Get Support
Recently active
Instead of seeing iOS 19 and macOS 16 at WWDC this year on June 9, Apple is planning for iOS 26 and macOS 26. It's a similar name convention for automakers. Like the Toyota Camry 2026. Other Apple Operating Systems will follow suit. iOS 26iPadOS 26macOS 26watchOS 26tvOS 26visionOS 26 Thoughts? https://www.macrumors.com/2025/05/29/ios-26-again-rumored/
Do you have a naming convention for Smart Groups and Static Groups in Jamf as well as for iPhones and iPads?
HII apologize in advance if that question was asked but I cannot find answers :( I need to retrieve following information through API: 1. retrieve members through API from static computer groups - i need to list computer names that belong to specific computer groups. All i'm able to find is how to list computer groups, but not how to retrieve members. # Endpoint to retrieve computer groups$computerGroupsUrl = "$jamfUrl/api/v1/computer-groups"# Request computer groups$responseComputerGroups = Invoke-RestMethod -Uri $computerGroupsUrl -Method Get -Headers $headers -ErrorAction Stop 2. retrieve members through API from smart computer groups - i need to list computer names that belong to specific computer groups 3. retrieve data through API from "reports" found under "Search inventory"
Hi, Does any of you have a solution to synchronize all contacts from Active Directory and keeping them updated?While searching for a solution, I came across a post that suggested to have a shared Exchange account that would have all contacts stored, and add that as an extra account on all iOS devices. Is it possible to tell an Exchange profile to only sync contacts? If not, this is not an ideal solution in our case.Any ideas?
Like a lot of other Jamf admins I see a small number of Macs that have stopped checking in and sending inventories. I see some that appear to be having problems with MDM. I am curious about what everyone else is doing to solve these issues. Since we also use some other management agents I can see that a lot of the Macs that are having Jamf agent issues are working with the other management agents. They appear to be in use. I wrote a script that leverages the Jamf Management Framework redeployment API command. I was able to deploy it through Tanium to some systems that had stopped checking in and sending inventories. This has worked on some but not on others. For the systems having MDM issues, this may not work since the Jamf Management framework redeployment using the API needs MDM functionality to work. Here’s the current version of the script that I created.#!/bin/zsh --no-rcs:<<ABOUT_THIS_SCRIPT-----------------------------------------------------------------------------------
Student devices have had iOS 26 deferred until recently. They’ve been on iOS 18 until this month. But with the students finally upgrading the “Modifying wallpaper” restriction hasn’t been working as usual. They still can’t access the wallpaper menu in their system settings however when they press and hold to edit apps and widgets on their screen they can edit their home screen wallpaper from there. As a last ditch resort we can make a home screen layout payload but this locks in all app and widget customization. We have made and automated management action that will change the wallpaper every day but we do have some tenacious kids who continue to change it every day. Does anyone know another fix for this or maybe it will be something patched in the future? What would be really amazing is if they could restrict it so they cannot select photos but only pick the gradients or a solid color. but it doesn’t seem like they have that as an option for iPads
Hey,I am looking for a way to distribute Firefox Addons via Self Service …?The following Addon should be available in Self Service:Passwork Self-Hosted Extensionhttps://addons.mozilla.org/en-US/firefox/addon/passwork-self-hosted/?utm_source=addons.mozilla.org&utm_medium=referral&utm_content=searchDo I have to change anything else after the distribution as an PKG?How can I make sure that the installed Addon gets automatically updated?
Ninyo did a fantastic little article on update management with Blueprints. I just was hoping for some clarification on the process. I had setup a test blueprint just as spec’ed from the article and it doesn’t act the way I would expect. I am using the Software Update Settings payload. It is configured with deferrals just like the article. I then go to “Computer Software Updates” and select the test group, select update, select “Download and Install” and “Install latest version based on device eligibility”. I can then see the update start to be queued on the devices Management pane.After 10 minutes an error appears on the management pane.OSUpdateStatus The client requested cancellation completed. 12 minutes ago And it fails.I am able to update the device easily and instantly with the “Software Update” payload. I am a bit confused on what I am doing wrong. Other combinations in the Software Updates pane fail the same way.
We use Snow as an asset management system and would like to use a smart computer group to target machine’s for updatesWe have created the package, a policy and also a smart computer group.The SCG has criteria of:Application Title - is - Application Ver - is not. - latest versionPackage Installed By Jamf → is not → YourPackageName.pkgOur current issue is that even though it looks like “snowagent” is the application title, the Smart group shows 0 completers when clicking View. If I do drop app tittle and app ver, then it does show the machines that do not have the Package installed.So but this still does not push out the pkg to these machines.Any help on what might be wrong would be greatly received. Thank youAdam
Lots of posts about return to service, but nothing I have found about the Wi-Fi profile used in the Prestage Enrolment.As this profile cannot have anything except the Wi-FI payload (why??) There’s a workaround for Enterprise networks which have such things as a certificate payload.The workaround is to add the certificates to the profile after you have added the profile to the Prestage Enrolment. But when you go to save the modified profile, you are given a choice between sending to all devices or only devices without the profile.Well none of the devices have the profile yet, and if it’s a clone of your normal enterprise Wi-Fi profile, what will happen if you go ahead? Will you end up with two profiles with the same Wi-FI payload? I am reluctant to go ahead as changing WI-Fi profiles midstream is fraught...
Hi All, Does anyone has a script for automate User, Email Address, Position and Department after enrolment?Thanks in Advances
I’m pretty new to JAMF. I’ve got JAMF Connect 3.5.0, Self Service+, and JAMF Connect Launch Agent 3.5.0 deployed on my Mac Mini test device. I deployed these so I could start working on Tahoe support. After upgrading to Tahoe, everything seems to be working fine, except I now have to log-in twice when rebooting. The first login seems to be Filevault for unlocking the disk, and the second is the Entra web sign-in window from JAMF Connect.With Sequoia and the older version of JAMF Connect that most users are on, they only have to log-in once with the Entra web sign-in window.I’m using all the same config profiles as the old machines. Is this expected in Tahoe or is there some config change needed to get SSO sign-in to cover both filevault and OS login? Also, I have to enter the username in the second login as well. I’m pretty sure this was pre-populated before. I’m not 100% sure if this was caused by the new JAMF Connect apps versions, or only after the Tahoe upgrade. Is there anything I
We currently have an instance installed on tomcat and working on getting memcached working.memcached out of the box works fine, but it supports TLS encryption. When we enabled this, it appears that JAMF doesnt know what to do with the TLS connection.We will firewall off that port as suggested. But TLS seems like a good idea.
Is there any expectation that the Self Service+ icon will be Liquid Glass compatible when using custom branding? This would be helpful for consistent appearances across the new macOS UI. I created a .icns file using Icon Composer that contains icons using our own branding for Default, Dark, and Mono themes but, I’m unsure if there’s a preferred or supported method to deploy these icons in a way that ensures compatibility with Liquid Glass design standard.
Apple now supports Platform SSO during Automated Device Enrollment (ADE) in macOS 26. This allows users to authenticate with Entra ID directly in the Setup Assistant, create a local macOS account, and gain immediate SSO access to apps and websites.Currently, the Microsoft Platform SSO plug-in does not support this flow, and Microsoft has not announced full support.Could this serve as a workaround for first-time login on a JAMF-managed Mac?A possible setup using Entra ID:1. Start the Mac → Setup Assistant2. Sign in with Managed Apple ID (federated with Entra ID)3. Redirect to Entra ID → authenticate4. Create a local macOS user5. Enroll the device in MDM6. Configure Platform SSO later using the Entra ID user This approach enables initial device setup while allowing Platform SSO to be activated once the local user account is established.
Is there a way to prevent local administrators from removing the JAMF Binary with jamf removeFramework ? We still need local administrator accounts for our professors but don't want them to be able to delete the JAMF Framework.
Hi all,I’m looking for some advice on improving our macOS update workflow. Current setupRight now we’re using a mix of:Restrictions payload with no deferral for our tester group, 1week deferral for everyone else.Nudge -separate config profiles depending on whether we want to push a required update or just remind users.This works, but managing multiple profiles every time there’s a new macOS version isn’t ideal.What I’d like to achieve is: A cleaner process for forced updates for everyone when needed.A standard workflow where users get UI prompts to update (Nudge-style), based on our deferral policy.Ideally: define the update version and handle the user prompts from one place, without juggling several profiles. Does Jamf Pro offer any built-in way to handle both the update logic and user prompts together?Or is Nudge still the best option?If you have a setup that avoids maintaining multiple profiles per update, I’d love to hear how you do it.Thanks!
Hi! As my institution's Jamf admin I'm working on developing procedures to manage our to-this-point large pool of essentially unmanaged iOS devices. Prestage Enrollment isn't new to me, but managing iOS very much is. I'm currently working on bringing management to a pool of loaner iPads, but with an eye towards managing personally assigned iOS devices once I've got the loaners under control. I've been playing around with Jamf Reset, Jamf Setup, and Apple Configurator 2, and I'm still confused on a few points. 1) I think I already know the answer to this (No) but... there's no way to wipe an iOS device via Configurator, Jamf Reset, or any other method that wipes everything EXCEPT a wireless profile, right? Doing so would actually allow us to provide the "over the air" functionality everyone likes to talk about. 2) Activation Lock seems to be a sticking point. I definitely want "Prevent user from enabling Activation Lock" since that's burnt us before, but if I enable "Enable
Today we are releasing a maintenance version of Jamf Pro; highlights include: Resolved IssuesJamf Pro Server[PI122411] Fixed: After making changes to a user level configuration profile that is made available in Self Service, Jamf Pro unexpectedly redistributes the profile when devices update inventory, sometimes resulting in devices losing network access. [PI134378] Fixed: When attempting to upload a file (e.g., configuration profiles, in-house apps, eBooks, certificates) the page refreshes or the Upload dialog closes before the upload is complete. [PI148308] Fixed: The Jamf Pro API endpoint POST /v1/devices/{id}/erase does not clear Activation Lock for computers, despite clearing Activation Lock when erasing computers with a remote command via the Jamf Pro interface. [PI148751] Fixed: Attempting to create or retrieve patch software titles using the /JSSResource/patchsoftwaretitles endpoint of the Classic API results in a 500 Internal Server Error. For additional information on what's
To all those who celebrate/observe, may you and your families have a Happy Channukah/Hannukah/Hanukah/Festival of Lights!
Update 12 December 2025: Standard Cloud upgrades are scheduled for the weekend of 9–10 January 2026 (details below). We appreciate your patience with the revised schedule. Today we are releasing Jamf Pro 11.23; highlights include:New Settings for Privacy Preferences Policy Control and Platform Single Sign-onJamf has expanded support for additional Privacy Preferences Policy Control restrictions and the Single Sign-on Extensions payload with new computer configuration profile keys. This update enables administrators to define and deploy more granular privacy and security permissions for macOS devices while streamlining the user experience.Return to Service EnhancementYou can now add more than one payload to a configuration profile when configuring Return to Service in a PreStage enrollment. Previously, only one Wi-Fi payload could be used. For additional information on what's included in this release, review the release notes via the Jamf Learning Hub.To access new versions of Jamf Pro,
Today we are releasing Jamf Pro 11.20; highlights include:Compatibility with Apple Operating SystemsCompatibility and new feature support are based on testing with the latest Apple beta releases of macOS Tahoe 26, iOS 26, iPadOS 26, tvOS 26, visionOS 26, and watchOS 26. Simplified Setup for Platform Single Sign-OnJamf Pro can now support deployment of a Platform Single Sign-on (Platform SSO) application during the Setup Assistant with macOS 26* using the Simplified Setup for Platform Single Sign-on workflow in a computer PreStage enrollment. This workflow allows for Platform SSO to be enforced through the Setup Assistant during Automated Device enrollment, requiring registration with an identity provider (IdP) and the ability for macOS to create a user account based on the user’s information from the IdP.*Feature support is based on testing with the latest Apple beta releases. Full functionality requires compatible implementation from supported identity providers (Okta and Microsoft
I use the API to set an owner and it works fine however, the documentation states that to remove an owner the owner should be set to zero and the message I get back is user not foundhttps://api.zuludesk.com/docs/#api-Devices-Assign_owner
A couple users updated to MacOS 26.2 over the weekend and are seeing this in Jamf Trust. I updated my computer and I’m seeing the same. I’m guessing that Trust just doesn’t recognize 26.2 yet? Or is there something I need to do on the admin side of things to fix this? I don’t think I’ve ever had to touch macOS versions in trust before. “MacOS is outdated”MacOS version 26.2
Hello, We have an issue where iPads running 26.0.1 are working absolutely fine no issues whatsoever however as soon as they upgrade to 26.1 their internet connection stops working. Devices can be connected to the network no issues and appear to be working fine but you are unable to access the internet and they refuse to talk to JAMF.I found the following : https://discussions.apple.com/thread/256182709?sortBy=rank which appears to be the same issue. Wiping the devices hasn’t helped and the problem persists.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!