additionally, our ADFS-based web applications (intranet portals, internal sites) no longer perform automatic Single Sign-On once Platform SSO is active.I’ve tested this behavior in multiple browsers (Safari, Chrome, Edge, and Firefox), and in all cases, users are prompted to sign in manually.Whe
The criteria Postion in the User and Location for iPad users was removed. Not all user... Any ideas why? I can’t find that anything was changed in Jamf.
In macOS 15, the new Private MAC address settings is enabled by default, and there is a new settings in Profile to disable it, BUT it's only for a spacified SSID. If you need a global setting to disable the Private MAC for all existed and new SSID, try to create a new policy to run this command: sudo defaults write /Library/Preferences/SystemConfiguration/com.apple.airport.preferences.plist PrivateMACAddressModeSystemSetting -int 1 It will not disable the Private MAC Address immediately, but it will work after forgot the network or reboot the computer.
as a systemadmin I really like the Mac Apps updates , both Jamf App catalog and App store. But as a user (and all our users) we get annoyed by the popups. The announcement popup I can understand, but the thank you popup after update is really not needed I think.Would be great if we can disable that.
When creating a smartgroup, there’s a criteria for Last Enrollment. But it’s based on the enrollment date, which does not always have a value. Those machines seem to be excluded from any search which uses the enrollment date criteria. How do you search for machines with no enrollment date?
Hello all, I am struggling getting OneDrive to silently sign in and redirect folders. I have researched previous posts, and am using Microsoft's guide here: https://learn.microsoft.com/en-us/sharepoint/deploy-and-configure-on-macos to no avail. Here is my configuration policy below -- can anyone take a look and see what I'm missing? I swapped out my real tenant ID with (Tenant ID) for the sake of sharing. Thanks for your help. <?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"> <plist version="1"> <dict> <key>KFMBlockOptOut</key> <True/> <key>KFMSilentOptIn</key> <string>(Tenant ID)</string> <key>KFMSilentOptInWithNotification</key> <True/> <key>KFMOptInWithWizard</key> <string>(Tenant ID)</string> <key>EnableSyncAdminR
Thanks in advance for your input...Our current scenario: our newly purchased iOS/iPadOS devices are automatically enrolled into Jamf Pro and then go into a default group. This group has a relatively restrictive Configuration Profile that prevents users from adding an Apple Account. If the user needs a different configuration or apps on their device, they need to submit a form to the device management team. From there, the device mgmt team works with the user and so on. Since we’re in education, we’re dealing with a full gamut of needs, business apps, engineering, utility/infrastructure, scientific, entertainment, media, development...you get the idea. So, we can’t anticipate ALL of the apps users want beforehand.Questions: what is your organization's workflow for newly purchased iOS/iPadOS devices? And how do you communicate to end-users where to go for additional support/apps/configs when they power on their new device?We're thinking either a wallpaper with messaging about reaching ou
This was reported to us earlier this week. iOS 26.x appears to break or override applied JAMF content filtering profiles with the addition of an “Add Website to Allowed List” button that appears on blocked websites. Thankfully this only seems to apply when using a content filtering profile set to “Limit Adult Content” and not the more restrictive “Specific Websites Only” setting, but if you’re blocking websites with the former and a user navigates to a restricted site, they can just tap this button and it overrides the applied profile to grant them access. Getting A LOT of complaints from some of our buildings that students are exploiting this to access websites that had previously been blocked. Not sure what Apple’s thought process was in adding this button...
Students are using Performance Matters but are just accessing Google Lens. We can open a Chrome window and type the following in the address bar: chrome://flags and it opens a settings window where you can enable and disable features but we are looking for a way to add an XML file to Google Chrome in Jamf School for our iPads to disable Lens Overlay. I have seen this XML file but I’m not sure it’s written for Jamf School:<?xml version="1.0" encoding="UTF-8"?><!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"><plist version="1.0"> <dict> <key>LensOverlaySettings</key> <integer>1</integer> </dict></plist> Has anyone had success in disabling Google Chrome Lens in Chrome from Jamf School?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!