Get Support
Recently active
Today we released Jamf Connect 3.6.0. This release includes the following: Changes and ImprovementsThe Jamf Connect login window now includes Dutch as a supported language. The authchanger command-line tool now recognizes Microsoft's macOS Platform Single Sign-on (SSO), allowing administrators to safely use the authchanger -reset command without affecting deployments of macOS Platform SSO. For more information, see macOS Platform Single Sign-on overview in the Microsoft Entra documentation. In Jamf Connect Configuration, the Quit and Preferences options in the "Hidden menu items" section are now selected by default. Additionally, the About option is no longer available. Resolved Issues[PI140308] Fixed: When switching networks from the Jamf Connect login window, disconnecting from Wi-Fi and attempting to reconnect will prompt users for the Wi-Fi password instead of connecting without a prompt. [PI144503] Fixed: The Jamf Connect login window presents the following error after entering
JAMF Nation, I am trying to configure a plist file to disable Bluetooth Sharing. It appears this could be done in com.apple.Bluetooth in the "By Host" folder of preferences in finder. (Users/$user/Library/Preferences/By Host) I have come up with the following plist, when I push it via the JSS it is installed on the endpoint but the setting isn't enforced. Has anyone enforced this setting in this manner? Additionally I am aware of the JAMF Github with the CIS benchmarks and @franton Github with the benchmarks as well. I would just like to enforce this via config profile if possible. <?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"> <plist version="1.0"> <dict> <key>PrefKeyServicesEnabled</key> <false/> </dict> </plist>
Hello Jamf Nation!We’ve released Jamf Pro 11.25.0 beta. This release includes Branding Self Service+ for macOS via Jamf Pro, Improvements for OIDC-Based Single Sign-On Through Jamf Account and more.How to join the beta: Enroll in the Beta Program under Product Feedback at account.jamf.com. Click “Join Community” to join the beta forum once enrolled. Please also check out this recent blog on Configuring SSO in Jamf Account prior to testing Compliance Benchmarks, Blueprints, and App Switcher.Email beta@jamf.com with questions.The beta program is covered by the Jamf non-disclosure agreement; please do not share any information regarding your testing on any public forum, including the non-beta areas of Jamf Nation. Use the Jamf Nation Beta Forum or contact Jamf via beta@jamf.com with any questions. Thank you to all who participate in this program!
Hi All,we currently use Jamf School to manage our iPad estate. it works great for what we use it for, but the goalposts have been changed on us.Moving forward, Cyber Essentials requirement are set to change so that our devices need to be trusted. Our trusted IP address will no longer satisfy the requirements. So we will need to add our devices to Microsoft Intune. I believe that this is configurable with JAMF Pro, but not JAMF School. Is this the case? Is this a feature that will be added in the near future?We are currently having to evaluate using Microsoft InTune as an MDM alternative to JAMF School if it cannot fulfill this requirement, and it is already covered in our Microsoft Licence.Any advice would be much appreciated.
We are using Jamf School to send a profile that blocks certain apps on student tablets from 8:30 AM to 3:00 PM. However, for the past few weeks, this profile—and all other profiles—activate as scheduled but then get removed by themselves after 5-10 minutes, causing a continuous loop of removal and reinstallation throughout the day. Has anyone experienced this issue or knows a solution to prevent profiles from repeatedly removing themselves?
I just found out that Microsoft Office has been automatically saving all files to the cloud for several months. I would like to disable this feature for my environment via Jamf Pro. I guess the easiest option would be to uncheck “Enable automatic saving by default” in Office via Configuration Profile. Where can I find the plist that controls this setting? Are there other ways to set this centrally via Jamf Pro?
Hi everyone,I need help understanding the correct way to disable password sync in Jamf Connect while still using Google Workspace authentication during ADE enrollment.Our current setup (Jamf Connect + Google Workspace + ADE) behaves like this: During initial login, the user signs in with their Google Workspace account Jamf Connect creates the local macOS user account based on the Google workspace account (First name and Last name) The initial local mac password is set to the Google password If the user later changes their Google password, Jamf Connect detects a mismatch and prompts:“Your local password and network password are different. Please enter your local password to sync.” Once the user enters it, the Mac password gets updated to match the new Google password What we want instead: Users authenticate with Google Workspace ONLY for the first login Jamf Connect creates the local account After that, the macOS password and Google password must be completely independent
We have one user with a Macbook Pro M1 Laptop. Big Sur is installed on the machine and the logged in user is a Mobile Account and has admin rights. File vault 2 is also enabled.Deployment was some month ago and everything worked fine. Two days ago the user approached me as he was not able to login with his account credentials at home. He was in the office yesterday and after I logged in with my local admin account everything was fine and he could work. So told him to also to update his Big Sur installation from 11.2.x to the latest version 11.5.2. But as he tried to enter his password the following screen states that Authentication is disabled.I grabbed this screenshot from the internet cause our dialogue is in German.Anybody have seen this? Where does this come from and how can we fix this? I would greatly appreciate your help.Thanks
Hello everyone!I’m currently going through a PCI audit process and we need to collect logs for specific events within macOS, we aim to do this with Jamf Protect (Telemetry, Analytics, Unified Logging, whatever fits best honestly). But having rather low success so far, given the amount of noise we get from, probably, too general predicates.Have you had to set this up? Do you have hints or tips (or, even better, your analytics/filters)? This is the list of events we want to get logged: a. all administrative actionsb. accessing audit trailsc. invalid access attemptsd. successful access attemptse. elevation of privilegesf. creation/deletion/changing an account with admin privilegesg. start/stop/pausing of audit logsh. creation of system-level objects Thanks in advance!
We're having an issue with the Jamf Setup app (iPadOS) displaying in single app mode. We've configured the app so that the user can enroll their device during the process with Entra Login. However, the Jamf Setup app requires Safari to display the Entra registration window. Unfortunately, when I launch the Jamf Setup app in single app mode, I can't enroll my device because the Entra registration window doesn't appear. I don't want to use the "restriction" profile to only allow Jamf Setup and Safari, because our users might simply browse with Safari without registering their device. Do you have any suggestions or experience on how I can lock my iPad in the Jamf Setup app and registering the device using Entra Login?
Here’s the problem we need to address: many of the things IT teams do aren’t documented because they’re seen as busy work, there’s no time, people forget, or they just don’t want to. But here’s the thing: documentation may take some time, but it takes exponentially more time to research a solution every time you need it. For example, it might take 20–30 minutes to create a quality document. Researching a solution can take 10–15 minutes, and if you need to research it 2–3 times, that’s 20–45 minutes of research. Meanwhile, it only takes about 5 minutes to re-read a well-written document. So, let’s get started on how to do this. It happens all the time: you figure out a solution or process, implement it, and move on to the next task on your never-shrinking to-do list. A few months later, you need to do the same thing again and must dig through scripts, tickets, blogs, Slack, or wherever you found the solution, trying to recreate it. It takes a lot of time, and you think, “I really should
I am having a separate issue but need to submit ticket. When I log into Jamf Account and try to click the “Contact Support” button, nothing happens. Is anyone else experiencing the same issue?
I’m trying to deploy a Mac App that was purchased through Apple School Manager VPP.When I go to Computers → Mac Apps → App Store and add the app from the App Store, I can find the app and click Add, but the page spins and never moves past for me to actually finish adding the app to my tenant. I’ve checked the VPP token and ensured everything is connected properly. This is not an issue when working in the Devices, only when adding apps from the app store for computers.
Hi,Could any one guide on how we can migrate data between two managed macOS devices and same for iOS devices?
We’ve been using a script that automatically downloads and installs the latest version of Google Chrome when we push a prestage policy to our Macs. This script no longer works on Tahoe. This is the error that shows up in the logs:Script result: Wed Jan 21 16:08:00 CST 2026: Create temporary directoryWed Jan 21 16:08:00 CST 2026: Download 'https://dl.google.com/chrome/mac/universal/stable/GGRO/googlechrome.dmg' Wed Jan 21 16:30:23 CST 2026: Check downloaded DMG hdiutil: attach failed - no mountable file systems find: : No such file or directoryI’d like to find out how I can update this script to work with Tahoe. Here’s the script we’re currently using:#!/bin/bash bundle="Google Chrome.app" tmp="/private/tmp/GoogleChrome" echo "$(date): Create temporary directory" mkdir -p "${tmp}" echo "$(date): Download 'https://dl.google.com/chrome/mac/universal/stable/GGRO/googlechrome.dmg'" curl -s -o "${tmp}"/"GoogleChrome.dmg" "https://dl.google.com/chrome/mac/universal/stable/G
Is there a way to send alert messages to iPhones manage by JAMF. I can do it in Mac via policy using the JAMF helper. Is there a same method in doing this to iPhones?
Hi! We finally upgraded Bomgar or BeyondTrust Remote Support to 24.3.2 to support Sequoia. The only issue I'm having is finding a way to allow standard users to toggle on, or allow applications in System Settings > Privacy & Security > Remote Desktop.I didn't see anything in the PPPC Utility tool and wasn't able to find anything in Jamf Pro under the Privacy Preferences Policy Control config settings. Wasn't sure if it's possible to allow currently or not but thought I'd ask here.
Follow this instructions :https://support.grammarly.com/hc/en-us/articles/8341875702413-How-to-deploy-Grammarly-for-Mac But still at Accessibility admin rights are required. Any idea what is wrong? thanks
Hi, Is there an updated way to install Avast via JAMF? I have search previous post but it seems its a long time ago and its not working anymore as per the last replies. Advance thanks.
I’m not too familiar with Securly (was just given access to Securly Filter for testing), but during the pandemic (before my time) Securly was implemented when students took iPads home. This was when our school district had Jamf Pro. Pretty much all of our iPads (less than 70~ stragglers still in Pro) are in Jamf School now. I replicated what we had in Jamf Pro as a configuration profile. It was simple enough from Securly’s documentation/old Jamf Pro configuration profile. But when I test it, and I see the activity, I only see ‘email’ (in Securly) as the user and not the actual email of the user. I’ve tested this by having my email account, a random student email account, and no active owner as the owner on the iPad (by adding/removing in Jamf School iPad inventory). All just say email. I tried this with the serial number as the variable but that shows up with random letters in the user field. I was hoping at least the serial number would actually show up correctly. Mostly, K-1 use iPad
Afternoon, Just got a reminder that i need to migrate to the new Self Service + does anyone know how to do it? Thanks
Hi Jamf Nation! 👋I'm excited to share an open source tool our team built: Jamf Docs MCP ServerWhat is it?An MCP (Model Context Protocol) server that gives AI assistants like Claude direct access to Jamf documentation from docs.jamf.com. Instead of copy-pasting documentation or switching between windows, you can ask your AI assistant questions and it will search and retrieve the official Jamf docs automatically.FeaturesSearch across all Jamf product documentation (Pro, School, Connect, Protect) Fetch full article content in Markdown format Browse documentation structure by product Built-in caching for faster responsesQuick Startnpx @get-technology-inc/jamf-docs-mcp-serverOr add to your Claude Desktop config:{ "mcpServers": { "jamf-docs": { "command": "npx", "args": ["-y", "@get-technology-inc/jamf-docs-mcp-server"] } }}Example Prompts"Search for SSO configuration in Jamf Pro" "How do I set up MDM enrollment?" "Show me the Jamf Protect documentation structure"LinksGitH
Hey everyone, Im suddenly running into an issue were I need all applications, both pushed by JAMF and others installed by the users, to have the option of “Scale to fit below built-in camera”. I could write a script to enable it for every app that we push but that is 1- not elegant and 2-wouldn’t hit any of the user installed apps.Does JAMF have a way to do this or has anyone been able to do something like this? Thanks.
I couldnt find any clear answer about my question. For Self Service Classic, I set a custom install location (/Applications/Catalog.app).From what I read, once I enable Self Service+, the branding will carry over, but my custom install location won’t ? I’m planning to enable the “Use Self Service+ as the default end user application” option very soon, will it use my custom install location, or will it use a default one (/Applications/SelfService+.app) ? Thank you
Today we are releasing Jamf Pro 11.24; highlights include:OIDC-based SSO Through Jamf Account Enabled by Default for New Jamf Pro Instances All new cloud-hosted Jamf Pro instances are pre-configured to use OIDC-based single sign-on (SSO) through Jamf Account as the default authentication method for first-time access. This eliminates several steps of the Jamf Pro setup workflow and also ensures that new Jamf Pro instances have access to platform capabilities (e.g., blueprints and compliance benchmarks) immediately after setup.Note: This change only affects newly created Jamf Pro instances hosted in Jamf Cloud (not available for Jamf Premium Cloud Plus or StateRAMP environments). Automatic Jamf Protect Tenant Registration Jamf Pro can now automatically register your organization's Jamf Protect tenant to establish a secure connection between Jamf Pro and Jamf Protect. This eliminates the need to manually integrate by creating an API Client in Jamf Protect and configuring connection settin
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!