Get Support
Recently active
I am a Jamf Pro customer and think Jamf Teacher has great potential! However, our teachers are struggling to fully integrate it because of some missing key features. 1.) We are not enforcing the home screen layout payload so students can customize their iPads and organize their apps in a manner that works best for them. After restrictions are cleared, their apps lose their organizational structure and end up anywhere on their iPads. Apps that were in folders don't stay in those folders. 2.) Lack of status window/confirmation pop-up to see when you have a lesson in progress or have issued a command to student iPads. Teachers would like more visibility/confirmation as they issue commands and place restrictions.
Since November 2025 you can find the warranty information for your Mac devices in Apple Business Manager. You can call this information using API calls. Is there any information if Jamf is going to make an Jamf integration? This warranty information would be a cool feature to have in Jamf. As an MSP it would be great for Life Cycle Management for our customers.I’ve seen no information from Jamf jet.Sofar I've been working on local scripting in python to get the ABM warranty information in Jamf as an Extension Attribute. For Computers I've succeeded I'm however not successful yet for mobile devices. The Jamf Classic and Pro API’s won’t let me update Extension Attributes for mobile. So I'm stuc.Anybody there who would like to help? Or can somebody tell me how to update an extension attribute for mobile, if it is possible and not blocked in api.Kind Regard Remco.
We currently have the “Erase All Content and Settings” option blocked on our student iPads. However, we would also like to block the “Transfer or Reset” option, or at least the “Reset All Settings” option, on those devices.Is this something that can be configured? Thank you
Hello all,I just started with an existing system that isn’t really documented. This means I have to do a lot of jumping around to determine what something does, where it applies, and even if it is working. I want to create some good documentation for this, but I’m don’t know what the best method for doing this would be.Thank You in advance,-Pat
We manage our ipads using Jamf Pro. We load the students google email accounts onto the device using a Jamf configuration profile with the Google payload. The mail account will appear on the device (ipad iOS mail app) and prompt user to enter google password. The user enters the password and the iOS mail app will display the students google email. However, several times through out each day, the iOS mail app will stop displaying google email and prompt user to re-enter their google password. After re-entering the google credentials, the Mail app will not always start working again. I have had Jamf support review our config file with the google payload - they said it is set up correctly. I have contacted Google and they said that it is a Jamf issue. Has anyone else experienced this issue? How did you resolve it? thanks.
Howdy everybody! Time for my annual post about how we all need to get our budgets prepped and ready to go for all the hardware we need to replace that Apple is dropping from its OS Compatibility list!I've modified my previous regex statement to take out the models that were lost to us this year to the latest macOS version. It looks like Apple is taking a big ole axe to the intel macs, minus only a couple of exceptions that seem to tie to the devices that were still being sold at the time of the M1 release. One tricky piece are the specific intel MacBook Pro's that Apple has listed. In that grouping are the MacBookPro16,x models, where x is 1,2 and 4, but not the 16,3 model, so keep that in mind. If anyone has details that contradict that, please let me know here and i'll quickly change the posted regex.I've tested this in my own Jamf instances to verify its returning the data that i'd expect to see, and am confident this will be able to match everything that is no longer supported by M
After poking around Jamf Pro and Jamf Protect, it seems that JSC/RADAR/Wandera is the only source of storage for CVE-level details for managed client app inventories. I can plainly see them in the default web dashboard. So I set up a Risk API key, and enabled the option to see user and device details.Both the docs [1] and manual exploration seem to conclude that only “Device risk” can be gathered from the public API, whereas things like “Average CVSS score” (or anything related to CVEs) cannot. Which would be fine if those two had a tight relationship, but I can plainly see things like an endpoint with six (6) high-scoring app vulnerabilities (including a 10 and a 9.8) per CVSS that only has two (2) app vulnerabilities reported per device risk and grading overall as low-risk.I did notice that app vulns as a category can be force-upgraded from low to high to influence device risk more, but it’s possible that device risk will entirely miss the presence of vulnerable apps and this still d
Hello Jamf Nation!We’ve released Jamf Pro 11.26.0 beta. This release includes updating session duration and time out within Jamf Account, automatic device registration with Microsoft Entra when using Simplified Setup for Platform Single Sign-on (Platform SSO), various bug fixes and more! For full details, check out the release notes after enrollment.How to join the beta: Enroll in the Beta Program under Product Feedback at account.jamf.com. Click “Join Community” to join the beta forum once enrolled. If you encounter an error on Jamf Nation joining the beta forum, please log into Jamf Nation and then click “Join Community” again. Please also check out this recent blog on Configuring SSO in Jamf Account prior to testing Compliance Benchmarks, Blueprints, and App Switcher. Email beta@jamf.com with questions.The beta program is covered by the Jamf non-disclosure agreement; please do not share any information regarding your testing on any public forum, including the non-beta areas of Jamf
You got this. TGIF!Have a great weekend!Feel free to share to your memes or express that you are glad this moment has finally arrived and the weekend will soon be upon us.
We are currently using a pre-stage created managed account and the LAPS process for passwords on that account. Since we use Jamf Connect, we have ‘skip account creation step’ turned on.I am finding that this account is not getting the bootstrap token escrowed or a secure token after MDM enrollment. Is this intended? How can I change this? Ideally, I’d like to have a hands off option that doesn’t require a manual installation so that we always have the bootstrap token escrowed and a secure token on our managed account. What am I missing in this step? I am finding when we do need to use the local admin account, it’s not able to take some actions, like install a new OS.
👋🏻 Hi everyone!We are organizing a Mac Admin community event on April 30th in Leiden (Netherlands) and wanted to share an early heads-up here.This is not a vendor or company event — it’s very much by the community, for the community, Inspired by established Mac Admin conferences and from years of local community meetups. Expect practical talks, shared experiences, and plenty of time to talk with other Mac Admins.More details coming soon, but feel free to reach out if you’re interested or want to know more. 🙂Website is https://macadmins-eu.org.LinkedIn page is https://linkedin.com/company/mac-admins-europe.Hope to see many of you there! ✌🏻
Greetings all, We are trying to enforce screen lock time limits (which InfoSec wants), but when we do, it also enforces a particular screensaver module (which InfoSec doesn't care about in the least). Some of our users don't like "Flurry" and want to set their own. These two seem joined at the hip in the GUI. Copilot had a suggestion using a script, but it didn't work for me. Does anybody have these two things functioning, but separately. It doesn't seem like a big deal to me, but some of our users are really not happy about not being able to set their preferred screen saver.
If you’re not using any enrollment progress tool in your Mac Environment now, or if you’re shopping for a replacement, consider Jamf Setup Manager. When exploring options, we wanted something easy to configure. Something we’d be able to set and forget. And if configurations needed tweaking later, it’d be easy to update. I am lazy. There, I said it. Enter Jamf Setup Manager (JSM). Setup Manager is the best gift I gave myself this Holiday Season. The best part is that we pass this onboarding experience to our customers and technicians. No heavy lifting. No scripting skills are needed. Just add these two ingredients and you’re on your way. The Setup Manager Package A new Setup Manager configuration profile Add the two items to your Prestage The folks at Jamf added a QuickStart guide to help you get started. I’d recommend giving this a read. This helped me generate ideas for customizing Setup Manager for my organization (more on that below). &nb
Hi all I have a fleet of Mac Pros all sitting behind a firewall. All traffic - IPs, ports have been allowed as per the Jamf documentation. All Macs can sync and restart however apps can't be deployed or updated. Am I missing something? I even have the entire APNS IP range allowed but still nothing. Any help or advice would be much appreciated
We are new to Jamf Now. WE have been experiencing issues with deploying apps to some of our phones. I have tried to re-enroll it, restore the phones, re-create the blueprint and create a different blueprint. I also updated the tokens. Has anyone encountered this issue? If yes, would you tell me what troubleshooting steps did you do?
Hi everyone, I'm deploying the Global Secure Access (GSA) client on macOS using Jamf, following the official Microsoft documentation:https://learn.microsoft.com/en-us/entra/global-secure-access/how-to-install-macos-client The installation completes successfully, but on first launch, users are still prompted with the message:"Global Secure Access Client would like to add proxy configurations." Does anyone know how to pre-approve or automatically allow this proxy configuration request via a configuration profile or PPPC/extension setting? Thanks in advance!
We have had a PolicyBanner installed on our fleet for several years. We have not had an issue with it until users upgraded to 26. When the banner pops after user login, the window is stretched to almost full screen, regardless of screen size or resolution. Screenshot attached of my large screen monitor.I have tried editing the RTF file a few ways to change margins and it will change the text but does not affect how the window sizes.I have also tried changing Desktop & Dock > Windows to Prefer tabs to Always instead of Full Screen This screenshot shows after trying to change margin and text. I can share another with all the txt centered and nothing on the right of the txt but empty white space. Thoughts? Here is the original screen
Based on your feedback and a review of the potential impact of the Jamf Trust iOS/iPadOS 11.47.0 upgrade to your fleet, we delayed the rollout to allow additional time for preparation.Jamf Trust 11.48 is scheduled for release February 25, 2026 at 9:00 AM UTC. This update resolves the network connectivity issue that could affect devices running iOS/iPadOS 26.1 during the Jamf Trust update. This release replaces the previously paused 11.47.0 rollout.We continue to recommend updating devices to iOS/iPadOS 26.2 for the best experience. Only devices running iOS/iPadOS 26.2 or later will receive new versions of Jamf Trust, 11.48.0 included.For more details, please refer to the Jamf Nation community post: Action Required: Update Jamf Trust App on iOS/iPadOS 26.1Need Help? For additional questions or assistance, please log in to Jamf Account with your Jamf ID and click Contact Support in the upper right-hand corner.
I get a Lego block icon when trying to login to a Mac on a domain. It doesn’t happen on all computers. I recently wiped a MacBook, that I could log into, however, after enrollment... now I get the Lego block icon. I can log in with other accounts.I believe it has something to do with the AD binding and possible VPP issue (my logs have been flooded with VPP Invitation Usage notifications). I don’t know how to fix it.Any help, would be greatly appreciated.Thank you.
I have been checking my Change Management logs .. and I have hundreds of VPP Invitation Usage logs - is this normal, is it causing other issues?
Morning,Anyone else experienced this issue since updating to Logic Pro 12 - We’ve got Jamf Pro at my org and currently push out Logic Pro via Apps store on Jamf which takes care of the updates and deployment to our various smart groups but since updating to version 12 yesterday we receive this error everytime we launch LP: The application cannot be used because the App Store authentication failed or no Network is available.Any ideas?Any advice or tips is greatly appreciated.
Hello there everyone, I have come across a very weird issue lately.Any policy that I add to Self Service+ fail to run, while if I open Terminal and run jamf policy -event TRIGGER it works like a charm.The policy does not matter it if includes a package or a script. It has been driving me nuts.Tried on different machines and re-installing Self Service+ app. Thank you in advance,Spyros
Hey everyone!We are relatively new to Jamf School and iPads in general for our district!We come from a Chrome environment so of course there are some abilities we had with GAC that we would like to emulate with Jamf School! Are we are to lock Chrome or Safari to only sign-in/authenticate with our @Domain accounts? Our fear is that students will just be able to login to any personal account and message/interact with each other that way (our admin is very pro-restricting student's virtual communication platforms).I appreciate any and all help!Thanks all,
With Jamf Pro 11.25, customize the application name and icon of Self Service+, adjust the session duration and inactivity timeout with Jamf Account enhancements, and use your Jamf Pro server to host enrollment information for account-driven enrollment!Be sure to check out the Jamf Pro release notes for all of the exciting new features and enhancements.Thank you for your continued support and feedback!
We’re moving some devices from Jamf to Intune now when the new fuction with OS 26 is in place with School and Business Manager.We have encountered problems with two units so far, that you can't specify a date for the change. With that, it doesn't seem like they are being moved as intended and need to be deleted the old way. Does anyone know what could be causing this and/or if there is a solution?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!