Get Support
Recently active
Hey Nation,I’m normally not one to jump on a trend but this one was too fun not to! Who’s up for sharing theirs??Head to ChatGPT (I know it’s already open so shouldn’t take you long 😂) and ask: “Create a caricature of me and my job based on everything you know about me.”Here’s mine! Post yours in the thread 🧵! I can’t wait to see them all!!!
Hey There! Is there any way to obtain free voucher for Jamf 100 certification?
Even when Erase All Content and Settings is restricted, the option “Erase This iPad” still appears during sign out.Will it be possible to restrict this as well?The same behavior occurs even when using a Managed Apple Account...
HI everyone,I am trying to implement JAMF Connect in our organization. I was able to successfully configure the OIDC, but while testing the ROPG, I am getting the attached error. I have confirmed that the client secret ID is correct, as the ROPG login is working for just one account. Also, all the users have been given access to the Enterprise Application. Any leads would be helpful. Thanks
Has anyone successfully managed the following Safari settings via Jamf Pro (macOS and iPadOS)?• Hide IP Address from Trackers • Prevent Cross-Site Tracking (I have disabled this in Safari on Macs with the “WebKitPreferences.storageBlockingPolicy” key.We are trying to determine whether these can be enforced through a configuration profile or other supported method, rather than relying on per-user changes. This is for lab or classroom environments,If you’ve implemented this, could you share:- Whether it’s working on macOS, iPadOS, or both - The payload/key used (if profile-based) or the approach taken Thanks in advance for any insight!
Hi everyone, we’re currently testing Platform SSO (Secure Enclave) in combination with the Kerberos Single Sign-On Extensionon our Macs (managed via Jamf Pro).Since enabling Platform SSO, we’ve encountered issues with password synchronization as well as Single Sign-On authentication for ADFS-based web applications. As soon as Platform SSO is enabled, users receive the following prompt either after some time or following a reboot:Password SynchronizationVerify your Active Directory and Mac passwords. If they do not match, your Mac password will be synced. The passwords are identical (local macOS login = AD password). However, this prompt appears repeatedly — and only when Platform SSO is active. Additionally, our ADFS-based web applications (intranet portals, internal sites) no longer perform automatic Single Sign-On once Platform SSO is active.I’ve tested this behavior in multiple browsers (Safari, Chrome, Edge, and Firefox), and in all cases, users are prompted to sign in manually.Whe
The criteria Postion in the User and Location for iPad users was removed. Not all user... Any ideas why? I can’t find that anything was changed in Jamf.
In macOS 15, the new Private MAC address settings is enabled by default, and there is a new settings in Profile to disable it, BUT it's only for a spacified SSID. If you need a global setting to disable the Private MAC for all existed and new SSID, try to create a new policy to run this command: sudo defaults write /Library/Preferences/SystemConfiguration/com.apple.airport.preferences.plist PrivateMACAddressModeSystemSetting -int 1 It will not disable the Private MAC Address immediately, but it will work after forgot the network or reboot the computer.
as a systemadmin I really like the Mac Apps updates , both Jamf App catalog and App store. But as a user (and all our users) we get annoyed by the popups. The announcement popup I can understand, but the thank you popup after update is really not needed I think.Would be great if we can disable that.
When creating a smartgroup, there’s a criteria for Last Enrollment. But it’s based on the enrollment date, which does not always have a value. Those machines seem to be excluded from any search which uses the enrollment date criteria. How do you search for machines with no enrollment date?
Hello all, I am struggling getting OneDrive to silently sign in and redirect folders. I have researched previous posts, and am using Microsoft's guide here: https://learn.microsoft.com/en-us/sharepoint/deploy-and-configure-on-macos to no avail. Here is my configuration policy below -- can anyone take a look and see what I'm missing? I swapped out my real tenant ID with (Tenant ID) for the sake of sharing. Thanks for your help. <?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"> <plist version="1"> <dict> <key>KFMBlockOptOut</key> <True/> <key>KFMSilentOptIn</key> <string>(Tenant ID)</string> <key>KFMSilentOptInWithNotification</key> <True/> <key>KFMOptInWithWizard</key> <string>(Tenant ID)</string> <key>EnableSyncAdminR
Thanks in advance for your input...Our current scenario: our newly purchased iOS/iPadOS devices are automatically enrolled into Jamf Pro and then go into a default group. This group has a relatively restrictive Configuration Profile that prevents users from adding an Apple Account. If the user needs a different configuration or apps on their device, they need to submit a form to the device management team. From there, the device mgmt team works with the user and so on. Since we’re in education, we’re dealing with a full gamut of needs, business apps, engineering, utility/infrastructure, scientific, entertainment, media, development...you get the idea. So, we can’t anticipate ALL of the apps users want beforehand.Questions: what is your organization's workflow for newly purchased iOS/iPadOS devices? And how do you communicate to end-users where to go for additional support/apps/configs when they power on their new device?We're thinking either a wallpaper with messaging about reaching ou
This was reported to us earlier this week. iOS 26.x appears to break or override applied JAMF content filtering profiles with the addition of an “Add Website to Allowed List” button that appears on blocked websites. Thankfully this only seems to apply when using a content filtering profile set to “Limit Adult Content” and not the more restrictive “Specific Websites Only” setting, but if you’re blocking websites with the former and a user navigates to a restricted site, they can just tap this button and it overrides the applied profile to grant them access. Getting A LOT of complaints from some of our buildings that students are exploiting this to access websites that had previously been blocked. Not sure what Apple’s thought process was in adding this button...
Students are using Performance Matters but are just accessing Google Lens. We can open a Chrome window and type the following in the address bar: chrome://flags and it opens a settings window where you can enable and disable features but we are looking for a way to add an XML file to Google Chrome in Jamf School for our iPads to disable Lens Overlay. I have seen this XML file but I’m not sure it’s written for Jamf School:<?xml version="1.0" encoding="UTF-8"?><!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"><plist version="1.0"> <dict> <key>LensOverlaySettings</key> <integer>1</integer> </dict></plist> Has anyone had success in disabling Google Chrome Lens in Chrome from Jamf School?
We are a school and deploy laptops to students starting in the 7th grade. Administration would like to set it so that the computers lock between 10pm EST and 6am where the students cannot log into their device. We have tried a few things but at best we can get the computer to lock but students just log back in. Does anyone have a similar setup or suggestions on how to properly setup a curfew on an Apple laptop? For what its worth we are working with all Apple Silicon laptops. Thank you!
Environment: iOS 26 Jamf Pro with Apple School Manager (ASM) VPP token User Assignment licensing (not Device Assignment) Personal Apple ID (non-managed) Issue: Successfully accepted a VPP invitation this morning. Deleted the VPP user in Jamf Pro to troubleshoot an app assignment issue. Created a new VPP invitation and sent it to the same email/Apple ID.When clicking the invitation link on the device: Tap "Accept" Redirects to App Store Hangs with "Can't Connect to App Store" error Steps Taken: Confirmed App Store is accessible normally (can browse/download personal apps) Deleted and re-created the Jamf user with same email address Issue persists across multiple attempts Current State: Unable to re-establish VPP association with the same Apple ID. Appears to be a cached association on Apple's backend preventing re-invitation acceptance.Question: What is the recommended method to force-clear the VPP user association on Apple's side, or is the only resolution to wait for the
For test purposes, I have a very simple shell script. #!/bin/shkillall Dockexit 0A policy runs the script, and it’s available in Self Service. When I run it from Self Service, it works as expected (I can see the Dock restart itself). Hooray!However... (1)Self Service reports “Item Failed”, and (2)when I go to the Policy and check its logs, there’s no indication the Policy ever ran (status remains Pending).Is there a way to reset the Dock that Self Service won’t regard as a failure, and fail to log the Policy execution?
Is there any equivalent application to Microsoft's AD Users and Computers but available for Mac OS X?Basically the only time given, my specific role, to access a Windows box or start-up a Windows VM is to unlock a users account on AD or to move/delete a computer object in the Mac OU in AD. Given those two specific requirements is there a Mac app for that (that is free if possible)? I have looked before into this and I could only find outdated apps or very expensive high-end server style Enterprise solutions. Thank you
Version: 12.1 MontereyProcessor: M1 ProLast Inventory Update:01/12/2022 at 12:27 PMLast Check-in:01/12/2022 at 12:26 PMSupervised: Yes What are my troubleshooting steps to get these to go through. Let's collab.
We're informing you that devices on your Jamf Trust iOS fleet should be updated to iOS/iPadOS 26.2 ahead of an upcoming Jamf Trust release to avoid potential connectivity disruptions. We are resuming the rollout of Jamf Trust 11.47.0 for iOS/iPadOS. This message provides details on timing and recommended actions for customers still running iOS/iPadOS 26.1.Rollout UpdateThe gradual release of Jamf Trust iOS/iPadOS 11.47.0 will resume Monday, February 16, 2026 at 9:00 AM UTC, with rollout expected to complete by end of that week.⚠️ Action Required Before the Rollout: Update to iOS/iPadOS 26.2Apple resolved the underlying root cause of this issue in iOS/iPadOS 26.2, released December 12, 2025. Devices running 26.2 or later are not affected. We strongly encourage all customers to prioritize updating devices to iOS/iPadOS 26.2 before the Jamf Trust rollout begins this week. This is the only permanent fix for this issue.Potential Impact (iOS/iPadOS 26.1 Only)Devices still running iOS/iPadOS
Hi Jamf Nation Team, We are currently working to deploy the Falcon Sensor in our system, but we need to monitor the sensor's status. Unfortunately, the Extension Attribute I was using is not gathering the necessary information. Could you please help me if you have any that I can use: Sensor Registration: Confirms whether the Falcon Sensor is correctly registered with the CrowdStrike cloud.Sensor Operational Status: Checks if the Falcon Sensor service is running correctly on the endpoint.Sensor Cloud Connectivity: Verifies that the sensor can successfully communicate with CrowdStrike’s cloud infrastructure. Thank you!
https://support.apple.com/en-us/100100 Name and information link Available for Release date iOS 26.3 and iPadOS 26.3 iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later 11 Feb 2026 iOS 18.7.5 and iPadOS 18.7.5 iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation 11 Feb 2026 macOS Tahoe 26.3 macOS Tahoe 11 Feb 2026 macOS Sequoia 15.7.4 macOS Sequoia 11 Feb 2026 macOS Sonoma 14.8.4 macOS Sonoma 11 Feb 2026 tvOS 26.3 Apple TV HD and Apple TV 4K (all models) 11 Feb 2026 watchOS 26.3 Apple Watch Series 6 and later 11 Feb 2026 visionOS 26.3 Apple Vision Pro (all models) 11 Feb 2026
I have worked through paloalto's official support document which explains how to create a jamf policy to uninstall Global Protect. It say that the script will run with "superuser authority". However, it still prompts the user to authenticate for the removal of the extension. Is there any way to get around this prompt on the user side?
SummaryAn issue has been identified that can affect devices updating Jamf Trust while running iOS/iPadOS 26.1. This post is related to the second scenario described in our previous announcement regarding compatibility issues impacting Jamf Trust in iOS 26.1.Issue OverviewDevices running iOS/iPadOS 26.1 with Jamf Trust and On-Device Content Filter (ODCF) may experience loss of network connectivity when upgrading to Jamf Trust 11.47.0 or later whilst on unstable or poor networks. During the update, the installation may hang, causing device-wide loss of internet connectivity. Recovery requires a factory reset.This issue affects any app implementing the On-Device Content Filtering extension on iOS and is not specific to Jamf Trust.Conditions (all must apply):iOS/iPadOS 26.1 ODCF vectoring enabled Jamf Trust updating to 11.47.0+ Unstable or poor network during updatePotential OutcomesThe Jamf Trust update hangs indefinitely Device loses all network connectivity (not restored by reboot) Fac
We have run into a situation where closing the lid on a Mac Book Pro or even just setting the device to sleep is resulting in a machine that cannot be recovered without holding down the power button.I’ve looked for changes that might be causing this but the only thing I changed (and have now disabled) was an extension attribute that was reporting PlatformSSO status.OS impacted are Tahoe, Sequoia and Sonoma generally on latest versions.If anyone has any clues on which logs might reveal why this is happening or to help understand what a fix might look like, that information would be gratefully received.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!