Get Support
Recently active
Hi Jamf Nation! Exciting news - the JNUC 2026 Call for Sessions is officially open through April 10!Thinking about becoming a JNUC speaker? Check out the Speaker Prospectus for all the details. We can’t wait to see your ideas - submit your session here! Questions? Email us at jnuchelp@jamf.com
It would be great to introduce a more granular approach to scoping Blueprints in Jamf Pro.Having the ability to define exclusions within Blueprint scope would be extremely valuable.
Hi folks,I’m doing an audit of our config profiles and would like to break our baseline configuration profile into multi profiles. Right now, we have a massive baseline profile. If I need to edit a specific feature or settings, the whole profile gets push out everywhere.I would like to create smaller profiles that are specific to subsets of settings so I have more granular control over updating settings and the distribution of those settings.For example I may have profiles like the following as opposed to one massive profile:Baseline- Network UsageBaseline- FunctionalityBaseline- Setup StepsBaseline- Hidden AppsI can certainly created those subset profiles now without any scope assigned. My question is whether people have suggestions on the best order of steps to accomplish this task without the world exploding :-)For example, if I replicate everything currently in effect within multiple profiles, and I scope those new profiles to my all devices group, then I remove the current massive
Today we are releasing a maintenance version of Jamf Pro; highlights include: Engage Settings for In-App MessagingYou can use the Engage settings in Jamf Account to opt-out of web interface messaging or surveys. Opting-out affects all Jamf platform interfaces for your user account. For more information, see Profile Management in the Jamf Account Documentation. Resolved IssuesJamf Pro Server: Security Issues[PI149568] Fixed: A known vulnerability in a third-party library (CVE-2025-67735). [PI158236] Fixed: A known vulnerability in a third-party library (CVE-2026-25896).Jamf Pro Server[PI139067] Fixed: Jamf Pro may intermittently invalidate active JCDS download tokens, causing all cloud distribution downloads to fail with 401 errors until a new token is generated. [PI140295] Fixed: Advanced inventory searches and smart groups do not add criteria correctly if the selected criteria contains 2-byte characters. For additional information on what's included in this release, review the release
I’m a little bit disappointed about so much missing endpoints in the API. So many Informations about devices, groups, profiles that i can’t get or set over the API. I often like to write shell-scripts that could solve problems automatically, for example with profiles not installing, but because of missing endpoints for these functions i can’t and have to do it by hand. For example: Sometimes Apps on Devices use Single App Mode für Exam-Mode and stuck in it after that. Its not visible on the device but inhibit that profiles with whitelists can be installed. Thats a problem for profiles that are time based. The solution is to set this device in a profile with single app mode, wait until it is installed and remove the device out of this profil. But i cannot automate this, because the API have no Endpoint for installation status of profiles. So i cannot get a list of devices that cannot install the white list profile with a reason and also not the status if the repair profil is installed.
Hey guys, I'm in the process of testing Jamf Connect, I noticed this as a sign-in option Would it be possible to remove it since no one will use it to sign in to their Mac!!? I couldn't find any related settings in our Azure AD. Thanks in advance
Hello all,We are finally moving our labs away from AD, and our admins are setting up JamfConnect for authentication. I’ve been able to repurpose most of our apps/config profiles etc but I wonder if anyone has had success with WEPA and passing credentials via JamfConnect / PlatformSSO etc. TIA
Hello All, I can’t seem to make sense of this one. So I was looking at Patch management and Jamf Connect.Jamf Connect 3.7 came out recently, so I’m thinking I’ll add it to patch management.I look at the definitions and I see 3.14 as the newest, and there isn’t even a 3.7 listed.I am lost.-Pat
Today we released Jamf Connect 3.7.0; this release addresses the following product issues: [PI-923] Fixed: Authenticating via web view with Entra ID using a FIDO2 passkey prevents users from authenticating with Jamf Connect via the login window. [PI140159] Fixed: After two incorrect login attempts, the Jamf Connect login window fails to accept the correct password and prevents the user from authenticating after the lockout timer is complete. [PI152763] Fixed: The Sign In window displays two arrows that do nothing when clicked. Fixed: The installer for Jamf Connect does not force quit the Jamf Connect login window while deployment tools, such as Jamf Simplified Device Enrollment, are in use. To access new versions of Jamf Connect, log in to Jamf Account with your Jamf ID. The latest version is located in the Solutions section under Jamf Connect.Product DocumentationFor additional information on what's included in this release, review the release notes via the Jamf Learning Hub.
Anyone having a keychain issue and the onboarding window not opening automatically upon first login (newly imaged machine that hasn’t been logged into before)? Tried 3 times and get the same result.Self Service+ Version: 2.4.0Jamf Connect Version: 3.4.1Jamf Connect Preference Domain Version: 3.2.0macOS Version: 15.5 (24F74)
Reading documentation about 3rd party SSL certs and Jamf Pro. We are in the process of automating our Jamf Pro SSL cert renewal and I keep seeing that you need upload the 3rd party cert using the Jamf Pro interface. Is this that case? We already have a script for renewal that stops tomcat, edits the server.xml file with the correct cert info and re-starts tomcat. Do you also need to upload the cert into the Jamf console? is the cert also stored in the Jamf Pro DB?“Note:If your environment is clustered, you must log in to the Jamf Pro web app for each Apache Tomcat node and create or upload any SSL certificates for each node””This also comes up with migrating Jamf Pro to another server documentation (which we are also working on)
Dear community,I am facing a major issue with our Jamf Pro environment.We are running Jamf Pro 11.21 On-Prem and have several working PreStage enrollments—until today.I had a device that was already upgraded to macOS Tahoe. After erasing the Mac, I started the PreStage enrollment. The macOS installation completed normally, and the device enrolled in MDM.However, after the Setup Assistant finished, Self Service never appeared, and only half of the expected configuration profiles were installed.I waited over 30 minutes, thinking it might be a timing or network delay, but nothing happened. I also tried: restarting the Mac running sudo profiles renew -type enrollment manually installing Self Service.pkg and jamf.pkg copied from a working machine Even after manual installation, the agent could not connect to the server.It looks like the Jamf framework does not install correctly on macOS Tahoe during enrollment.Has anyone seen this behavior, and what could be causing it?Thank you in adva
If anyone runs into this when trying to install the Nessus Agent with Jamf Pro: Installation failed. The installer reported: installer: Package name is Tenable Nessus Agent installer: Certificate used to sign package is not trusted. Use --allow Untrusted to overwrite. I have a fix. Thanks to Bartłomiej Sojka for pointing out that it's a hard link, and suggesting the solution. It’s the package downloaded directly from the vendor https://www.tenable.com/downloads/nessus-agents, in the section Nessus Agents - 7.4.3, NessusAgent-7.4.3.dmg I think the visible package in the disk image is actually a hard link to a hidden package in the disk image, named .NessusAgent.pkg. I have no idea why. Here is me using “ls -la” to get a long listing of all the files, even hidden files, in the disk image: MacBookPro:Nessus Agent Install ladmin$ ls -la total 28120 drwxr-xr-x 5 ladmin staff 238 Sep 10 16:11 . drwxr-xr-x+ 4 root wheel 128 Oct 31 19:55 .. -rw-r--r-- 1 ladmin staff
Greetings All!, Just getting started on my road to JAMF admin and am slowly building up my library of First Aid apps inside of Self service. Trying to eliminate tickets coming my way and empowering the Help Desk to do some of this stuff. I created this script to view the Personal FV Keys from the server without have to give anyone rights into the server. This script is not perfect in any way, but I thought I would share it with the group nonetheless. This using SwiftDialog for the GUI and was taken from a lot of GitHub scripts and customized it for my needs. Enjoy! #!/bin/zsh # This script retrieves the Personal FileVault Key for a particular computer # # Written by: Scott Kendall 12-20-2024 # Last Modified on: 12-20-2024 jamfpro_user=${4} jamfpro_password=${5} declare api_token declare api_authentication_check declare ID declare reason declare serial_num ###################################################################################
I’d wanted to understand for a while how Apple structures its own support approach and what really lies behind the Apple Certified Support Professional certification. So I decided to take the exam myself. In this post, I’ll share how I prepared, which learning resources helped me most, and what I’d recommend to anyone planning to do the same. The Apple Certified Support Professional (ACSP) certification validates comprehensive knowledge in supporting and administering Apple devices. It’s designed for IT professionals, help desk staff, and administrators who regularly work with macOS, iOS, or iPadOS and provide daily end-user support. “This course introduces you to the knowledge, skills, and tools used to support and troubleshoot Apple devices in a large organization as a level 1 or 2 help desk professional.” Learning Resources and Preparation Apple offers free official learning modules on the Apple Training platform. These cover all topics included in the exam, such as user manageme
How can I disable the Help Apple Improve Search Item in the Spotlight Section of the System Settings?I can't find anything in Configuration Profiles and didn't find something related in com.apple.Spotlight.plist in /Library/Preferences/ or ~/Library/Preferences/.
Update 23 February 2026: Standard Cloud upgrades have been rescheduled for the weekend of 6–7 March 2026 (details below). We appreciate your patience with the revised schedule. Today we are releasing Jamf Pro 11.25; highlights include:Branding Self Service+ for macOS via Jamf ProYou can change the Self Service+ application name and icon using Jamf Pro and Self Service+ 2.15.0 or later if Self Service+ is set as the default end user application. Previously, modifying Self Service branding settings in Jamf Pro only altered these attributes in the Self Service classic application.Improvements for OIDC-Based Single Sign-On Through Jamf AccountThe Jamf Pro login page retains the last-used identity provider (IdP), eliminating the need to reenter an email address. This requires users to allow cookies from jamfcloud.com. Ending a session in any Jamf web app integrated with OIDC-based SSO through Jamf Account will end the same session in Jamf Pro. Likewise, ending a session in Jamf Pro will end
Hello everyone,I'm just sharing my fix for a problem I got since I switched to Self Service+ (SSP). I'm not sure if others have encountered this but it affects all our Macs (40+) so it's definitely not isolated.Hope this can help and I'm open to any discussion on the matter. EnvironmentSelf Service+ 2.16 via jamf pro (Use Self Service+ as the default end user application) SymptomsSelf Service+ would quit and relaunch itself every time a standard user executed any policy (or when doing a check-in). Admin users were unaffected. Root causeWhen you rename Self Service+ through custom branding (via the cli as explained in the official docs), the app bundle name changes, but the jamf binary preference key self_service_plus_path in /Library/Preferences/com.jamfsoftware.jamf.plist still points to the old path /Applications/Self Service+.app.When a policy executes, the jamf binary tries to send the completion callback back to SSP via XPC using that stale path. It can't find the process, logs Co
Hello,My organization has asked me to explore whether it’s possible to control macOS login behavior based on Active Directory group membership.The goal is to automatically log out a user if they belong to a specific AD group. Additionally, as long as the user remains in that AD group, they should be prevented from logging in to macOS at all. We would also like to block all local unlock methods (password, Touch ID, etc.) while the user is in that AD group.Is this type of workflow achievable? Does Jamf provide functionality that can enforce these restrictions?
Has anyone determined a way to see how frequently Mac Apps is updating an application on a device? The scenario here is we’ve automated Chrome updates via Mac Apps. This is great and makes us IT admins happy. We have one user who complains his Chrome is being updated “almost daily”. Now I know this isn’t true but I want to capture logs to document how frequently his machine (or others) is updating apps. Has anyone run into this situation before and seen a solution? Thanks,
Hi, My JAMF ID is working and I can login at JAMF.com fine. I have existing accounts in JAMF Now and School. If I select JAMF now it logs me straight in. JAMF school sends me to the login page and none of my passwords work. requested a password reset and nothing ever comes through! Anyone else seeing the same?
Hi Jamf Champions,We have MC1223829 – Upcoming Conditional Access change: Improved enforcement for policies with resource exclusionsThis update states that if you have Conditional Access (CA) policies that are applied to all resources with excluded resources, and if those excluded resources have OIDC scopes or a limited set of directory scopes(user.read), then such policies will also be enforced for the excluded resources.As per Jamf requirements, we have the Jamf Connect app in our Microsoft Entra ID, which is currently excluded in our CA policies using custom security attributes. With this change, the app may no longer be treated as an excluded resource, since it uses the User.Read scope.What are your thoughts on this?The change is scheduled to roll out from 27 March, and you might be impacted.
We provide a pretty white glove service to our customers in that we run setup on every new IOS device, manually set some settings that our not manageable through an MDM, and decluttering the home screen of widgets and many native IOS apps.To be clear, I don’t want to remove or lock down the use of many native apps. I would like to remove all widgets, and remove the home screen SHORTCUTS to many native apps but leave the actual app itself available from the app library if needed.The goal is to deliver a device with a clean decluttered INITIAL layout device that has only the core native apps (such as phone, settings, messages, photos etc) and the required business apps on the main home screen page. After that, if a person wants to drag a shortcut to the calculator app (for example) out the home screen, they can do that from the app library.I realize that I can create a conf profile that HIDES apps, but I don’t want to do that because it removes access to that apps, not just the shortcut.
Hey Nation,A lot of what makes this community great isn’t what we build, it’s what you all bring to it.The answers, the advice, the time you give to help someone else out, it doesn’t go unnoticed.I wanted to share a genuine thank you to everyone who contributes, supports, and shares their knowledge here ❤️.And what better way to show that than bringing my fellow Jamfs into it 👀.So, Jamf team, let’s shout out what we appreciate about our customers!I’ll start….Shoutout to @scooterkohler , whose enthusiasm and desire to learn have been clear since joining the community last year. You’ve thrown yourself into the Jamf Heroes program (so much so, you’re a featured highlighted Hero 👏🏼) and have already started a user group in your area to bring others together 🙌🏼. Thank you for your energy and willingness to give back back!Jamfs, your turn next!
Hello!In the last 2 years, I have had some Macs lose all configuration Profiles (including the MDM profile) when they try to renew the MDM Certificate (and fail for some reason)Mostly that could be fixed cancelling the “Renew MDM Certificate”-Pending task in the Management-Tab and then have the User run “profiles renew -type enrollment”. But it surely seems like a bug, when the (non-removable) MDM profile is gone.Has anybody seen something similar and a fix for it?Bye, Frido.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!