Get Support
Recently active
Hello,Does anyone have a working method to install LsAgent-osx.dmg on computers with Jamf Pro and configure it with an agentkey? With no luck, I have tried making packages, scripts, and numerous other things, including Installomator. The only time the install works and the Mac communicates with our lsagentrelay is when I manually install the DMG, and even then, when I manually run LSAgent in the Application folder, I see an error that says "Configuration could not be updated: Access to the path '/Applications/LansweeperAgent/lsagentconfiguration.xml' is denied." Despite that error, it successfully communicates with Lansweeper. Any help would be appreciated, as I've tried everything I've found online so far. Thanks,Steve
Download the MATLAB DMG Installer:Visit MathWorks and log in with your MathWorks account.Download the MATLAB DMG installer for macOS.Mount the DMG and Run the Installer:Double-click the downloaded DMG file to mount it.Open the mounted DMG and run the InstallForMacOSX.app.Log In with Your Company Account:When prompted, log in using your company MathWorks account.Choose your license from the available options.Select Advanced Options:Before proceeding with the installation, click on "Advanced Options."Choose the option "I want to download without installing."Download the Installation Files:The installer will download the necessary installation files to a folder and then move to /private/tmp/MatlabR2024aCreate the Installer Input File:Navigate to the folder '/private/tmp/MatlabR2024a' and locate the installer_input.txt file. Edit this file to include the following parameters:destinationFolder=/ApplicationsagreeToLicense=yesoutputFile=/tmp/mathworks_install.logenableLNU=yesIf depl
So we have Apple TVs that are set up with a config profile to automatically go into Conference Room mode, which locks out the ability to use an Apple TV remote. Somehow, some of the Apple TVs got unenrolled from Jamf but are still stuck in Conference Room mode. There’s no way to get into Settings to reset them because the remote doesn’t work.I’ve tried the old method of resetting them by rebooting them 4-5 times until the Recovery menu comes up. That used to work, however, at some point they stopped going to that menu, and now only give the option to connect an iPhone or iPad to reset them. No problem, I thought, I can use my iPad. The problem is that now the ONLY option it gives is to upgrade the OS, and when choosing that option, it doesn’t actually go through the Apple TV setup again…. meaning it doesn’t re-enroll in Jamf. The Apple TV downloads and applies the OS upgrade… then puts me right back into Conferenced Room Mode, locked with no ability to use a remote.Is there anything I
Just wondering if anyone has seen this. The machine is Ventura (Mac OS 13.6) and trying to upgrade to Mac OS 14.1Machine is bound to an AD domain and the user has a secure token and is an administrator on the machine. The user is logged on with a domain account i.e. a mobile account. The machine is an M1I tried forcing the update/upgrade via Jamf using the MDM framework from the server as they are overseas but it got to the end of preparing and prompted them again
Dear Team,Anyone can address which domains or settings need to bypass in DNS settings to login cloudflare warp client successfully? My Jamf Web Protection only enable Internet Content Filtering, therefore MAC OS machine no need Jamf Trust, it only needs profile configuration , UEM connect settings in place.I have the issue that When the DNS settings disable I am able to login CloudFlare WARP client If the the DNS settings enable, i can not login the CloudFlare WARP client with the error message "CF_DNS_LOOKUP_FAILURE." and here is the solution Verify that the network the user is on has DNS connectivity.Verify that DNS resolution works when WARP is disabled.Ensure that no third-party tools are interfering with WARP for control of DNS.Ensure that no third-party tools are performing TLS decryption 5 on traffic to the WARP IP addresses 4.I already tried to bypass these domains without help in configuration proflie<string>*.cloudflareclien
Hello Jamf Nation! With the increasing frequency of Chrome updates, IT teams must proactively patch critical vulnerabilities. After testing several deployment methods (including Installomator and the Jamf App Catalog), I believe the built-in auto-updater remains the best way to upgrade your browser fleet at scale without interrupting your users at the wrong time, and ensuring all previously opened tabs are restored for a seamless user experience.Continue reading… [Medium.com - free, no paywall]
Hi Nation,Product Office Hours #3 - How we built AI Governance Next session: Thursday, 27th August - 9am CDT / 3pm BST / 4pm CESTSpeakers: Josh Stein, VP Product Strategy and Jon Malm, Principal Software ArchitectRegister here: https://jamf.it/ProductOfficeHours 🧵 Got a question? Drop it in the comments below ahead of time if you want it on our radar, though you don't have to. We'll be taking questions live on the call! Anything we don't get to, we'll follow up right here within 24 hours.See you Thursday 27th!
For years, MacAdmins have had to manage random service files (like ssh, pam, sudo, etc) with packages, scripts, custom agents, postinstall logic, or vendor specific workflows. In 2023 with macOS Sonoma, Apple introduced a feature that sort of slipped under the radar a bit on how it could be used…Declarative Device Management (DDM) added Service Configuration Files. Service Configuration Files give us a declarative, tamper resistant, native way to deliver text based configuration. Service Management Configuration files fixes managing text configuration files that live throughout the macOS, something traditional legacy MDM couldn’t do. That is boring in the best possible way. You set it, and it can’t be changed or messed with. But what if you could use it beyond Apple’s documented use cases…managing third party apps, or even building or own app that reads its configuration this way?To use Service Configuration Files you create a zip file of a configuration for certain services and then a
Has anyone started down this road of managing MacBook Neo’s with JAMF School? I have started testing and have encountered a couple of annoyances thus far. We are generally a Microsoft shop and use JAMF School to manage student iPads. As such, we are using JAMF Connect for student login to the devices on these devices as well.There seems to be an issue with the Neo’s not wanting to reconnect to wifi after a restart. Also, Keychain is asking for access to JAMF Connect password after installation. We have this same setup working on 10 iMacs at one school and they do not ask for Keychain access.Any thoughts or shared experiences would be great. Thanks.
Hi All. We noticed a lot of network bandwidth when using the Mac Apps installers via Jamf, and abnormally large sizes for application updates, such as Microsoft Excel. I asked Jamf Support in a ticket how big the update was for Microsoft Excel, going from 16.76 to 16.77 [for the Jamf Mac Apps installers], they said it was 1.23GB. But when using MAU (Microsoft AutoUpdate), the update size is much smaller (less than 100 mb).Another user commented on this a few years ago, but it was in reference to Jamf Patch Management (not Mac Apps installers). That link to that thread can be found here.Within that thread, the user links to a Mac Admins site, which showcases how big the current updates are for all Microsoft apps: https://macadmins.software/updatesize/You can see the update size for Excel is under 100mb, and nowhere near 1.2gb. It may be possible that Jamf is using the updater PKG provider by Microsoft, which by itself is around 1gb. If you scroll down on this page, under Update pac
Some users in my organization experience high CPU usage by Jamf Protect after updates to new macOS Tahoe 26.6.2.Does anybody experience the same? Is it a know issue?
Hi Nation,Product Office Hours #1 - AI Governance: What is it and what can we do with it?Next session: Thursday, 13th August - 9am CDT / 3pm BST / 4pm CESTSpeakers: Sam Johnson, Akash Kamath & Matt BenyoRegister here: https://jamf.it/ProductOfficeHours 🧵 Before the call, this is on you: drop your question in the comments below, and like the ones you want to see answered. Q&A is built entirely from what gets submitted and upvoted here, so if you don't ask it, it doesn't get covered live.No questions, no Q&A, it's that simple. Anything we don't get to, we'll follow up right here within 24 hours.See you Thursday 13th!
Today we are releasing a maintenance version of Jamf Pro; this release addresses the following product issues:Jamf Pro Server: Security IssuesJamf provides the CVE-ID for security issues with high or critical severity when possible.[PI186191] Fixed: A cross-site scripting (XSS) issue. [PI208395] Fixed: A cross-site scripting (XSS) issue. [PI209382] Fixed: The Jamf Pro installers include Spring Framework 6.2.18, which includes multiple vulnerabilities, including CVE-2026-41842 and CVE-2026-41855.Jamf Pro Server[PI148391] Fixed: After modifying the custom configuration PLIST for iOS shared device compliance, Jamf Pro fails to redistribute the updated configuration to target devices until they are re-enrolled.Note: This issue was resolved in Jamf Pro 11.31.0 and was inadvertently omitted from those release notes. Subscribe to Jamf Learning Hub contentWhen logged in to the Learning Hub, click the Subscribe button (bell icon) on the release notes page to receive email when that content is u
Hey folks! Just wanted to drop by with another bit of info that may be helpful when using the new Self Service+ application on your managed computers. The app leverages macOS unified logging, so to grab logs you'll want to parse the log stream to get app activity. One way to grab these files programmatically (as of version 1.2.0 of the app) is to use the Collect Troubleshooting Info option in the Help menu (or use the hotkeys ⇧ ⌘ L /Shift + Command + L) and the app will generate a zip file and save it wherever you specify. For folks familiar with parsing the unified log on macOS, you can use Terminal to filter the log and look for Self Service+ events. To see events from the last hour would look something like this: log show --info --predicate 'subsystem BEGINSWITH "com.jamf.selfserviceplus"' --last 1h --style compact To stream activity from the app as it's running in real time you'd want to use an elevated log stream command, something like this: sudo lo
I often have different research groups that need to have admin access on their computers due to the type of work and research they are doing, but currently I don’t have a method to give them this access in the way they would like. Additionally, these research computers are shared between the primary researcher that can have admin access, and additional researches that cannot be given admin access.I use Jamf Connect with Entra SSO. Pre-stage enrollment creates all new users as standard users. When we use a command or trigger to elevate someone to Admin, this reverts to standard at their next login. Using Self-Service+, users can select temp admin access when they need it, but applying this to device means all users on the device have access, even those that shouldn’t, and applying it to a user makes it available to that user on any device, not just the device they need it on.I don’t know if there’s any other setting, configuration, or options I could use that would make this function t
Hey Nation!🎤 Free live workshop. Aug 19. Register now → https://jamf.it/JamfNationEventsHere's the deal. 👇JNUC is seven weeks out. Whether you're speaking on stage or just want to stop dreading the "can everyone see my screen" moment in meetings, this session is useful for anyone who presents, leads User Groups, or just wants to come across better in meetings and Zoom calls.We're kicking off the next session in our Development Series with Bryan Lemos, Senior Consultant at Decker Communications. Bryan coaches senior leaders at companies like Google, LinkedIn, Workday, and Pfizer (he's also worked with MIT and international heads of state), and he's tailored this session specifically for our community.You'll walk away knowing:The best ways to manage and overcome presentation nerves How to use the Behaviors of Trust™ to build credibility and connect with your audience, including executive presence, vocal tone and pace, and eye communication Storytelling methods that make your message me
Hi There, i would like to change local admin password via jamf, is that possible
Hello Just wanted to understand how you’re using JSM for UIE. I noticed there’s a slight delay when triggering the Enrollment Complete policy for JSM. Self Service launches before the JSM policy is triggered/completed. Is this expected behavior, or is there a way to ensure the JSM policy runs first before Self Service launches?
From a small email distribution list to a formalized community forum, Jamf Nation has served as the premier online resource for Apple management enthusiasts for more than a decade. And recently, in case you missed the news, it hit a milestone - 300,000 posts. Jamf’s founder, and former CEO, Zach Halmstad, not only recognized the desire for customers to share ideas as a way to problem solve, but he also saw their need to connect as humans. So in 2012, he pitched an idea - Jamf Nation. “Early on we witnessed the huge benefits our customers saw when they could ask each other questions and share their solutions,” Halmstad recalled. “Jamf Nation was the next step for us to ensure customers were successful.”In a 16-slide Keynote, Halmstad pitched his idea to his colleagues at Jamf. He shared the reasons to shift the company’s rapidly growing email distribution list to an online forum, citing communication as a main goal. (Slide from original deck shown below). Fast forward 12 years, a
Engage. Empower. Elevate.When we started Mac Admins India, the vision was simple: create a place where Apple IT professionals across India could learn from one another, build meaningful connections, and strengthen the enterprise Apple ecosystem.On 1 August 2026, the Apple IT community came together at Radisson Blu Hotel, Outer Ring Road, Bengaluru, for the second edition of Mac Admins India Connect. What began as an idea to bring Apple IT professionals together has quickly grown into India’s largest community-driven conference dedicated to Apple enterprise professionals.What began as an idea has now become India’s largest community-driven conference dedicated to Apple IT professionals.Community FirstTechnology conferences are often measured by attendance numbers, sponsors, or session counts. While those are important milestones, the true success of a community event is measured by the conversations that happen between the sessions.This year we welcomed 370+ attendees from across India
Hey folks, I worked on a script to deploy Autodesk 2026 (the one that uses the named user licenses). We don’t teach Mudbox, so that isn’t in the script...but Maya and AutoCAD is (along with Darwin..what a PIA to get working). I packaged the apps and deployed to /private/tmp/AutodeskApps… I have a lot of logging left in the script as Darwin is a royal pain and can fail at many different steps. I also made use of a lot of variables to hopefully make updating in the future easier. Oh, also did it in zsh.Hope you all find it useful, or at the very least, a good jumping off point!#!/bin/zshset -euo pipefail############################# VARIABLES############################YEAR="2026"TMP="/private/tmp"APP_TMP="${TMP}/AutodeskApps"LOG="/var/log/autodesk2026_install.log"DMG_LIST=( "Autodesk_Maya_2026_1_Update_ML_macOS.dmg" "Darwin.dmg" "AdskIdentityManager-UCT-Installer.dmg" "Autodesk_AutoCAD_2026_macOS.dmg")PKG_FILE="AdskLicensing-15.4.0.13093-mac-installer.pkg"INSTALL_SUMMARY=()log() {
In macOS Tahoe, the command to get the current AirPort network is not working as expected, and the SSID value is showing as <redacted>.Could you please suggest any alternative script or method to retrieve the currently connected Wi-Fi SSID name?This is required to help us deploy the Network Configuration Profile only when the Mac is connected to an out-of-office network.Thank you.
Hi All,Has anyone seen Jamf Self Service fail to run an otherwise-valid policy? Been looking at this for a whileWe use Alectrona Patch to install 99% of our Self Service apps with the below script. Whenever i run one of these policies through JSS i get an “Item Failed.” notification. The symlink sudo patch install <id> works perfectly when run manually as root, so i think this is a Jamf error rather than a patch error, though i am speaking to them about it.#!/bin/zsh# Variablespatch="/Library/Application Support/Alectrona/Patch/patch"appName=$4# Check script parameter valuesif [[ -z "$4" ]]; then echo "Missing Application parameter" exit 1fi# Install App${patch} install ${appName} --silentif [[ $? == 0 ]]; then echo "$appName installed successfully" exitelse echo "Install failed - error $?" exit 1fiThe Jamf policy itself looks completely normal: enabled, no exclusions, no site restriction, ongoing frequency, Running jamf policy -id X -verbose from terminal thr
An original version of this post has been shared to Patch Notes and Progress. Reflections from JNUC 2025 — automation, openness, and community taking Mac management to new heights. Denver, Colorado | October 6 – 9, 2025Day 0 — Travel and New ConnectionsJNUC 2025 in Denver was my first in-person Jamf Nation User Conference — and my first time ever on a plane. Over three days, I watched Jamf redefine what MDM means in an API-first world, connected with the Mac Admins community I’ve long admired, and saw firsthand how automation, identity, and community are working to shape the next chapter of Apple device management services. As mentioned in a previous post: Prepping for JNUC 2025, I had been awarded sponsorship by Jamf to attend this year’s Jamf Nation User Conference in Denver Colorado. Before I even left Pittsburgh, Jamf had already dropped next year’s headline: JNUC 2026 will be held in Kansas City, Missouri (Sept 23– 25), with early-bird registration open. JNUC 2026 to be hosted at
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!