Get Support
Recently active
Trying to offboard a business org user who is keeping their laptop but it has to be wiped. However it is not accepting the activation unlock code.Steps taken: 1 - device was locked from jamf now2 - device was erased by sending “Erase device” command from jamf now.3 - Unlock code was provided to user to unlock. It failed. 4 - Tried to use activation unlock from Apple Business Manager. ABM now says the activation lock disabled, but device still shows activation lock screen. What else can I try as the MDM admin/ABM contact?
Hi team,We are looking to strengthen our change management and security controls within Jamf Pro. Specifically, we're exploring ways to implement a peer review workflow for high-risk payloads like Config profiles, policies and scripts.Currently, any admin with edit permissions can save and deploy those changes immediately. For us, having a single admin able to make immediate, wide-reaching changes introduces significant risk—whether from accidental misconfiguration or compromised admin credentials.We’ve considered reducing the permission scope of admins and granting limited time admin elevations, but we’re mostly interested in payload-level security here which we think is best to solve the problem.Curious to hear if you’ve thought of this, or if there’s any non-native way to solve it.I tried searching through the this forum and the mac-admins slack but couldn’t find any previous discussions on it. Feel free to point me to one if it already exist.Thanks!
Hey So Im looking to turn the hadware history of inventory into an extension attriubute that udaptes when the OS changes. I mnot sure if this is the right way to go however I made a script that runs during invetnory check in however its only pulling in with the OS was downloaded to install. Any suggetions on how to get this set up so other techs can use the extension t oassist with troubleshooting?
Hi everyone,I've been working through a deployment of Platform SSO Simplified Setup on macOS 26 using Microsoft Company Portal 5.2604.1 (5.2604.0 or newer is required per documentation), and I've hit a wall with username/account name mapping that I wanted to share in case others are running into the same thing and could potentially provide some alternative options.---Our Setup- Jamf Pro 11.28.1- macOS 26- Microsoft Company Portal 5.2604.1 (deployed as a PreStage package)- Microsoft Entra ID- PSSO profile with Simplified Setup enabled (EnableCreateFirstUserDuringSetup + EnableCreateNewUserAtLogin both true)- Authentication method: Password- Associated Domains payload included in the same profile---The ProblemEverything works end-to-end — Simplified Setup fires during the Setup Assistant, the user signs in with their Entra credentials, and a local account gets created. However, the local account short name is being set to the full preferred_username value (e.g. John.Smith@company.com), w
Anyone having some users upgrade to macOS 26.6 and now after they login with username password they are then greeted with a black screen. They can’t do anything else. We use Jamf Connect, users didn’t have any issues until they upgraded to macOS 26.6.
Anyone else having this issue?Jamf School’s app installers don’t seem to be installing apps onto my Macs properly. I have a list of apps in a device group that is sourced in the app installers - and upon a Mac joining said device group the apps stay stuck on “Installing” and they stay that way indefinitely. When I click on the stalled app to “Retry app stuck on installing” and refresh, the installation fails and I have to retry or it says “App installation timed out. Try again.”. This is really slowing down my zero-touch deployment process.
Hey Jamf Nation!We’ve released Jamf Pro 11.31.0 beta. This release includes new Mobile Device Smart Group and Advanced Search Criteria, API changes and more, check out the release notes after enrollment.How to join the beta: Enroll in the Beta Program under Product Feedback at account.jamf.com. Click “Join Community” to join the beta forum once enrolled. If you encounter an error on Jamf Nation joining the beta forum, please log into Jamf Nation and then click “Join Community” again. Please also check out this recent blog on Configuring SSO in Jamf Account prior to testing Compliance Benchmarks, Blueprints, and App Switcher. Email beta@jamf.com with questions.The beta program is covered by the Jamf non-disclosure agreement; please do not share any information regarding your testing on any public forum, including the non-beta areas of Jamf Nation. Use the Jamf Nation Beta Forum or contact Jamf via beta@jamf.com with any questions. Thank you to all who participate in this program!
Is there an option like “Clear Activation Lock” for MacOS devices but for the API?There seems to be for Mobile Devices but I can’t find anything about doing this for MacOS. If there is not currently, do we know if this option will be available down the pipeline?
getting a few of these, has anyone figured a way to disable them completely?
Hi, in I recently discovered a bug in Jamf Pro that appeared just this week. After enrollment, profile/policy execution "stops" and is "waked up" by these commands: sudo jamf recon
My goal is to block FaceTime from opening, and removal from the dock would be a plus. I’ve looked at other threads on this same issue and consulted AI. I am doing what has been suggested but FaceTime still opens up and allows me to log in; user are not able to sign into their appleid’s. I am running version 11.30.1 of JAMF Pro. Does anyone have a current setup that is successfully blocking FaceTime. I’m just wondering what I am missing. Screen shots would be appreciated. Thanks.
Today we are releasing a maintenance version of Jamf Pro; this release addresses the following product issues:Jamf Pro Server: Security IssuesJamf provides the CVE-ID for security issues with high or critical severity when possible.[PI207065] Fixed: A vulnerability within the Jamf Pro XPC validation. Jamf Pro Server[PI-1418] Fixed: The enrollment process for computers with macOS 26.6 or later may fail during Automated Device Enrollment or user-initiated enrollment with error code 71 (JBEnrollErrorKeyRecon). Subscribe to Jamf Learning Hub contentWhen logged in to the Learning Hub, click the Subscribe button (bell icon) on the release notes page to receive email when that content is updated (i.e., a new version of Jamf Pro is available). For more information about the Subscribe feature, see Jamf Learning Hub Watchlist. For additional information on what's included in this release, review the release notes via the Jamf Learning Hub.To access new versions of Jamf Pro, log into Jamf Account
Hello everyone 🙂!I was wondering if any of you managed to make SSO work for SMB share with Platform SSO and Entra? (no jamf connect)I found this documentation on Microsoft learning hub, but as i’m still a newbie i’m not sure how to implement it yet.The idea is that i want to connect automatically to the share at the user login with SSO, for now it is manual and with the password which is not ideal if we want a passwordless environment.Any tip is welcome, thank you for your help!!Joséphine
Can we clear Activation Lock via an API Call?
I recently traveled to the Matter Career Readiness Institute (MCRI) in Victoria Falls, Zimbabwe to teach a macOS fundamentals and essential skills workshop alongside my teammate, Tyler Davis. MCRI's mission is to train students for jobs in the tech industry and create opportunities for those who might not otherwise have a clear path forward.We knew the students had potential before we arrived. Our MCRI intern, Anita, had just joined us full-time as a Client Platform Associate,* and hiring her was undoubtedly one of the best decisions our team has made. While I didn't expect the whole class to be like Anita, I had a feeling I'd catch glimpses of her intellect and drive in them.When we walked into the room, everyone was focused and ready to begin. As a woman in tech who spent the earlier years of her career struggling to be taken seriously and have her voice heard, seeing them all genuinely eager to listen was a full circle moment. Part of why I cofounded the Women in Tech Apple Admins g
If we want to use Jamf’s built-in Patch Management notifications to let clients know about new patches as they become available in Self Service, they will receive a notification for each patch title as their Macs come into scope for each patch policy. That’s not really a big deal if we only push out one or two patches at a time, but say after Patch Tuesday… yikes! That can easily result in a string of notifications which can get pretty annoying. Additionally, there may be situations where notifications do not behave as we would expect, such as with PI104511, which can result in Self Service notifications not consistently appearing in the Notification Center when they are scheduled to do so, resulting in unpatched apps quitting unexpectedly when they reach their install deadline. This is where we found ourselves and why we built our own patch notification workflow. It leverages jamfHelper and a Smart Computer Group to send our clients one notification each day while patches are availabl
Hi, Our company WiFi uses user network creds to join, but the window that pops up for this has a certificate dropdown box (with several items available). The users get confused and start trying these. Is there a way to remove this box for at least this one SSID? Thanks in advance, -Pat
Hi all,I'm running 2 macOS VMs on a bare-metal Mac (host is also macOS). I'm seeing inconsistent iMessage sign-in behavior depending on the Apple ID type and whether it's bare metal or virtualized:Managed Apple ID (ABM-issued): signs into iMessage fine on the bare-metal host.Same Managed Apple ID: fails to sign into iMessage inside the VM on the same physical machine.Personal/basic Apple ID: signs in fine in the VM without issue.Has anyone run into this specific combination — MAID working on bare metal but not inside a VM, while a personal ID works fine in both?
I was reminded about DDM being the method used to supply iPhones with updates going forward.This article (Managed Software Updates End User Experience for Mobile Devices • Jamf Pro Documentation 11.30.0 • Jamf Learning Hub) talks about DDM being used for the Download and schedule the install feature and this article (General Requirements • Jamf Pro Documentation 11.30.0 • Jamf Learning Hub) routes towards Blueprints for setting up DDM. Will we still be able to use the managed software updates in any capacity or will we need to set up Jamf SSO and use Blueprints once this update rolls out?
Mac Apps, App Installers, Jamf Apps, Jamf App Catalog… whatever name you know it by, the feature found in your Jamf Pro server at Computers – Mac apps – Jamf App Catalog is a great tool for deploying and patching many commonly used Apps which aren’t available through Apple’s App Store. For the sake of clarity, I will refer to them as App Installers for the remainder of this post. App Installers do have some caveats which are documented here. Being aware of those is well and good, but even the most experienced admins can make mistakes. Jamf Pro will not alert you if you have done something like overlapped scopes for different deployments of the same App Installer title.If this occurs, that App Installer will likely cease to recalculate its deployment as more Macs are added to the Computer Group it is scoped to. If you toggle the “stuck” app’s deployment off and back on again, it’ll force it to recalculate and the Macs it was missing will begin to receive it.This overlapping scope behavi
Hello:I’m looking at this document about setting up Federated IDs in ASM:https://support.apple.com/guide/apple-school-manager/intro-to-federated-authentication-axmb19317543/webWe have about 300 students in Apple School Manager with their school email addresses and Managed Apple IDs. They look like this:email: slynch30@students.mpslakers.commanaged: slynch30@appleid.mpslakers.comWe’re trying to set up our new students using Entra so they can use SSO. Students are currently in Entra using their email address as their UPNs.Is this possible? How, if at all, will this affect our other 300 students in ASM?
Is there a statuspage for cloud based JamfPro?
Connect 3.4.0Self Service+ 2.12.0OS 26.1 Tahoe (Many other machines on 26.0.1)I can not get this prompt to close no matter what I do. Everything in the back end seems fine with my machine and my connection to Jamf, self service, connect, everything, it all seems fine. Anyone have any ideas? I did not see this issue prior to updating OS from 26.0.1 to 26.1 and that is the only thing I can think of that may be triggering it. I have tried deleting associated keys and allowing them to regen, I have tried flushing and re-pulling Config Profiles and Policies. P&S settings are all good. I have fond that if I leave the window there for 30min or more, it will finally close after entering PW and selecting Always Allow, but then comes back up after Reboot.
• iOS 26.6 and iPadOS 26.6 address almost 90 security vulnerabilities • macOS Tahoe 26.6 has more than 130 vulnerability fixeshttps://support.apple.com/en-us/100100
I am attempting to run policies on one device and receive an error "The index 999107 is invalid". I am able to run jamf recon and jamf manage. I renewed the Jamf framework. I also ran it with -verbose and nothing stands out.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!