Get Support
Recently active
I am trying use Exhibit to create a custom background on the AppleTV’s at my workplace, which has been working great, however, I have run into a road block. I want to have a slideshow in the front office/waiting room and, a static screen on all of the other TV’s. I have been trying to make Exhibit work, but I can’t find a solution none of them seem to work, or my organisation has blocked them, I wanted to see if anyone had any ideas.
Hi, hoping someone is able to help!We’ve successfully deployed SCEP with Jamf School for our iPads. The devices received their certificates correctly and were able to connect to our Wi-Fi.However, we are now experiencing an issue with certificate renewal around a year later. The certificates are not automatically renewed when they are approaching their expiration date. It seems that Jamf School’s SCEP configuration does not send a new certificate request before the current certificate expires.As a result, the iPads are dropping off our Wi-Fi and are unable to reconnect once the certificate expires. To get them back online, we have to connect the iPads to another network and then manually push the Wi-Fi profile again through Jamf School.Other MDM solutions provide an option to specify how many days before expiration a certificate should be renewed, but I can’t find a similar setting in Jamf School.How can we configure automatic certificate renewal in Jamf School? I’ve looked through the
I was excited to hear at Jamf Nation Live about this criteria “Username directory service group” for smart groups.We’re already Entra ID integrated so I was hoping it would be a breeze to put into practice. Our mappings are standard setup as per the doco. The username field in Jamf populated for at least some devices but I still get 0 results when using this criteria in a Smart Group.Has anyone had any luck using this criteria for scoping or did I get my hopes up a little prematurely?
Hi everyone,We manage approximately 330 student iPads with Jamf School and have used Time Filter-based Safari restriction profiles for a long time.During the semester, we normally restrict Safari from 7:30 PM to 8:00 AM, and this setup had previously worked reliably across almost all student devices.The issue started after our summer break.During the semester, we used our normal Safari restriction profile. When summer break began, we switched to a different Safari restriction profile with the same restriction settings but a different Time Filter schedule.We used that vacation profile for about six weeks, and when the new semester began, we switched back to the original semester Safari restriction profile that had worked reliably before.That is when the problem suddenly started.At first, some grade-level groups were showing only about 4–11% Installed during the active Time Filter window.We are now seeing several different behaviors:Some devices have recent check-ins and successfully ack
Please change the category for Collegboard.org in Jamf Radar to Education ONLY.
Hi all, I did not see anything like what I needed so I created one. Below is a script to copy image files to a users local directory. It works fine, very basic, but I'd like to combine the two if statements and work out an exit code if the source files are not present. If anyone is bored out there???? : ) #!/bin/sh #Created by Brian LaMantia 6/1/2020 #Move FIS background images from /private/tmp to the current users Uploads folder in Teams. #Run after the images are deployed to the tmp folder then displays a message to the user. #If the package fails, do not display a message. #If you make this better, post a copy for me! #get current user currentUser=$(/bin/ls -l /dev/console | /usr/bin/awk '{ print $3 }') #Check if the images package was installed sourceFiles=/private/tmp/Teams #Check if Teams uploads folder exists teamsPath=/Users/"$currentUser"/Library/Application Support/Microsoft/Teams/Backgrounds/Uploads/ #jamfhelper path jamfHelper=/Library
Hey,since the last iOS update for iPads, I've noticed that the devices are still showing up under Devices > Update even after a successful update.In the activity log, I see that "AvailableOSUpdates" is not a valid request type.I haven't found a way to solve this problem yet. I'm using Jamf School. Regards
Hi Jamf Community,I’m reaching out as a frustrated parent dealing with managed iPads at my son's school, trying to permanently block specific apps like Instagram and Snapchat via Jamf Parent.Unfortunately, I've run into a wall with several limitations and confusing UX choices in the current implementation: Incorrect App Store Categorization: Blocking the "Social Media" category in Jamf Parent does not affect Snapchat or Instagram, as Apple/developers categorize them under "Photo & Video" or "Entertainment". However, Jamf Parent doesn't offer a dedicated "Photo & Video" category filter to toggle off, nor does it allow parents to manually recategorize or target individual apps for permanent restriction. No Permanent Single-App Blocking: In Jamf Parent, restricting individual apps seems strictly tied to a timer mechanism. UX / Translation Issues ("Clear after..."): The option labeled "Clear after [X] hours" is extremely misleading. In the German localized version, it translate
I need to update Docker to the current version across the fleet. Rather than downloading, repackaging, and then deploying via policy, I saw the Jamf App catalog has a docker entry for it. My question is if I set it up as...target group: all managed devicesInitial Deployment: Self ServiceUpdate Method: Automatically UpdateWill thatnot push to devices that don’t have it installed update automagically to devices that do or will it update devices that only installed, initially, from self service?
Does anyone know how to get rid of this option? I'm not very techy, but my daughter keeps bypassing onto bad websites by using this option. I'm using an image off the Internet as an example but this is exactly what it looks like. Thank you 😊
Hello everyone,We're having problems with students changing the DNS configuration to access forbidden sites.Is it possible to block the Manual DNS option in JAMF Pro? See screenshot belowThank you in advance for your help.
Had a student this week figure out that if they look at the more information of the connected Wi-Fi that they could change the Configure DNS from Automatic to Manual and then provide a new DNS IP. Which then jailbreaks our content filter.Any suggestions on how to enforce the Automatic setting of Configure DNS? There should be no reason for any of my students or staff to need to Manually configure this.
I am new to the community. I have a configuration policy for AD binding. The policy has been in place for well over a year. There has been no changes to the Active Directory settings, however its giving failing messages. What's causing this?
Hey Jamf Nation!We’ve released Jamf Pro 11.31.0 beta. This release includes new Mobile Device Smart Group and Advanced Search Criteria, API changes and more, check out the release notes after enrollment.How to join the beta: Enroll in the Beta Program under Product Feedback at account.jamf.com. Click “Join Community” to join the beta forum once enrolled. If you encounter an error on Jamf Nation joining the beta forum, please log into Jamf Nation and then click “Join Community” again. Please also check out this recent blog on Configuring SSO in Jamf Account prior to testing Compliance Benchmarks, Blueprints, and App Switcher. Email beta@jamf.com with questions.The beta program is covered by the Jamf non-disclosure agreement; please do not share any information regarding your testing on any public forum, including the non-beta areas of Jamf Nation. Use the Jamf Nation Beta Forum or contact Jamf via beta@jamf.com with any questions. Thank you to all who participate in this program!
Hi Nation,Product Office Hours #6 - OS Readiness and BlueprintsNext session: Thursday, 17th Sep - 9am CDT / 3pm BST / 4pm CESTSpeakers: Katie English, Principal Product Manager and Mark Buffington, Senior Consulting Engineer, Apple TechnologiesRegister here: https://jamf.it/ProductOfficeHours 🧵 Got a question? Drop it in the comments below ahead of time if you want it on our radar, though you don't have to. We'll be taking questions live on the call! Anything we don't get to, we'll follow up right here within 24 hours.See you there!
Hello Jamf Nation!We’ve released Jamf Pro 11.33.0 beta. With this version we’re excited to announce OIDC-Based Single Sign-on for End Users! For full details, check out the release notes after enrollment.How to join the beta: Enroll in the Beta Program under Product Feedback at account.jamf.com. Click “Join Community” to join the beta forum once enrolled. If you encounter an error on Jamf Nation joining the beta forum, please log into Jamf Nation and then click “Join Community” again. Please also check out this recent blog on Configuring SSO in Jamf Account prior to testing Compliance Benchmarks, Blueprints, and App Switcher. Email beta@jamf.com with questions.The beta program is covered by the Jamf non-disclosure agreement; please do not share any information regarding your testing on any public forum, including the non-beta areas of Jamf Nation. Use the Jamf Nation Beta Forum or contact Jamf via beta@jamf.com with any questions. Thank you to all who participate in this program!
Hello fellow Jamf Admins,I would be extremely grateful if anyone has come across this App before (Hospital setting) called, “CBORD Mobile Inventory”. I am trying to add the App Config settings like I’ve done for plenty of our other Apps, but this particular App won’t give me a break. Below is a screen shot of what fields need to be filled out and the App Config I came up with and verified via AI. I am at a loss right now. The last thing we want is for our end-users to have to enter the data manually as that would be a nightmare. Any assistance would be very much appreciated. App Config I’ve tried (certain fields have been changed for obvious reasons). <dict> <key>serverURL</key> (<===== I have also tried “APIURL”) <string>https://netmenu4.cbord.com/NetMenuAPI</string> <key>appClientId</key> <string>xxxxxddddfffcxxxxxxxx</string> <key>region</key> <string>us-east-1</string> <key>
Those who know, really know. And they’re excited. In less than a week, Apple admins from around the globe will descend on Kansas City for one of the most-anticipated events of the year. JNUC 2026…we’re coming…and we have exciting additions. Let’s get into it. This year, you’ll experience an entirely new Jamf Nation booth. While I won’t give away the details, I’ll leave you with a riddle: You've typed my name a thousand times to install something else.This time, say it out loud — and someone hands you a cup.Come back all three days. I'll have something new for you each time.No install required. Excited? We are. Lots of details (big and small) went into this year’s booth, so ensure it’s on your agenda. And don’t worry. Even if you forget, we’ll be hard to miss. And in true JNUC fashion, community will fill the halls. Friends, new and old, are waiting to meet you. But if talking to random strangers isn’t your thing, just remember:They’re there for the same reasons as you. Everyone wants
Today we are releasing a maintenance version of Jamf Pro; highlights include:Changes and ImprovementsJamf Pro 11.32.1 includes Tomcat 10.1.59. Jamf Remote Assist now includes compatibility for computers with macOS 27 or later.Resolved IssuesJamf Pro Server: Security IssuesJamf provides the CVE-ID for security issues with high or critical severity when possible.[PI205872] Fixed: A known vulnerability in a third-party library (CVE-2026-56822, CVE-2026-55831,CVE-2026-59901). [PI222752] Fixed: A known vulnerability in a third-party library (CVE-2026-55858). [PI223203] Fixed: A known vulnerability in a third-party library (CVE-2026-73089). [PI-1654] [PI223696] Fixed: A known vulnerability in a third-party library (CVE-2026-41003).Jamf Pro Server[PI-1519] Fixed: Jamf Pro returns a 409 error when using referential smart groups with the advanced mobile device searches API endpoint. [PI-1580] Fixed: The device compliance workflow with Entra ID fails to register devices if an interactive sign-in
Hello,I’m looking at deploying Logic Pro to shared/classroom Macs using Jamf Pro and I’m trying to work out the best way to manage the Logic Pro Sound Library for multiple users.My understanding is that newer versions of Logic Pro use a single Logic Pro Library.bundle, which can be relocated to a shared location such as /Users/Shared/ and accessed by multiple macOS users.What I’m trying to establish is:Is the Sound Library installed on a per-user basis by default? If the full Sound Library is downloaded by one user, can other local users access those sounds without downloading them again? What is the recommended way to deploy/configure a shared Logic Pro Sound Library using Jamf Pro? Can the Sound Library download/installation be automated through a Jamf policy or script? Has anyone successfully deployed this configuration to shared Macs in an education environment? If the Logic Pro Library.bundle is moved to /Users/Shared/ can I default Logic Pro to look at this directory for new user
Wondering how others are handling the transition from PPPC Profiles to DDM Blueprints. For this example I’ll use Zoom. The PPPC that’s pushed out has Accessibility: Allow and ScreenCapture: Allow standard users to allow access.For Blueprints under App Settings, then App privacy the permission defaults are configured for Accessibility: Allow, Camera permission: Allow, Microphone permission: Allow. There is no option for ScreenCapture in Blueprints yet. So is the recommended action to push the Blueprint prior to users upgrading to MacOS 27 (right now all of our devices are on 26 and we’re just testing 27). Then also to keep the PPPC in place for the ScreenCapture feature, and if it’s being kept in place are you stripping out the Accessibility setting in the PPPC once all users are upgraded to MacOS 27 and the Blueprint is successfully pushed to all devices?
Hi there.Recently, I have been experiencing issues with system permissions on macOS when using Cisco AnyConnect VPN.Users are prompted to go to System Settings, then to the Privacy & Security settings. In many cases, they manage to find the required settings, but some users are unable to do so.I have pushed a Configuration Profile, but it seems that it is no longer working.This issue occurs with macOS 26 and Cisco AnyConnect client version 5.1.17.Do you think there might be a solution outside of Blueprint? I don't have a Jamf Cloud instance; I have an on-premises Jamf instance, and I haven't enabled SSO yet.Thank you.
I'm creating an extension attribute, which I want to use as a criterion for a smart computer group. I want the group to contain only those for whom the extension attribute has a particular value.That is, if my criterion is "[name of extension attribute] [is not] [value I'm interested in]", then members of the group will include those that have a different value from the one I'm interested in, which is right, BUT ALSO all computers that don't yet have the extension attribute populated.For example, suppose my extension attribute is called ApplicationBlahInstalled, and based on the actions of a script, it will populate the extension attribute as either "Not Installed" or some data indicating where and how it's installed. I will therefore have 3 different possible states:1. ApplicationBlahInstalled is populated, and has the value "Not Installed"2. ApplicationBlahInstalled is populated, and has some other value3. ApplicationBlahInstalled is not yet populatedI need to detect machines that ar
So It seems Apple has removed some MDM control of macOS updates in macOS 27 and they are only allowing using DDM commands to do this.Wanting to know if the Defer Major macOS updates MDM profile setting will work in macOS 27 or is this gone too? (I would assume that deferring upgrading to 27 will still work since older versions of the OS still support MDM update control. This is more about the future) I see with Jamf 11.29 that the download & schedule install is now DDM and works on prem but what we are really looking for is a way to continue Defer Major macOS updates for 90 days. We are not in Jamf cloud and not really looking to move.
We have a tech that needs setup to use Jamf Nation with our Company’s tenant. Please let me know if you require any additional information or if there is another way to attach him to the tenant. Thanks,Nick Lumpkins
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!