Get Support
Recently active
Are you familiar with or have you used MacPAR deLuxe?For a long time, it was a go-to tool for creating and using PAR2 files, which can repair corrupted files using parity data. PAR2 files are primarily used on Usenet servers (newsgroups).The problem is that the application was developed solely for Intel-based Macs and appears to have been abandoned since 2018. Furthermore, the announced removal of Rosetta 2 in a future version of macOS effectively rules out its use on Apple Silicon Macs.PAR2Manager can help you solve this problem. Developed natively for Apple Silicon Macs (while remaining compatible with Intel Macs), this open-source application allows you to create, verify, and repair PAR2 file sets.GitHub : https://github.com/chrisbasse/PAR2Manager
Is there a statuspage for cloud based JamfPro?
This thread is a decent reference to the "feature" on Big Sur, as it's not brought up that much from what I can tell: Solved: Hide "Your screen is being observed" - Jamf Nation Community - 236104Unfortunately the solution was "you can't" and I would not be surprised if that's the same solution here, just want to confirm before I have to break the bad news to the teams that'll be affected by it. Now when you remotely screenshare with ARD/VNC, it makes a very obvious popup from the menu bar with icon stating that "Your screen is being controlled" with the IP that it's coming from:And then on top of that, it says when it stops being observed: I get that it's for security and can help a little bit, with the off chance that someone sees a connection that's not with an expected IP address (for example we'll be asking folks to watch for any non 172.etc addresses), but most end users won't know or retain that information and generate unnecessary noise and change a lot of behavio
Is the API call for the "Overview of Automated Device Enrollment devices" working for anyone? I use Jamf School, and while many endpoints work perfectly, this one doesn't. I am getting a "404 Not Found" error.GEThttps://{yourDomain}.jamfcloud.com/api/dep
I am attempting to roll out Jamf trust for ZTNA. I currently have Crowdstrike falcon installed on all of my fleet. My understanding is a limit of Mac is only one network filter can be active at a time. It seems like Crowdstrike doesn’t play nice with Jamf Trust. Even with the filter disabled I am unable to edit the DNS settings to have default to Jamf. Has anybody successfully deployed both products?
Districts buy a lot of apps. Some get used every day. Others quietly gather dust after the first semester. The problem is that most IT teams don't find out which is which until renewal season, by which point it's too late to make a good decision. That's the gap RapidIdentity Insights is built to close.What Insights actually shows youInsights is the analytics engine built into RapidIdentity. It doesn't just tell you an app is licensed. It shows you how students and teachers are actually using it, down to the individual login. That includes:A full inventory of your SSO applications, including their status, security controls, and who has access to what Usage stats by user type, school, grade level, or location, so you can see exactly which apps are catching on and where Trend analysis and forecasting, so growth or decline in adoption shows up before it becomes a budget surprise Individual application launch events, if you need to drill down that far Engagement tracking, including which us
Cisco Secure Client (CSC): Version 5.1.12.146MacOS: Tahoe 26.5Current issue we are facing is that when enrolling new MacBooks into our environment we are seeing that Cisco Secure Client is no longer passing through deviceID to azure to pass through conditional access policies. Previously our environment was running JAMF conditional access, and our devices were enrolling without a problem. All applications were passing deviceID and going through conditional access policies (CAPs) without any blockers. Recently we have shifted over to platform SSO as per many people’s recommendation as the old method was being deprecated. Since then, we have noticed that most applications are still working without issues, but unfortunately Cisco Secure Client is failing to pass deviceID and is now being blocked by our Azure CAPs. The main difference that I'm seeing is that the previously enrolled devices also received a WJP certificate, while the new enrollment method no longer utilizes this check. We or
We have all our Users Synced from ASM. Pupils will bring their own iPads from August. These will not be Supervised but we would like them all to enrol in JAMF.Is there anything that could be done during Enrollment that would automatically associate the device with the correct User so that we can use JAMF Student?
Another year, another Jamf Nation Live London and Berlin in the bag! And this might be bold to say, but I think it was the best one yet. This year, the Community team wanted to approach things differently. Rather than assuming we know what you need from us, we wanted to hear it directly from you, the community members, so we could understand our gaps and figure out how to close them. My "vision" was simple: create an interactive space that got attendees to stop and think about where they are in their Apple admin career, and see other people right there alongside them. We built a wall showcasing the different stages an Apple admin might find themselves in, from just starting out in management and security, all the way through to leading teams and strategy, with plenty of stops in between. Attendees filled in cards with a mix of light-hearted preference questions (light mode vs. dark mode... guess what won? 🌚) and the areas where they'd like more help, like AI integration, career growth
https://ideas.jamf.com/ideas/JPRO-I-2178i think this would be invaluable, please vote on if you agree
Newbie MDM user here. Signed up for Jamf Now and have 6 iPhone 14's being managed for work. The iPhones are not signed into an iCloud account. What is the best/easiest way to push a managed list of contacts to the phones?
What are the best practices for legal name changes for staff when utilizing Google Workspace and JAMF Connect? If you change the Google Workspace account name, JAMF Connect creates a new user on the users Macbook when they log in with that new account. How would I effeciently sync the new google account to the previous user account. I have read the Unmigrating a local Account post, but not sure how that helps with linking the new google account to that unmigrated account now.
Configuring single sign-on through Jamf Account for administrator authentication to the Jamf platform now supports Microsoft's admin consent flow for Entra ID connections.From Organization > SSO > New Connection, choose Entra, then select "Use Microsoft's admin consent flow for multi tenant applications." Click Connect with Microsoft and approve the screen. If you're not the Entra Global Admin, copy the link and send it to them instead. Once they approve, Jamf configures the connection. Manual configuration is still available as an option.New Entra connections request GroupMember.Read.All and User.Read instead of Directory.Read.All. Existing connections on the old scope can switch to the new scope using the "Entra Scopes" selector, which preserves existing group mappings.If your organization's domain is already verified in Microsoft Entra ID, Jamf inherits that verification automatically. Domain verification in Jamf Account is skipped for that connection.Full setup steps: Setting
I’m not sure if anyone else was struggling with some of these apps as much as I was for the past few weeks but we’ve got quite a few that we use in our environment: Linear, Notion, Claude Desktop, Google Antigravity (just to name a few).If so, I was able to create a few configuration profiles that will stop them from auto updating and stop all those annoying prompts users keep getting.I’ll leave a comment with each config profile\policy and the setup and hopefully it’ll save someone out there some time and headaches.
Hey Everyone, I have been battling this issue for quite some time and have done rigorous testing but have sincerely hit a wall with this issue. My organization is prepping to remove Administrator access from all users on our macOS systems, this requires them all to be converted to a Standard user. (We have a "MakeMeAnAdmin" script in place in JSS we plan to utilize) MacOS: 14.3.1Jamf Connect: 2.32.0 We use Jamf Connect with Azure/EntraID so users can authenticate on login, we have the app roles setup for the app registration in Azure with two groups, MacUserAdmin-Entra & MacUserStandard-Entra with the correct roles tied to each (Administrator & Standard) The Problem:Whenever a user is moved into the group tied to the STANDARD role in Azure and attempts to login to Jamf Connect on one of our Macs they can enter the O365 email, PW, verify 2FA, but then hit a "Yellow Exclamation Point" box with simply an "Okay" button. Once you click "Okay" you are kicked back
With Apple recently expanding access to the ABM/ASM API, I set out to recreate the GSX experience. By leveraging Jamf’s new MCP feature, Claude Code, and MUT, I believe I’ve come very close. Additional details are outlined below.Please visit the following Github repo for the latest version of Warranty Wrangler: https://github.com/brndnwds6/Warranty-Wrangler/tree/main Warranty Wrangler — Setup & Usage GuideThis guide walks through everything needed to run warranty_wrangler.zsh, a script that pulls warranty and AppleCare+ coverage data from Apple Business Manager (ABM) or Apple School Manager (ASM) and produces CSV files ready for import into the Mass Update Tool (MUT).PrerequisitesA Mac running macOS Administrator access to Apple Business Manager or Apple School Manager jq installed — if you don't have it, install it with Homebrew: brew install jq openssl, curl, and xxd — all included with macOS by defaultStep 1 — Create a Working DirectoryCreate a dedicated folder to store the scr
Is anyone experiencing issue with the lock desktop wallpaper configuration with macbook neos in Tahoe 26? I can get the configuration profile to block the “change the wallpaper” section in System Settings; however, users can still download a picture and right click to “Set Desktop Picture.” I have a policy to downloads and sets the wallpaper, which works, but users can now download any image and set the wallpaper. I am uncertain if this is a OS bug with Tahoe
Hey Community,From now until Sep 26th, you’ll earn 20 BYTES in Jamf Nation Rewards just for subscribing to our Jamf Nation General Discussions!How? Easy:Head to the page linked above! Click the big blue Subscribe button. Stay in the loop on all things Jamf + Apple - and get rewarded for it!⭐️ BONUS TIME ⭐️For a limited time, get 50% off the bytes needed to redeem some of our newest swag. Imagine rocking that gear at JNUC!Not part of Jamf Nation Rewards yet? If you’re a Jamf customer, sign up through your Jamf Account (details here).Your swag is waiting…⏰Please note: You may not see your new points reflected in your Jamf Nation Rewards Account right away. We are currently in the process of reconnecting our updated Jamf Nation with Jamf Account. We appreciate your patience while we reconnect these programs.
Hi. Im working with the new platform API, but i cannot access the Integrations tab on our company Jamf Account, and every time need to ask my colleague. My colleague has exactly same permissions as meand yet he can access Integrations tabs just fine, creating and modifying integrations, while all am seeing is two errors:Has anyone had a similar problem and managed to resolve it? Our accounts are provisioned from Duo IdP
Hello, Looking for a way to configure the Global HTTP proxy via Jamf Pro for macOS. The "Global HTTP Proxy" payload is only available for 'Devices' in JamfPro. We previously pushed a proxy pac URL setting that restricts browsing if not signed in to VPN via a script from macmule that uses the networksetup command. We found that this method doesn't restrict Safari and only restricts Chrome. After a chat with Apple Support, it appears that we need to use the Global HTTP proxy method for it to apply to Safari. Has anyone deployed a "global HTTP proxy" configuration to macOS devices via Jamf Pro? Thank you! Thank you
Anyone able to update to Google Chrome to version 150+? I’m stuck at 149. It won’t flip for me. And I tried creating a new title too.
Has anyone else noticed that custom Self Service branding no longer applies to App Installer / Notification Center notifications?Environment:Jamf Pro (current version) Self Service 11.28.1 macOS Tahoe 26.5.1What I’m seeing:Self Service branding is configured correctly in Jamf Pro. The custom icon appears correctly in the Self Service UI and as the application icon. However, macOS Notification Center notifications (e.g. App Installer update notifications) show the generic Jamf icon instead of our branded icon.Some investigation:Notifications appear under Management Action in System Settings > Notifications. CFBundleIconFile for Self Service points to AppIcon. AppIcon.icns appears to contain the generic Jamf icon. Running selfservice branding brand --icon <path> changes the Dock/Finder icon but does not affect notification icons. The behavior appears to be specific to notifications delivered via Management Action, which is how they appear in System Settings > Notifications.I
Has anyone started down this road of managing MacBook Neo’s with JAMF School? I have started testing and have encountered a couple of annoyances thus far. We are generally a Microsoft shop and use JAMF School to manage student iPads. As such, we are using JAMF Connect for student login to the devices on these devices as well.There seems to be an issue with the Neo’s not wanting to reconnect to wifi after a restart. Also, Keychain is asking for access to JAMF Connect password after installation. We have this same setup working on 10 iMacs at one school and they do not ask for Keychain access.Any thoughts or shared experiences would be great. Thanks.
Many organizations recommend or prescribe a specific web browser for their users. The user can change the setting in the user interface, even though it is not really obvious where to look. Many MacAdmins would like to pre-set this browser and the default during enrollment. However, there are several challenges associated with this in macOS. It would be really nice if Apple provided some means to manage this with a configuration profile. If you agree, please file feedback with your AppleSeed for IT account. While we wait for that, what can we do? Use the browsers Most third party browsers have a built-in command option to set themselves as the default browser. Most Chromium based browsers (Google Chrome, MS Edge, etc.) can be launched with the --make-default-browser option: open -a "Google Chrome" --new --args --make-default-browser open -a "Microsoft Edge" --new --args --make-default-browser For Firefox, the options are different: open -a "Firefox" --new --args -silent -nosplas
Hi, Has anyone been able to deploy Crowdstrike Falcon via jamf? We need to deploy this to 180+ machines and don't want to manually install every device.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!